Location:
Search - yoda
Search list
Description: This a simple compressor based on aplib, yoda s Kernel code, and my own
stuffing around. It only has one function with MANY limitations at the moment,
but it is desinged for demo purposes only so it don t matter.
Platform: |
Size: 24986 |
Author: gogo |
Hits:
Description: 原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码
Platform: |
Size: 458407 |
Author: 东南 |
Hits:
Description: 原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码
Platform: |
Size: 457170 |
Author: 东南 |
Hits:
Description: yoda s Crypter 1.2 程序及源码 yoda PE加密保护,Win32ASM源码。 -Yoda s Crypter 1.2 procedures and source Yoda PE encryption protection, Win32ASM source.
Platform: |
Size: 25048 |
Author: waterwhu |
Hits:
Description: yoda s Crypter 1.2 程序及源码 yoda PE加密保护,Win32ASM源码。 -Yoda s Crypter 1.2 procedures and source Yoda PE encryption protection, Win32ASM source.
Platform: |
Size: 24576 |
Author: waterwhu |
Hits:
Description: This a simple compressor based on aplib, yoda s Kernel code, and my own
stuffing around. It only has one function with MANY limitations at the moment,
but it is desinged for demo purposes only so it don t matter.
-This a simple compressor based on aplib, yoda s Kernel code, and my ownstuffing around. It only has one function with MANY limitations at the moment, but it is desinged for demo purposes only so it don t matter.
Platform: |
Size: 24576 |
Author: gogo |
Hits:
Description: 原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码-Principle: The Pe documents. Data section,. Text section to XOR encryption, and then will take declassified documents Loader write head and the first between the beginning of paragraph, modify Entry Point to point Loader. Test cases: the use of vc6. 0 automatically generated mfc dialog application. References: (1) def source (2) debug technology hackers Secret (3) yoda s protector source
Platform: |
Size: 457728 |
Author: 东南 |
Hits:
Description: 原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码-Principle: The Pe documents. Data section,. Text section to XOR encryption, and then will take declassified documents Loader write head and the first between the beginning of paragraph, modify Entry Point to point Loader. Test cases: the use of vc6. 0 automatically generated mfc dialog application. References: (1) def source (2) debug technology hackers Secret (3) yoda s protector source
Platform: |
Size: 456704 |
Author: 东南 |
Hits:
Description: PE加密保护,Win32ASM源码。
作者yoda-PE encryption protection, Win32ASM source. Author yoda ..
Platform: |
Size: 24576 |
Author: Laona |
Hits:
Description: 著名牛人yoda写了个16进程编辑的dll,这个是delphi调用dll以16进制打开文件的代码-Yoda wrote a well-known cattle were 16-process editing dll, this is a delphi call dll in order to open the file 16 hex code
Platform: |
Size: 18432 |
Author: 9908006 |
Hits:
Description: A decrypter for Yoda s Crypter from version 1.0 to version 1.3
Platform: |
Size: 15360 |
Author: bigboss62 |
Hits:
Description: 加壳机(vc源码)源码在vc7+xp-sp2下编译通过
原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码
存在问题:只对.data节,.text节加密,且其中不能包含Resource,Import Table.....等结构,通用性很差
下图为测试用例的section table和directory table。 工具打包源码。加壳机
试用例.
加壳机源码.
加壳机静态mfc
-Packers machine (vc source) source in vc7+ xp-sp2 compiled by Principle: The Pe file. Data section,. Text section to XOR encryption, decryption of the Loader and then written to a file with the first and the beginning of a paragraph between the modified Entry Point to point Loader. test case: automatically generated using vc6.0 mfc dialog application. References: (1) def source (2) hackers debug Uncovered (3) yoda' s protector Source problem: only. Data section,. Text section of encryption, and which can not contain Resource, Import Table ..... structure of , generic photo shows poor test case under the section table and directory table. Tool Package source. Packers machine trial cases. Packers machine source. Packers machine static mfc
Platform: |
Size: 497664 |
Author: 程光 |
Hits:
Description: yoda s shell.玩壳的朋友不会不知道吧。1.01的源码,很老了-yoda' s shell. Play Shell' s friends would not know. 1.01 source code, very old
Platform: |
Size: 98304 |
Author: cai |
Hits:
Description: With yoda s ExeJoiner you can combine two windows portable executable files into one.
It also allows to set the icon file for the new binded exe.
Platform: |
Size: 10240 |
Author: ColdFusion |
Hits:
Description: 非常好用的加壳程序,采用yoda‘s protection加壳-Very easy to use packers, packers use yoda' s protection
Platform: |
Size: 1024 |
Author: cc |
Hits:
Description: hello world和I Am Yoda两个字符串的排列组合,分两步来移动他们的顺序,然后按照ASCII码来排序。 -hello world and I Am Yoda permutations and combinations of the two strings, two steps to the order in which they are moving, and then sorted according to the ASCII code.
Platform: |
Size: 6144 |
Author: 韩玉敏 |
Hits:
Description: WSUnpacker是一个“通用”脱壳机,之所以在通用前面添加了双引号是因为目前的通用脱壳引擎能力很有限,只能脱压缩壳-目前带有的脱壳函数:
aspack
bjfnt
dxpack
fsg
nspack
pecompact
pepack
upx
winupack
yoda s Cryptor
yoda s protector
petite 2.2- 2.3
telock 0.8x- 0.9x
acprotect 1.41- 2.1x
asprotect 1.3x- 2.4x
rlpack 1.21 full edition
pespin 1.32
Platform: |
Size: 377856 |
Author: whwei |
Hits:
Description: developer Yoda shows a method of how to modify Visual C++ linker options (within source file) to create the smallest executables
Platform: |
Size: 3072 |
Author: cfbs_alias |
Hits:
Description: developer Yoda shows how one could hide a process on Windows based operation systems task viewers like ProcDump or ProcessExplorer (SysInternals). It could e.g. be used as some kind of dump protection. Supports NT and Win9x-developer Yoda shows how one could hide a process on Windows based operation systems task viewers like ProcDump or ProcessExplorer (SysInternals). It could e.g. be used as some kind of dump protection. Supports NT and Win9x
Platform: |
Size: 38912 |
Author: cfbs_alias |
Hits: