jump to navigation

Syser Debugger 1.97.1900.1016 2008.5.27 May 31, 2008

Posted by reversengineering in DEBUGGER, TOOLS.
add a comment

1. Improve Syser’s video card compatibility.
2. Add 3 Video Display Card Detect Mode:
Auto (If you don’t care)
User Mode (High Compatibility)
Kernel Mode (Support DirectX)

DownloadLink: http://rapidshare.com/files/119028937/Sys.Debug.v1.97.1900.1016.zip

Sysinternals Suite 2008-05-28 May 31, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

Sysinternals Suite 20080528

2008-05-28

Handle v3.4: This release fixes a bug that allows it to run from read-only locations on 64-bit Windows and adds an option to show the sizes of pagefile-backed sections.

Process Explorer v11.20: Process Explorer now shows thread permissions, adds process working set minimum and maximum columns, and fixes a bug that allows it to run from read-only locations on 64-bit Windows.

Sigcheck v1.53: The CSV column headers have been fixed to correctly reflect the extended version and hash options.

ZoomIt v2.0: This major ZoomIt update adds the drawing color pink, adds screen blanking to the undo history, extends the maximum pen size from 9 to 19 pixels, has an option to hide the tray icon and makes it easy to save zoomed and annotated screens as bitmap files.

http://download.sysinternals.com/Files/SysinternalsSuite.zip

OllyDbg 167 Plugins 2008-05-24 (plus update package) May 24, 2008

Posted by reversengineering in OLLY'S PLUGINS, TOOLS.
add a comment
all ollydbg’s palugins(  old and new  )
if u have old package(116 plugins) only need to update them
thanx fly out to all developer of plugins ;)
best regards
73mg  >16mg zipped
 http://rapidshare.com/files/117227524/OllyDbg_167_Plugins_2008-05-24.part01.exe
 http://rapidshare.com/files/117227908/OllyDbg_167_Plugins_2008-05-24.part02.rar
 http://rapidshare.com/files/117228263/OllyDbg_167_Plugins_2008-05-24.part03.rar
http://rapidshare.com/files/117226990/OllyDbg_167_Plugins_2008-05-24.part04.rar
l
**************************************************************************************************************
30 mg > 9 mg zipped
 http://rapidshare.com/files/117228516/update_51plugins_2008-05-24.part01.exe
http://rapidshare.com/files/117228722/update_51plugins_2008-05-24.part02.rar
http://rapidshare.com/files/117228923/update_51plugins_2008-05-24.part03.rar

MORE INFO ABOUT RECon2008 May 24, 2008

Posted by reversengineering in NEWS.
add a comment

hi

u can find  more info about RECon2008  here: http://recon.cx

Dup v2.18 beta series ( 08.04.29 ) May 24, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

lasted version 2.18 beta 3 ( 08.04.29 )
[2.18]
-replaced WinExec API by ShellExecute for Windows Vista
-bugfix in Dialog for editing S&R Pattern Occurrence
-added check for skins button ids
-improved window resizing engine

beta series link:
http://free.pages.at/d2k2/stuff/dup2.beta.rar
http://diablo2oo2.di.funpic.de/stuff/dup2.beta.rar
released link:
http://free.pages.at/d2k2/downloads/dup2.rar

by diablo2oo2

WinHex 14.9 SR-5 May 24, 2008

Posted by reversengineering in HEX EDITOR, TOOLS.
add a comment

NeedZ:

│            We do not condone the sales of pirated software.                    │
│       The software developers need to be paid for their efforts.            │
│              If you like the software, you should buy it.                            │
│         This is to allow the software developers to survive                     │
│       and that we will get to enjoy more innovative products.               │
│    After testing of full version software,please destroy them.              │

