downloadbrowseThe Binary Auditor's The Binary Auditor™ - File Format Exercise

Download File_Format_Exercise.zip, 4 kb (password: crackmes.de)
Browse contents of File_Format_Exercise.zip

Crudd's Forward Me

Well, here's my newest reverse me. Actually, its kinda reversed already. Guess whut that means you have to do. Thats right, put it all together and make a working PE file. It shouldnt be too hard for seasoned reversers and will be a good learnig experience for the rest of us.

Things you'll need to do:
Add/Create the Dos Stub/PE Header
Figure out which section is which
Put it all together, and make it run

Crackme designed by Crudd

Difficulty: 2 - Needs a little brain (or luck)
Platform: The Binary Auditor
Language: Assembler

Published: 21. Aug, 2010
Downloads: 329

Rating

Votes: 3
Crackme is good.

Rate this crackme:

Send a message to The Binary Auditor »

View profile of The Binary Auditor »

Solutions

Solution by tomkol, published 31. aug, 2013; download (51 kb), password: crackmes.de or browse.

tomkol has rated this crackme as awesome.

Solution by sghctoma, published 10. sep, 2010; download (17 kb), password: crackmes.de or browse.

sghctoma has not rated this crackme yet.

Solution by onepatop, published 23. sep, 2010; download (1046 kb), password: crackmes.de or browse.

onepatop has not rated this crackme yet.

Submit your solution »

Discussion and comments

freesoul
22. Aug 2010
As a hint: have careful with the data section... which is it's real RVA? :P
You can find 00 20 40 00 at the start of it.. but if you study a bit the code section you can find:

00401400 |. 6A 00 PUSH 0
00401402 |. 68 38304000 PUSH Loader_B.00403038 ; <- :O
00401407 |. FF75 F4 PUSH DWORD PTR SS:[EBP-C]
0040140A |. FF75 08 PUSH DWORD PTR SS:[EBP+8]
0040140D |. E8 FA000000 CALL Loader_B.0040150C
00401412 |> 5F POP EDI

which look a messagebox call :P
The Binary Auditor
Author
24. Aug 2010
Please do not give do many hints ;) Let people struggle with it :)

You may leave your comment, thoughts and discuss this crackme with other reversers here.
Acting childish will not be tolerated.
HTML and such will be left as-is, so don't try.