Reverse Engineering RET Homepage RET Members Reverse Engineering Projects Reverse Engineering Papers Reversing Challenges Reverser Tools RET Re-Search Engine Reverse Engineering Forum Reverse Engineering Links

Go Back   Reverse Engineering Team Board > Search Forums
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Showing results 1 to 25 of 34
Search took 0.01 seconds.
Search: Posts Made By: zhgong007
Forum: .NET Reverse Engineering 09-23-2012, 07:39 PM
Replies: 7
Views: 31,569
Posted By zhgong007
have you tried the unpacking method as shown...

have you tried the unpacking method as shown below?


http://tuts4you.com/download.php?view.2676
Forum: .NET Reverse Engineering 09-18-2012, 07:20 PM
Replies: 6
Views: 25,137
Posted By zhgong007
after a few days' investigation, problem now...

after a few days' investigation, problem now solved.

the best tutorial about strong name protection removal can be found here:

http://tuts4you.com/download.php?view.2701



thank you,
Forum: .NET Reverse Engineering 09-10-2012, 01:04 PM
Replies: 6
Views: 25,137
Posted By zhgong007
mr Kao, I get some clues from your previous...

mr Kao, I get some clues from your previous post:

http://www.reteam.org/board/showpost.php?p=26841&postcount=4

however, but I don't know how to update Assembly table, AssemblyRef table and don't...
Forum: .NET Reverse Engineering 09-10-2012, 09:42 AM
Replies: 7
Views: 31,569
Posted By zhgong007
before you ask question, have you tried this ...

before you ask question, have you tried this tool to unpack it?

de4dot

just goolge it
Forum: .NET Reverse Engineering 09-10-2012, 09:32 AM
Replies: 6
Views: 25,137
Posted By zhgong007
further to my question, I find although the main...

further to my question, I find although the main program is now exectable, one of the dll cant be loaded. the fusion log is as follows:


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
*** Assembly...
Forum: .NET Reverse Engineering 08-29-2012, 08:31 AM
Replies: 6
Views: 25,137
Posted By zhgong007
thanks. seems working using resign tools instead...

thanks. seems working using resign tools instead of manually removing the publickey.

by the way, Kao is always the person who is most helpful in net reversing. he answers all questions in a...
Forum: .NET Reverse Engineering 08-27-2012, 05:04 PM
Replies: 6
Views: 25,137
Posted By zhgong007
strong name protection issue?

a .net 4 program A.exe, called a few .net dlls , say B.dll, c.dll, and D.dll. all these exetuables have strong name protections.
the main dongle protection code is in B.dll. I have used Ilasm to...
Forum: .NET Reverse Engineering 08-24-2012, 09:14 AM
Replies: 2
Views: 21,234
Posted By zhgong007
wow, it is working. you are always the...

wow, it is working. you are always the expert,Kao
but why I use the following command, then not working?


ilasm /output: *.dll *.il
Forum: .NET Reverse Engineering 08-24-2012, 07:13 AM
Replies: 2
Views: 21,234
Posted By zhgong007
want to revise a .net method , but failed

there is a net dll,in which a method I want to modify. the original il code for this method is as follows:


.method assembly static string GetComputerInformation() cil managed
{
// Code...
Forum: Reverse Code Engineering 07-17-2011, 07:35 PM
Replies: 22
Views: 14,397
Posted By zhgong007
I am pretty sure that the expire time is recorded...

I am pretty sure that the expire time is recorded in the "data" section. no simple way to figure it out unless you debug the original program.
Forum: Reverse Code Engineering 06-21-2011, 06:10 PM
Replies: 4
Views: 5,731
Posted By zhgong007
thanks. hasp key now recongnized, but the program...

thanks. hasp key now recongnized, but the program can't still work for 64system. perhaps this software is not able to work under 64 system at all?
Forum: Reverse Code Engineering 06-21-2011, 05:09 PM
Replies: 4
Views: 5,731
Posted By zhgong007
thanks , working with 32 bit multikey 18.0.3 ,...