DownloadLink: http://rapidshare.com/files/117185415/WH-14.9.SR-5.rar

OR

http://letitbit.net/download/b7c013795956/WH-14.9.SR-5.rar.html

ReCon 2008, Security conference in Montreal, Canada May 24, 2008

Posted by reversengineering in NEWS.
add a comment
Guest speakers:
Ilfak Guilfanov
Michael Strangelove
Other not-so-famous speakers you might know:
TiGa
Woodmann will also be attending.
Slides and videos of the past editions are available too.
Conference Details
The conference will be composed of 30 and 60 minutes talks on a single track, and will have lightning talks during Recon Party.
Guest Speakers
Ilfak Guilfanov – Building plugins for IDA Pro
Michael Strangelove – Hacking Culture
Speakers
Pierre-Marc Bureau – How I learned Reverse Engineering with Storm
Tiller Beauchamp – RE:Trace – Applied Reverse Engineering on OS X
Sharon Conheady and Alex Bayly – Social Engineering for the “Socially Inept”
Bruce Dang – Methods for analyzing malicious Office documents
Sébastien Doucet (TiGa)- 64-bit Imports Rebuilding and Unpacking
Thomas Garnier – Windows privilege escalation through LPC & ALPC interfaces
Cameron Hotchkies – Under the iHood
Eric D. Laspe – The Deobfuscator
Anthony de Almeida Lopes – Bypassing Security Protections by Backdooring libc
Aaron Portnoy and Ali Rizvi-Santiago – Reverse Engineering Dynamic Languages, a Focus on Python
Nicolas Pouvesle – NetWare kernel stack overflow exploitation
Jason Raber – Helikaon Linux Debuger
Gera – TBA
Craig Smith – Creating Code Obfuscation Virtual Machines
Pablo Sole – RE over Adobe Acrobat Reader using Immunity Debugger
Alexander Sotirov – Blackbox Reversing Of XSS Filters
………
TiGa:
Introduction to IDA Pro for OllyDbg users – Sébastien Doucet – IITAC
Summary: This 3-part training focuses on examining the differences between OllyDbg and IDA Pro and using them to your advantage. It is intended for persons who are already familiar with reverse-engineering using OllyDbg or other similar debuggers but have never fully explored the world of IDA Pro.
This training will occur during the 3 lunch breaks. The lunch will be served in the training room.
Prerequisites
edited for some request from tHE mUTABLE

DotNET Dumper 0.2 BETA May 22, 2008

Posted by reversengineering in .NET, TOOLS.
add a comment
DotNET Dumper 0.2 BETA, Dumping tool for executable assemblies
by Kurapica

This is the beta version that can dump all methods on the fly.

1 – Select the executable assembly
2 – Click “Start”
3 – Check the “\Dump” folder in the selected assembly’s folder to see the dumped methods

Download here:

http://letitbit.net/download/49bf7d134261/kdd.rar.html

GUI for IDA sig making May 22, 2008

Posted by reversengineering in OTHER, TOOLS.
1 comment so far

GUI for IDA sig making tools alias <SiDAg>
by Zool@nder

The is a GUI tool that helps beginners making IDA signatures from Obj files/ librarries and PAT files.
You will also find sig files for wwwidgets v2.8.7

GUI for IDA sig making tools alias <SiDAg>
by Zool@nder

The is a GUI tool that helps beginners making IDA signatures from Obj files/ librarries and PAT files.
You will also find sig files for wwwidgets v2.8.7

http://letitbit.net/download/1ec6f7328675/SiDAg-v1.0-by-Zoolander.of.AT4RE.zip.html

FBA V1.5.0 May 22, 2008

Posted by reversengineering in DETECTOR, TOOLS.
add a comment
FBA – analisator exe, scr, dll, sys and others files. He possesses beside unique particularities and possibilities. Gives the recommendations on unpacking of the file. Has 5 built-in plugins. Possesses the most enormous base of the signaturs.History version:
FBA 1.4.0 [10.01.08]
- Added plugin HEX editor
- Is Added detections: mPack(!), Simple Pack, SlvC0deProtector, some cyptors for virus and others
- Is Renewed bases Signs, Unpackinfo and built-in
- Bugfixs
- Other small change

