FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

IDouble/Simple-Disassembly-Notes: โš™๏ธ Simple Step to Step Tutorials for Disassembling / Code Injection & getting Pointer Addresses ๐Ÿ”ง ยท GitHub

Latest commit

ย 

History

99 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

โš™๏ธ Simple Disassembly Notes ๐Ÿ”ง

โš™๏ธ Simple Step to Step Tutorials for Disassembling / Code Injection & getting Pointer Addresses ๐Ÿ”ง

๐Ÿ”ง Get Pointer Address from Value ๐Ÿ”ง

  1. Set Value Type All
  2. Set Value (ex. (Int 32 = 4 Byte = 32 Bit) 85 or (float/double) 85.5) you search for and press First Scan

  1. Change Value in the Process
  2. The Changed Value will be red, on the left is the Pointer Address

๐Ÿ”ง Replace the Assembly Code with Code that does Nothing ๐Ÿ”ง

  1. Right Click on Address Record
  2. Select Find out what writes to this address
  3. Press on Replace

  1. Delete the Assembly Code and Press OK

๐Ÿ” Get the Pointer Address from the Pointer of the Value (Way 1 : easier) (level-1 pointer) ๐Ÿ”

  1. Read the Address

  1. Check Checkbox Hex and put the Address in it
  2. The Address to the Pointer is in this ex. 1002CBA40

๐Ÿ” Get the Pointer Address from the Pointer of the Value (Way 2 : harder) (level-1 pointer) ๐Ÿ”

  1. Select Find out what writes to this address
  2. Press on More information

  1. The Address to the Pointer is in this ex. 011DC7A0

๐Ÿ” Get the base Address from a multilevel pointer (level-4 pointer) ๐Ÿ”

โžก๏ธ Example of a level-4 pointer โžก๏ธ

01168A78 = Address / base pointer (base ptr)

0x18 = Offset

"Tutorial-x86_64.exe" + 2CBA70 = static base address

-> = points to

01168A78 = Value = 2765

01188070 -> 1168A60 + 0x18 = 01168A78

01168A18 -> 01188070 + 0 = 01188070

011681D0 -> 1168A00 + 0x18 = 01168A18

"Tutorial-x86_64.exe" + 2CBA70 -> 11681C0 + 0x10 = 011681D0

๐Ÿ” How to find out each base pointer with its offsets until you get to the static base address ๐Ÿ”

  1. Right Click on Address Record
  2. Select Find out what accesses this address

  1. Calculate the Address using the Offset ex. -> (01188070 -> 1168A60 + 0x18 = 01168A78)
    Calculation (hex) : (01168A78 - 18 = 01168A60 = 1168A60)
  2. Check Checkbox Hex and put the Address in it (ex. 1168A60)
  3. The Address to the Pointer is in this ex. 01188070
  4. Repeat Step 1 to 5 until you get the static base Address, in this ex. "Tutorial-x86_64.exe" + 2CBA70

โš™๏ธ Add Pointer Address manually (level-1 pointer) โš™๏ธ

  1. Click on Add Address Manually

  1. Add Address, if needed with Offsets and click OK

  1. The Result should look like this:

โš™๏ธ Add Pointer Address manually (level-4 pointer) โš™๏ธ

  1. Click on Add Address Manually

  1. Add Address, if needed with Offsets and click OK

  1. The Result should look like this:

๐Ÿ›  Code Injection ๐Ÿ› 

  1. Right Click on Address Record
  2. Select Find out what writes to this address
  3. Press Show disassembler

  1. Click on Tools and select Auto Assemble

  1. Click on Template and select Code Injection

  1. Click on OK
  2. Comment out as an ex. //sub dword ptr [rsi+00000780],01 (value - 1)
  3. Write as an ex. add dword ptr [rsi+00000780],01 (value + 1)

  1. Press on Execute and then click OK and it's Done!

About

โš™๏ธ Simple Step to Step Tutorials for Disassembling / Code Injection & getting Pointer Addresses ๐Ÿ”ง

Topics

Resources

Stars

64 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages


Back | FazBrowse Home | New Git URL