Editing Dumping Metldr
Jump to navigation
Jump to search
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then publish the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 146: | Line 146: | ||
dump shared lsa (located at 0x3E000 in ls)<br> | dump shared lsa (located at 0x3E000 in ls)<br> | ||
and keep increasing 0x2000<br> | and keep increasing 0x2000<br> | ||
until somewhere in the shared lsa | until somewhere in the shared lsa 0x40 byte change<br> | ||
2) when it changes 0x40 bytes, you can add/subtract the proper amount to make it decrypt the proper locations<br> | 2) when it changes 0x40 bytes, you can add/subtract the proper amount to make it decrypt the proper locations<br> | ||
3) then dump the shared lsa and you have a decrypted header<br> | 3) then dump the shared lsa and you have a decrypted header<br> |