FBA 1.3.0 New Year Edition! [31.12.07]
- Much-plenty of changes
- Is Powerfully renewed Unpackinfo.txt
- Is Added detections on linker and names section
- Are Removed spare, are added new labels from signs.txt
- Is Added generator of the passwords of any length
- Support drag’n'drop
- An Integration in contextual menu
- An Options are now saved in roll, rather then in file
- SM 0.3 -> SM 0.5
- Some inscription(than is packed) at äâîéíîì call are copied in buffer
- Is Added in archive SignMan 1.1 by NEOx
- Are Added in plugins 3 unpackers with the help of ap0x unpack engine Aspack’à 2.12, FSG 2.0, Upx 1.x-2.x + easy scramblers.
- Is Changed design
- UPX ver detector in plugins
- Is Removed check uncared-for mines FBA
- Finally-that FBA detect to FSG 2.0, eXepressor 1.x, WinUpack 0.37-0.39

http://www.fba2008.land.ru/

the info about detection:
- 68 names section
- 18 linker
- 1782 labels packers and protectors
- 66 labels unpackers

 

http://letitbit.net/download/087b35458671/fbaneweng.zip.html

Armageddon v 1.3.2 BY CondZero May 22, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
1 comment so far
May 2008 – v1.3.2
+ hotfix to resolve nanomites
+ relocate base address of Nanolib.dll
===========================================
May 2008 – v1.3.1
+ hotfix to resolve CreateProcess API problem
in Nanolib.dll for target work directory
http://letitbit.net/download/140739459910/Armageddon-v132-by-CondZero.rar.html

Armadillo Crc Finder V1.4 + AoRE Unpacker 0.4 May 19, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
3 comments

v1.4.1 [05/07/08]

- Copy function added
- Some code changed.
http://letitbit.net/download/6ac469151293/ArmaCRC-1.4.1.zip.html
Update*: AoRE Unpacker 0.4

05/18/2008
- IAT’s bug fixed
http://letitbit.net/download/6c6f70619178/AoRE-Unpacker-0.4.rar.html

ArmaGeddon 1.3 May 19, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
add a comment

May 2008 – v1.3
+ resolve relocations for dll files (Nacho_dj)
+ added new option to minimize the size of a dumped file (Nacho_dj)
Particulary useful for Shockwave Flash + applications that make use of an overlay. Of course this will also rebuild a normal target’s PE structure.
+ improved import rebuilder v1.1.2 (Nacho_dj)
+ added new option to “Resolve” nanomite INT3 instructions with their original
jmp instructions and patch directly to the dumped target. Requires use of the nanomite “Analyze” + “Log” options. Note: you can also elect to resolve nanomites directly to a target process’s memory if you elect to detach!!
+ integrated Admiral’s Strategic Code Splicing removal engine into the tool.
This is now the (default) behaviour and can be overridden with new option to
redirect CS (code splices) instead
+ new option to dump / decrypt / decompress the .pdata section to a binary file
+ new option to detach from a process (choose: DebugBlocker or CopyMemII)
+ resolve problem for ArmAccess dll function:Installkey missing error msg
+ add support for UPX compressed single process targets
+ new option to change your Standard / Enhanced Hardware Fingerprint ID
+ resolve some minor bugs
===========================================
March 2008 – v1.2g [gabor edition]
+ add warning message for OEP call return VA not from Armadillo VM
Note: Informational, not usually relevant for dll’s or exe’s with copymem2,
but may be useful for troubleshooting invalid OEP’s resulting
from custom implementations and/or packing / compressing of a file
prior to being protected by Armadillo
+ fix problem with copymem2 search string error
+ fix problem with createdump on error
===========================================
March 2008 – v1.2
+ improved PE section name resolution for internal use (thank’s Ghandi)
+ improved ARTeam Import Reconstructor v1.2
===========================================
February 2008 – v1.1
+ added dll support (dll loader.exe)
+ added option “Use OpenMutext trick” to force a single process. Use only if normal “debug blocker” processing fails. This would occur when a parent process launches the child process, but doesn’t debug the child process (i.e. use the WaitForDebugEvent API)
+ improve IAT elimination functionality
+ includes updated ARTeam Import Reconstructor
===========================================
February 2008 – v1.0 (initial release)
Born – 11/13/2007

