View previous topic :: View next topic |
Author |
Message |
Tr1gun87 Cheater
Reputation: 0
Joined: 17 May 2017 Posts: 27
|
|
Back to top |
|
 |
Csimbi I post too much
Reputation: 97
Joined: 14 Jul 2007 Posts: 3312
|
Posted: Tue Aug 25, 2020 7:48 am Post subject: |
|
|
Some based offset seems to come from the stack: EPB+08.
The, base+14 is read.
Did you check what's the base and where's that base coming from?
|
|
Back to top |
|
 |
Tr1gun87 Cheater
Reputation: 0
Joined: 17 May 2017 Posts: 27
|
Posted: Tue Aug 25, 2020 8:21 am Post subject: |
|
|
on the link there is the export of the trace
i don't see anything...
i saw ebp = starting position of the stack at the start of the call, so maybe ebp+8 is the esi value?
i noticed now the trace and the image come from 2 different sessions
the select line of the img is line 9263 on the trace file
184AFA8E - lea esp,[ebp-08]
|
|
Back to top |
|
 |
|