thanks , working with 32 bit multikey 18.0.3 , but not working with 64 bit multikey 18.0.3. any reason? the usb dongle is not reconginized at all under 64bit system

my computor is 64-bit operation...
Forum: Reverse Code Engineering 06-21-2011, 02:37 PM
Replies: 4
Views: 5,731
Posted By zhgong007
hasp reg conversion help

how to convert the following reg to a multikey reg? thanks

REGEDIT4
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\NEWHASP\Services\Emulator\HASP\Dump\7D015D11]
"Name"=""
"Copyright"="Copyright (C)...
Forum: Reverse Code Engineering 06-19-2011, 01:13 PM
Replies: 4
Views: 4,711
Posted By zhgong007
hi, zementmischer. thanks for your suggestion. I...

hi, zementmischer. thanks for your suggestion. I have now solved the problem. this program uses its own function to revise the registry value:)

there is a checksum in the "data" .
Forum: Reverse Code Engineering 06-16-2011, 11:47 PM
Replies: 4
Views: 4,711
Posted By zhgong007
OK, I have edited the regfile using notepad, and...

OK, I have edited the regfile using notepad, and then install the regfile and the multikey emulator as well. I have then checked the regfile by running regedit. it confirms the cell value is...
Forum: Reverse Code Engineering 06-16-2011, 04:16 PM
Replies: 4
Views: 4,711
Posted By zhgong007
Help: memory data of the reg modified

I encountered a program protected by hasp HL dongle, and I have successcully emulated the dongle, however, there is an expiry date for the application. by reversing the application, I know the...
Forum: .NET Reverse Engineering 04-26-2011, 06:21 AM
Replies: 3
Views: 5,653
Posted By zhgong007
thanks for your fast response. I don't realize...

thanks for your fast response. I don't realize dis# can do the work.
Forum: .NET Reverse Engineering 04-23-2011, 12:42 PM
Replies: 3
Views: 5,653
Posted By zhgong007
help with dotfuxcator protection

problem solved by Kao. thanks
Forum: .NET Reverse Engineering 09-17-2010, 12:46 PM
Replies: 12
Views: 14,128
Posted By zhgong007
master, you are right. after I corrected the...

master, you are right.
after I corrected the SizeofImage, it is working.
I think I did make a change of it before, but I make a stupid wrong calculation of the SizeofImage: a000+2000= c0000, but not...
Forum: .NET Reverse Engineering 09-17-2010, 08:29 AM
Replies: 12
Views: 14,128
Posted By zhgong007
[Please DO NOT reply to yourself. Use the EDIT...

[Please DO NOT reply to yourself. Use the EDIT button to add to your post]

master Kao,
Again, thanks for your patience to answer my question which sounds to be simple for you, but it is really...
Forum: .NET Reverse Engineering 09-17-2010, 05:19 AM
Replies: 12
Views: 14,128
Posted By zhgong007
[Please DO NOT reply to yourself. Use the EDIT...

[Please DO NOT reply to yourself. Use the EDIT button to add to your post]

thank again.
actually, I have done exactly as what you said. but the dump doesn't work yet.
I understand that FF25 means...
Forum: .NET Reverse Engineering 09-16-2010, 06:12 PM
Replies: 12
Views: 14,128
Posted By zhgong007
thanks again for your quick answer. I am not very...

thanks again for your quick answer. I am not very clear about the PE strucuture at all. so I have such a stupid question:)

so, if we got the following dump...
Forum: .NET Reverse Engineering 09-15-2010, 04:50 AM
Replies: 12
Views: 14,128
Posted By zhgong007
[Please DO NOT reply to yourself. Use the EDIT...

[Please DO NOT reply to yourself. Use the EDIT button to add to your post]

thanks. I will do some homewokrs based on your information:)

I have read UFO-Pu55y's tutorial about "Unpacking CodeVeil...
Forum: .NET Reverse Engineering 09-14-2010, 05:47 PM
Replies: 12
Views: 14,128
Posted By zhgong007
.net dll packed by Xtreme-Protector v1.05

anyone can help me to unpack this dll? I'm not sure, but it may be packed by Xtreme-Protector v1.05
http://www.megaupload.com/?d=L90MQE8C

thanks
Forum: Reverse Code Engineering 05-06-2010, 09:17 AM
Replies: 10
Views: 11,364
Posted By zhgong007
I don't think it is hasp srm since neither h6dmp...

I don't think it is hasp srm since neither h6dmp nor srm logger can dump it or log it.
Showing results 1 to 25 of 34

 
Forum Jump




Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2020, Jelsoft Enterprises Ltd.