http://letitbit.net/download/4fa2c3821802/Armageddon-v13-by-CondZero.rar.html

Aspr2.XX unpacker 1.14a (2008-05-19) May 19, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
5 comments

bug fixed

http://letitbit.net/download/e93da153238/ASPRUnpacker-v1.14aE.rar.html

EXECryptor V 2.4.1 crkd May 19, 2008

Posted by reversengineering in PROTECTOR, TOOLS.
17 comments
new link added 2008/07/07

DownloadLink: http://rapidshare.com/files/127933977/part1.7z
DownloadLink: http://rapidshare.com/files/127934024/part2.7z
DownloadLink: http://rapidshare.com/files/127934374/part2.7z

reversengineering.wordpress.com = pass

pass with http:// or not :) like always

Aspr2.XX unpacker 1.14 (2008-05-17) by Volx May 19, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
add a comment
History
———-

1.00
First release.

1.10
1. Occasionally crash when fixing initialization table of Delphi apps.
2. IAT rebuild for an early version of Asprotect.
3. Add one more crc check pattern.
4. Add one more Asprotect API emulation.

1.11
IAT rebuild is incomplete when the address of the API caller is beyond first section of the app.

1.12
With some version of ODBGscript it occasionally fails to locate the OEP.

1.13
1. With ODBGscript v1.63 or above it fails to fix initialization table of Delphi apps.
2. Support a newer Asprotect whose stolen code type definition is different.

1.14
1. Script runs on ODBGscript v1.64 or above only.
2. Modification of fixing CRC check point.
3. Failed to locate OEP of proggie packed with verison 1.4x
4. Unhide the Asprotect API used in proggie packed with version 1.4x.
5. If std function can’t find a match, they will be copied to .aspr section just like other stolen code.
6. Other bugs fix.

1.2
Add the ability to fix VM code.

**Modification needed before usage**

Copy the Asprvm8s.bin into a folder you want , then use text editor to modify this part of the script

lab78_1:
log VMcodeloc
lm VMcodeloc, 4000, “d:\Asprvm8s.bin” —> modify this line

if Asprvm8s.bin is copied under the folder c:\script the above command should be chnaged as

lm VMcodeloc, 4000, “C:\script\Asprvm8s.bin”

http://letitbit.net/download/83ac71613027/AsprUnpacker-v1.14E-2008-05-17.rar.html

AoRE Unpacker 0.3 May 19, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
add a comment

AoRE Unpacker is for unpacking simple packers, so far it supports the following:

!EP (EXE_Pack) 1.2
ASPack v2.12
AverCryptor 1.0
DexCrypt 2.0
eXPressor 1.2.0/1.3.0.1
MEW_1.1
Molebox 2.2.4
NsPack 2.9/3.0/3.3/3.4/3.6/3.7
PeCompact 1.30/1.50/1.84
UPX 1.25/1.91/2.00/2.01/2.02/2.90/3.00/3.01
and much more

 

http://letitbit.net/download/e65c6755738/AoRE-Unpacker-0.3.rar.html

TheMida/winlicense unpaker 2 by okdodo May 19, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
1 comment so far

http://letitbit.net/download/21f49a561171/tmdunpacker.rar.html

ExeInfo PE ver. 0.0.1.8 G May 17, 2008

Posted by reversengineering in DETECTOR, TOOLS.
add a comment

last update : 2008-05-08

web:http://www.geocities.com/exeinfo_PE/

link:

http://letitbit.net/download/1e4606756407/exeinfope.zip.html

Writing Secure Code May 17, 2008

Posted by reversengineering in E-BOOK.
add a comment

http://rapidshare.com/files/48733389/_MSPress__20Writing_20Secure_20Code.pdf

Software Security Building Security In 2006 May 17, 2008

Posted by reversengineering in E-BOOK.
add a comment

http://rapidshare.com/files/48733383/Addison.Wesley_.Software.Security.Building.Security.In._2006_.BBL.chm

or

http://rapidshare.com/files/48923271/Addison.Wesley_.Software.Security.Building.Security.In._2006_.BBL.chm

