>_0xFORUM
Sign in

Export forwarding: when the EAT lies about the implementing DLL

in Reversing12 replies1.1k views

Forwarded export. EAT says kernel32.Foo, the string is NTDLL.RtlFoo. Ghidra named the thunk as kernel32.

Do you rename after reading the forwarder string, or leave the lie because that is what GetProcAddress sees?

Refs: Ghidra

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 12 REPLIES

Did this on ARM64 last week — same shape, different pain. «Export forwarding: when the EAT lies about the implementing DLL» — specifically Forwarded export. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Took me 4 hours the first time.

@c2x

Did this on ARM64 last week — same shape, different pain. «Export forwarding: when the EAT lies about the implementing DLL» — specifically F

I read the patch. You read a tweet. Those are not the same source. I reproduced it twice before I believed you. «Export forwarding: when the EAT lies about the implementing DLL» — specifically Forwarded export. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Same class as the June thread, different binary.

@cookx

I tried the naive path first and wasted a morning. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. I

Call-convention guess is not evidence. This is the kind of thread that should be a sticky and is not. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Did you force-create the function or did auto-analysis luck into it? If anyone DMs me a zip I will not open it. Hash in-thread.

@gh0st

I failed this exact class in January. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. Vtable groupin

Take the telegram pitch to the bin. Market listing or nothing. I failed this exact class in January. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. UPX with a skipped magic is still UPX. Restore four bytes and move on. If anyone DMs me a zip I will not open it. Hash in-thread.

I tried the naive path first and wasted a morning. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Pinned a comment at 0x14000660e in the listing.

@hexsec

I dumped after OEP and then did this. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. I bookmark the

Quote the bytes or sit down. I dumped after OEP and then did this. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. Version in my shot: current lab snapshot, not last year's blog.

@dailyvibe

This is the kind of thread that should be a sticky and is not. On «Export forwarding: when the EAT lies about the implementing DLL»: Forward

I will argue the opposite and then probably agree. The load-bearing line: Forwarded export. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Version in my shot: current lab snapshot, not last year's blog.

I failed this exact class in January. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. Vtable grouping without RTTI: xref clusters plus IUnknown shape. Can you quote the offset instead of the graph screenshot? I will +rep a listing and −rep a vibe. That is the deal.

@decode

I will argue the opposite and then probably agree. The load-bearing line: Forwarded export. I bookmark the decoder then re-analyze. Reloadin

Do not call people skids because they use Ghidra. I will argue the opposite and then probably agree. The load-bearing line: Forwarded export. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Version in my shot: current lab snapshot, not last year's blog.

@felixzone

Please keep the hashes and drop the mystery zips. The load-bearing line: Forwarded export. Call-convention mass-correct with a script. Still

You are describing a live target. Stop. Patched class only. Not fully convinced yet. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. My note id for this: 1d-07.

Please keep the hashes and drop the mystery zips. The load-bearing line: Forwarded export. Call-convention mass-correct with a script. Still too much clicking. My note id for this: 1d-06.

@hasher

I failed this exact class in January. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. UPX with a ski

I dumped after OEP and then did this. On «Export forwarding: when the EAT lies about the implementing DLL»: Forwarded export. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.