Using OllyDBG to find a string in a small ".exe" software and change it before sending the HTTP request.
$10-30 USD
Avslutat
Publicerad över fem år sedan
$10-30 USD
Betalning vid leverans
I have a small ".exe" file, I need to change the HTTP request below before it sends out:
"GET /[login to view URL] HTTP/1.1
Content-Type: text/html
Host: [login to view URL]
Accept: text/html, */*
User-Agent: Mozilla/3.0 (compatible; Indy Library)"
I use OllyDBG to check the code of this ".exe". file, my goal is changing that IP address string "[login to view URL]" to " to "[login to view URL]"
It seems the code in this ".exe" software lead me into an infinite cycle when I trying to use F8(Step over.) to check the code step by step. I have found that HTTP request in "Registers Window" (ESI 00168020) before sending the HTTP request, but I don't know when it is being stored. I have attempted to set a "memory breakpoint" on that memory address "00168020", but I can't find that address in the "Memory Dump Window" before the infinite cycle.
You may need the software below to test this ".exe" file:
Windows XP virtual machine (test this ".exe" file)
Linux virtual machine(set the IP address to "[login to view URL]" to receive the HTTP request.)
OllyDBG(install it in the Windows XP virtual machine) - I can provide this
Smsniff(install it in the Windows XP virtual machine) - I can provide this
PEiD(install it in the Windows XP virtual machine) - I can provide this
Hello,
I know some ways to solve such problems.
I am not ready to deal with it, if the task requires serious effort, I am busy with another jobs.
But I wish to have a quick look. Should be nice to get the mentioned exe.
Best regards,
Maris
Hello Zheng,
It sounds like an interesting challenge and very good fit. I have great experience with reverse engineering, so it will be done in a very professional way.
Please let me know more about your .EXE file and when you are OK to discuss. Thank you.
Best regards,
-Mike
Hello there ^_^ I'm delphi software developer ^^ well I used to deal with delphi since version 7 till the current one for now 10.2.3 Tokyo , well I used to deal with both VCL and FMX , regarding to your issue yes as you mentioned we will sue OllyDbg and a recosntructor to generate a Map File to help us while tracing the code to do the modification , the IP adress could be hardcoded or simply saved as integer value or saved in the resource ^^
anyway just give me the green light and I will do my best ^^
best regards