OllyICE v1.10 repairs edition correction [2008.1.1] May 17, 2008

Posted by reversengineering in DEBUGGER, TOOLS.
1 comment so far
Renewal history
2008.1.1
1.LOCKLOSE increased part API and the syntagma information:
 1) increased some API recognition;
 2) increases to 290 syntagma & enumeration type;
 3) increases to 2504 API function structure;
 4) has contained the part VB common function, the part VC function, contains the part MSVCRT.DLL function;
2. integrates PhantOm the plugin 1.20 plug-in units (, because this plug-in unit may hide the window, kind of name, therefore repaired the edition correction to cancel the revision which 2007.9.21 did.
Attention: PhantOm.dll is possible and Caba has the conflict, if OD has exceptionally, may temporarily this plug-in unit emigration.
3. revision quick key 2 small bug

2007.9.21
1. revises Themida v1.9.x.x to examine OllyICE Anti, coordinates HideToolz then debugged the Themida v 1.9.3.0 before version’s Canadian shell procedure. Revision process:
 1) following character CPU, alters to the random character, like ICE.
  000B2760 7273 0043 5055 202D 2000 5255 4E20 B8FA rs.CPU – .RUN.
  000B2770 D7D9 2025 692E 20B2 BDBD F825 7320 B7B5. %i. ….%s.
 2) following character OllyICE, alters to the random character.
  000C0890 004F 6C6C 7949 4345 0041 7267 756D 656E .OllyICE.Argumen
  000C08A0 745B 2569 5D00 4172 6775 6D65 6E74 73 t[%i]. Arguments

2. revision quick key’s bug
Instruction:
push 401000
When revision according to Shift+ carriage return key, cannot jump to the code window in 401000 bug
================================================================================
2007.2.16
1. changed a OllyDBG kind of marking, some softwares will examine OD through this (under will be the OllyDBG master routines, 1212121 will be a kind of name).
000B6000 6E69 0049 434F 5F41 4141 4D41 494E 004D ni.ICO_AAAMAIN.M
000B6010 4149 4E4D 454E 5500 3132 3132 3132 3100 AINMENU.1212121.
2. optimized the quick key function related code, has removed small bug.
================================================================================
2006.11.30
cao_cong revised the sinicizing version thread demonstration mistake
(for details sees http://bbs.pediy.com/showthread.php?s=&threadid=35679)
================================================================================
2006.11.16
1. thanks dreaman to repair bug which the Findlabel, Findname, Findnextname three function processing string of character will overflow.
(for details sees: http://bbs.pediy.com/showthread.php?s=&threadid=33102)
2. improves the sprintf function to demonstrate certain floating numbers can collapse bug (above the Themida 1.8.2.0 edition uses this bug Anti-OD), here repair code directly quote heXer code.
(for details sees: http://bbs.pediy.com/showthread.php?s=&threadid=33621)
================================================================================
2006.10.15
Thanks DarkBul to inform SHIFT+F2 condition window demonstration bug and the repair.
when the OD counter-assembly window (or chooses according to SHIFT+F2 right key menu – > break point – > condition) changes the original condition break point, before the establishment condition break point’s dialog box the original condition, will add on a 0×14 byte.
================================================================================
2006.6.21
OllyICE.exe and OLLYDBG.EXE increase the practical quick key function
================================================================================
2006.2.8
1. cao_cong revised some sinicizing mistake.
2. Increases the binary duplication/binary system glue function for Ollydbg, the corresponding quick key is:
Ctrl+Shift+C binary system duplication
The Ctrl+Shift+V binary system sticks
================================================================================
2006.2.11
cao_cong revised some sinicizing mistake:
Originally several translators to not be able to guarantee that bug, used the blank space to fill guarantees the string position. Today, because detected demonstrated when the menu adds the blank space to be quite ugly, original sinicizing partial content restoration
For English, Chinese menu does transfers sinicizing, causes in the menu Chinese to demonstrate that looks like the comfortable spot.

