nick_name
October 27th, 2005, 08:46
1. i detach child from father
2. at child, i find IAT begins at 6961e0
3. i put a HW bp on write there
4. i restart olly , detach the father from child ( while the hw bp is already there)
5. i'm at child again
6. with a f9 , the child starts to run
OLLY does'nt break anytime on the IAT writting , where i'm going wrong ??
is there any other way to find the MAGIC jump or get the full IAT
where i'm going wrong ??
2. at child, i find IAT begins at 6961e0
3. i put a HW bp on write there
4. i restart olly , detach the father from child ( while the hw bp is already there)
5. i'm at child again
6. with a f9 , the child starts to run
OLLY does'nt break anytime on the IAT writting , where i'm going wrong ??
is there any other way to find the MAGIC jump or get the full IAT
where i'm going wrong ??

). Can anyone explain this to me (or provide a link to a English tutorial) ?