📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  IDA Pro  >>  hi question about x 86 emu plugin and decrypting xor crypted strings

Topic created on: July 21, 2009 02:09 CDT by nah .

Well i want to read out xor = exclusive or crypted strings from a dynamic library dll.
My ida pro is 5.2 and to get work the x 86 emu plugin i compiled it with 5.2 sdk so i get it working. Well if i click on the crypted string and click on the x 86 emu to run it just crashes ida pro.
If im using x 86 emu step into then i can open the decrypted string it shows some weird asm code with local functions, but after 10 or more steps into it will just crash also and i cant read out the string ...

Could anyone suggest me anoyther plugin , tool or somethinf what would be able to decrypt thous strings, or i am using the x 86 emu pulgin wrong?

Hoping to get good answers �, thnx

  cseagle     August 30, 2009 02:37.24 CDT
It sounds like you are using it wrong.  Pointing at the decrypted string and attempting to execute it is not correct.  You need to use the emulator to execute the function or loop that is used to decrypt the string.  Also prior to running the function or loop you need to ensure that any registers or parameters to the function are properly initialized as required by the function or loop.

Chris

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit