Find me faster !
Author: Aymen Borgi
rev100.zip
Starting to open our executable file on IDA:
There is some weird shit going around but we can see a function i_am_debugged() which leads you to exit the program if you running the program on a debugger like gdb or even IDA, there is alot of calls as you can see in the assembly code I could run the debugger and change those registers to not jump out of the program but since there was alot of calls I chose to do it in another way.
After a while I found this “loop” in the assembly code we can see they are just xoring two strange strings, variable “a” and variable “b” and then saving it on variable “c”.
Now we just need to find those “a” and “b” initial values and convert this assembly into python.
Finding “a” and “b” values is easy we can use IDA to do that:
Now we just write a python script equivalent to this assembly (Notice that wrote the strings in python as hex bytes because some characters weren’t pritable):
1 |
|
Running the script:
1 |
|