![]() |
|
Portal |
Downloads |
Arcade |
CD-Key Shop |
Register |
FAQ |
|
|
|
#1 |
|
MPC Member
Join Date: 23rd Mar 2006
Posts: 7
|
About Code Caving?
Speed:
00400019: fmul qword ptr [00400108] jmp 005eea87 Go to 5EEA81 Change EIP to 00400019 Add manually 00400108 and set it to 125 (default) CASE 1 ---------------------------- how interprete this? --------------------- 1) ctrl + g : put 00400019 2) right button --> assemble : put fmul qword ptr [00400108] 3) y next line right button --> assemble : jmp 005eea87 4) Go to 5EEA81 Change EIP to 00400019 Add manually 00400108 and set it to 125 (default) CASE 2 --------------------------other says ------------------------------ 1) ctrl + g : put 00400019 2) press ctrl + A (autoassemble) 3) paste : 00400019: fmul qword ptr [00400108] jmp 005eea87 4) Go to 5EEA81 Change EIP to 00400019 Add manually 00400108 and set it to 125 (default) WHAT IS STEP CORRECT?? (case 1, case 2, dont work for me) case 1) error : The generated code is 6 byte(s) long, but the selectd opcode is 2 byte(s) long! dow you want the incomplete opcodes(s) whit nops? CASE 2) error : not all code can injected |
|
|
|
|
|
#2 |
|
Knight of Wars
Join Date: 30th Nov 2005
Posts: 112
|
Case 2 is correct, but the addresses are outdated. The reason not all code can be injected is cause you're probably using TE.
|
|
|
|
|
|
#3 | |
|
MPC Member
Join Date: 23rd Mar 2006
Posts: 7
|
Quote:
but... don't me function with this injection 00400019: fmul qword ptr [00400108] jmp 005eea87 |
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|
![]() |
![]() |