Helgame.exe OEP
-
- just visiting
- Posts: 8
- Joined: Fri May 21, 2004 2:52 pm
-
- just visiting
- Posts: 2
- Joined: Sun May 02, 2004 9:29 pm
i wish i could bitch slap choketokill for being such a dumbass. hb still uses aspr but its a new strain
i looked into the client with a few friends and found it uses multiple SEH tricks to do stuff, and to find the OEP is easy, for all u non technical ppl, u can stop reading and continue with other shit
get one hb client (3.51 pref) and see its OEP, now loadup 3.62 and go trough aspr, pass the stolen bytes, and when u reach ingame, dump the executable, load the dumped executable up in IDA and load 3.51 in IDA, now u gotta remember where ingame ASPR resumed the code so u can do a code compre, simentech dont change their base code so the initial startup code will be the same, now look for a sequence of code in the function (dumped code) and look for the same in 3.51, from there slowly backtrace till u find OEP, when u find it, it wont be 00's like aspr usually does, it will be filled with some messed up code.
good luck
i looked into the client with a few friends and found it uses multiple SEH tricks to do stuff, and to find the OEP is easy, for all u non technical ppl, u can stop reading and continue with other shit
get one hb client (3.51 pref) and see its OEP, now loadup 3.62 and go trough aspr, pass the stolen bytes, and when u reach ingame, dump the executable, load the dumped executable up in IDA and load 3.51 in IDA, now u gotta remember where ingame ASPR resumed the code so u can do a code compre, simentech dont change their base code so the initial startup code will be the same, now look for a sequence of code in the function (dumped code) and look for the same in 3.51, from there slowly backtrace till u find OEP, when u find it, it wont be 00's like aspr usually does, it will be filled with some messed up code.
good luck
-
- just visiting
- Posts: 8
- Joined: Fri May 21, 2004 2:52 pm
-
- just visiting
- Posts: 8
- Joined: Fri May 21, 2004 2:52 pm
-
- just visiting
- Posts: 8
- Joined: Fri May 21, 2004 2:52 pm
-
- just visiting
- Posts: 8
- Joined: Fri May 21, 2004 2:52 pm