Quick key order
In these quick key order first edition OllyDBG does not have, is OllyICE add-on comes up, believed that can enhance the operation greatly the conveniences.
1). Binary duplication/glue quick key
Counter-assembly window: Shift+C/Shift+V
Data window: Shift+C/Shift+V
Attention: When data window, Shift+V, does not need to choose the block size, will cut the plywood the data to glue completely.
2). Examines the data
push A480033 //, if presses the carriage return key, then in the data window demonstrates a480033 data, this line according to the Shift+ carriage return key, then jumps to a480033 address;
mov eax,401000 // this line presses the carriage return, then in the data window demonstrates 401000 data
mov eax,[401000] // this line presses the carriage return, then in the data window demonstrates 401000 data
mov [ebp-4], esp // this line presses the carriage return, then in the data window demonstrated that ebp-4 the value (pays attention to EIP to aim at current line)
mov eax, [esp+10]//this line presses the carriage return, then in the data window demonstrated that esp+10 the value (pays attention to EIP to aim at current line)
3). The data window examined that the data (originates from heXer)
Data window:
00406000 00 10 40 00 00 00 00 00 00 00 00 00 CA 2E 40 00. @ ………? @.
^
The cursor transfers to “00 10 40 00” first byte 00, according to the carriage return, the counter-assembly window demonstrates 401000; The Shift+ carriage return, the data window demonstrates 401000
4). The storehouse window (originates from heXer)
0012FF44 the 00401D8A // presses the carriage return, the counter-assembly window demonstrates 0401D8A; The Shift+ carriage return, the data window demonstrates 0401D8A
0012FF48 00000000
5). Data window selecting data demonstration
When cursor when data window migration, will demonstrate the cursor start address, the end address, as well as selected block size.
6). The data window cuts the code window
00406000 00 12 40 00 00 00 00 00 00 00 00 00 CA 2E 40 00. @ ………? @.
^
The cursor transfers to “00 12 40 00” first byte 00, according to Ctrl+ double click mouse, then the counter-assembly window demonstrated 00401200 start code
7). The counter-assembly window or the data window take the current address
Quick key: ctrl+X
For example:
004091C0 push ebp
004091C1 mov ebp, esp
004091C3 push -1 // this line presses quick key ctrl+X, duplicates address 004091C3 cuts in the plywood
Data window similar operation.
0040DD40 55 8B EC 83 EC 08 53 56 57 55 FC 8B 5D 0C 8B 45 U
The quick key order increases: kanxue
Thanks help which and prompt heXer, CoDe_Inject gives!

IntroductionOllyICE.EXE and OLLYDBG.EXE have simultaneously made the following revision:
1. window, kind of name and so on common revision;
2. formatted string of character crack [OutPutDebugString] patch;
3. refers to dyk158 ODbyDYK v1.10, disposes UDD, PLUGIN is the absolute way automatically;
4. refers to nbw ” OD to duplicate the BUG analysis and the revision ” an article, when revises from the memory area duplication data, sometimes will be unable all data to duplicate clipboard’s bug.
5. refers to ohuangkeo “not one of by OD analysis reasons and the patching method”, improved OD to distinguish the PE form ability slightly (possibly still to report the right and wrong PE document, but oneself might debug).
6. revises question which OllyScript.dll the plug-in unit bpwm order memory read-write interrupts.
7.jingulong Loaddll.exe, may facilitate lets OllDbg interrupt in the dll entrance.
8. thanks DarkBul to inform SHIFT+F2 condition window demonstration bug and the repair.
9. thanks dreaman to repair bug which the Findlabel, Findname, Findnextname three function processing string of character will overflow.
10. improves the sprintf function to demonstrate certain floating numbers can collapse bug, here repair code directly quote heXer code.
11. should repair the edition correction, coordinates the HideOD plug-in unit, may hide OD well.
12. additional practical quick key function
13.LOCKLOSE increased part API and the syntagma information

