nick_name
October 27th, 2005, 08:46
1. i detach child from father
2. at child, i find IAT begins at 6961e0
3. i put a HW bp on write there
4. i restart olly , detach the father from child ( while the hw bp is already there)
5. i'm at child again
6. with a f9 , the child starts to run
OLLY does'nt break anytime on the IAT writting , where i'm going wrong ??
is there any other way to find the MAGIC jump or get the full IAT
where i'm going wrong ??
2. at child, i find IAT begins at 6961e0
3. i put a HW bp on write there
4. i restart olly , detach the father from child ( while the hw bp is already there)
5. i'm at child again
6. with a f9 , the child starts to run
OLLY does'nt break anytime on the IAT writting , where i'm going wrong ??
is there any other way to find the MAGIC jump or get the full IAT
where i'm going wrong ??