Attention: Hides OD tool HideToolz, compresses Bao Liji to provide, table of contents: \ tools \ HideToolz \ HideToolz.exe
The HideToolz use matters needing attention see OllyICE.chm.

Looks at the snow institute
Watches the snow software security forum

http://www.pediy.com

http; //bbs.pediy.com

http://rapidshare.com/files/115550173/OllyICE_2008.1.1.7z
or
http://letitbit.net/download/b2ab7b731783/OllyICE-2008.1.1.rar.html
pass:reversengineering.wordpress.com

AT4RE FastScanner Version 1.0 May 17, 2008

Posted by reversengineering in DETECTOR, TOOLS.
add a comment
AT4RE FastScanner Version 1.0

Yet another Win32 PE Packer/Protector Identifier

[ Features ]

- Detect About 2017 Signatures in PE Files.
- Easy & Amazing & Fast GUI .
- Drag and drop Capabilities.
- Shell integration .
- Signatures Update by user , and notify after 3 month if Signatures file hasn’t updated.
- Special Plugins by AT4RE , ‘ AT4RE PE Editor’ , …
- PEID Plugins Supported , just copy them to plugins directory.
- Full Package Contains most needed plugins .

Download FastScanner Full (with almost all PEiD plugins)

www.at4re.com/tools/Releases/at4re/AT4RE_FastScanner_v1.0_Full.rar
or
http://letitbit.net/download/5e4033621773/AT4RE-FastScanner-v1.0-Full.rar.html
or
http://rapidshare.com/files/115549089/AT4RE_FastScanner_v1.0_Full.rar
Download FastScanner Lite (with only 3 plugins)
www.at4re.com/tools/Releases/at4re/AT4RE_FastScanner_v1.0_Lite.rar
or
http://letitbit.net/download/2f3bb2988263/AT4RE-FastScanner-v1.0-Lite.rar.html
or
http://rapidshare.com/files/115549076/AT4RE_FastScanner_v1.0_Lite.rar

ImpREC Plugin Pack 2008 May 17, 2008

Posted by reversengineering in OTHER, TOOLS.
2 comments

 pack containing a big bunch of plugins for ImpREC.

It also contains source code for many of these plugins, for most common programming languages/compilers (VC++/Delphi/MASM/TASM). This source code is of course good for use as template code for new plugins.

It contains the following plugins WITH source:

ASProtect 1.2x
eXcalibur 1.x
Morphine 3.3
Perplex 1.01
PESpin 1.3.04
RLPack 0.7
tELock 0.92x
Yoda 1.02

It contains the following plugins WITHOUT source:

ACProtect #1.dll
ACProtect #2.dll
ACProtect #3.dll
Alex Protector.dll
Armadillo 2.6.dll
ASProtect 1.22.dll
ASProtect 1.23 rc4.dll
ASProtect 1.2x Emul API #1.dll
ASProtect 1.2x Emul API #2.dll
ASProtect 1.2x.dll
ASProtect 1.3.dll
ASProtect 2.xx.dll
CoolCrypt.dll
Cryptocrack’s PE Protector.dll
Excalibur.dll
ExeCryptor.dll
EXEStealth275.dll
Expressor 1.5.x.dll
ExtOverlay.dll
GoatsPEMutilator16.dll
HowTo.txt
Krypton 0.4 – 0.5 #1.dll
Krypton 0.4 – 0.5 #2.dll
Krypton 0.5.dll
Morphine.dll
NTKrnl Protector 0.1.x.dll
Null.dll
Obsidium #1.dll
Obsidium #2.dll
Obsidium #3.dll
Obsidium 1.3.dll
Obsidium 1.3.dll.txt
PE123.dll
PECompact 2.7.x.dll
PELock 1.06 (regged).dll
PELock 1.06 (regged).dll.txt
PELock 1.0x.dll
Perplex101.dll
PESpin.dll
PESpinPlugin.dll
Plugin.txt
PrivateExeProtector 1.8.dll
PrivateExeProtector 1.8.txt
Privilege.dll
Protection Plus 4.x.dll
RLPack 0.7.dll
RLPack 0.7.x.dll
RLPack 0.x.dll
RLPack 1.16.dll
RLPack 1.18.dll
SDProtector 1.12.dll
SVK Protector #1.dll
SVK Protector #2.dll
tELock 0.71.dll
tELock 0.92.dll
tELock 0.98 #1.dll
tELock 0.98 #2.dll
tELock 0.98 #3.dll
tELock 0.98 #4.dll
tELock 0.98 #5.dll
tELock 0.99.dll
tELock 0.9x.dll
TPP.dll
VisualProtect.dll
Yoda Crypter 1.02.dll

link:

http://letitbit.net/download/95e987964567/ImpREC-Plugin-Pack-2008-2-23.7z.html

Ollydbg 867 scripts or update 149 scripts May 17, 2008

Posted by reversengineering in Scripts, TOOLS.
6 comments
hi
new collection
if u dl  “Ollydbg 712 scripts 2007-8-9 ” u need to dl “update-149″file  only  ,but if u want all dl “Ollydbg-867″.
http://letitbit.net/download/02a267776572/update-149-scripts-2008-5-17.exe.html
or
http://rapidshare.com/files/115535528/update_149_scripts_2008-5-17.exe
http://letitbit.net/download/eccef3293138/Ollydbg-867-scripts-2008-05-17.exe.html
or
http://rapidshare.com/files/115535728/Ollydbg_867_scripts_2008-05-17.exe
pass:reversengineering.wordpress.com

TRIAL RESET 3.3 final reup May 17, 2008

Posted by reversengineering in OTHER, TOOLS.
2 comments

hi

i check this file by  NOD32 (3096 sign.) and its clear.

http://letitbit.net/download/48ed30958644/TRIAL–RESET-3.3-final-reup-.rar.html

p:reversengineering.wordpress.com

Asprotect ske 2.41.build.02.26 May 17, 2008

Posted by reversengineering in PROTECTOR, TOOLS.
1 comment so far
hi
thanx fly out to REVENGE Crew  team for this rlz  its 3000th.release of them
hav phun ;)
http://rapidshare.com/files/115509433/asprotect.ske.2.41.build.02.26.beta.retail.incl.keygen.RAR
or
http://letitbit.net/download/72eb1d479524/asprotect.ske.2.41.build.02.26.beta.retail.incl.keygen.RAR.html
 i recomend firfox and flashgot addon for dl fast;)
pass:reversengineering.wordpress.com

Phoenix Protector 1.1.0.1 May 17, 2008

Posted by reversengineering in .NET, TOOLS.
1 comment so far

for dotNet

http://letitbit.net/download/608376380901/Phoenix-Protector-1.1.0.1.rar.html

Reversing Secrets of Reverse Engineering May 15, 2008

Posted by reversengineering in E-BOOK.
2 comments

h

DownloadLink:

http://rapidshare.com/files/115061334/wReversing_Secrets_of_Reverse_Engineering.part1.rar

http://rapidshare.com/files/115061080/wReversing_Secrets_of_Reverse_Engineering.part2.rar

pass:http://reversengineering.wordpress.com

Professional Assembly Language May 15, 2008

Posted by reversengineering in E-BOOK.
add a comment

nullDownloadLink: http://rapidshare.com/files/115058901/Professional.Assembly.Language.rar
pass:http://reversengineering.wordpress.com

Follow

Get every new post delivered to your Inbox.

Join 35 other followers