Dumping a Dynamic Link Library [.DLL]
Howdy MPGH.
I'm Here to Introduce you to Dumping, a Simple Dynamic Link Library.
I'll be Going into as Much Depth, as Possible.
1.) Files
Firstly We'll be Making a "WIN32 Console Application"
New > Project > WIN32 Console Application > Enter a Project Name
After that You'll be Presented with a New Window in the C++ Client.
Application Setting(s) > Empty Project
Now, Right Click your Project Name, and Press "Add".
Proceed by Clicking the ".cpp", and Give it a Name, (ie: "Main.cpp")
I'll Comment, and Break this Code down via Comments (//) for Everyone to Understand.
Highly Commented Code
Now, Let's Proceed and Compile it.
Proceed to Compile it in "Release Mode".
Then Close Down C++ (Optional), And Proceed to Going via the Default C++ Projects Directory.
The Location of the WIN32 Console Application will Appear Here.
"\Documents\Visual Studio 2008\Projects\myProjectName\Release\"
Grab the Executable File, that we Created within the C++ Client,
Now Place the Program Next to the Dynamic Link Library File you wish To "Execute"
And Rename the Dynamic Link Library you wish to "Dump", to "myFile.dll".
Lets, Open our Fresh Copy of Our WIN32 Program.
Now, We've Got our Program Up and Running, if it has Loaded the Dynamic Link Library You'll Receive a Message, "LoadLibraryA: Loaded a File, It's now Ready for a Dump."
Now, Open up your Favourite Dumping Program, if You Dont Really have a Favourite.
I'd Strongly Recommend OllyDbg, as well as Using the Plugin "PEDumper.dll", Google the Plugins, as i Dont Feel I'm in the Position to Provide a an Offsite Link (If this is Anything like UC)
After You've Opened OllyDbg Attach it to our Dyanmic Link Libary "myFile.exe"
Unless You've Renamed it in C++ Client.
Now, We'll Proceed to Dumping the File, In OllyDbg, Press "File > Attach"
Click on the Program, in my Case it's "myLoader",
Then at the Top, Press "Plugins", and Then, Click "OllyDbg PE Dumper > Dump a Process"
Under "Pick a Module (Drop Down Box within the OllyDbg PE Dumper Window",
Press and Look for your Dynamic Link Libary, in our Case/Mine it's "myFile.dll"
Press Dump, and the File will Dump, Save the File as a .DLL (Dynamic Link Library).
Now You've Successfully made a Dump of a Dynamic Link Library,
Congratulations, Give your Self a Pat on the Back
Thank you for Reading/Studying this and Hopefully You've Learnt atleast Somthing :P
Keep a Eye out from More Tutorails from Me / Bases / Code Snippets / Bypasses.
Please Contribute & Ask Questions, I'd be More then Welcome to Help, and Give some Constructive Criticism.
Credits,
kJNR
MSDN
Cheers,
kJNR
I'm Here to Introduce you to Dumping, a Simple Dynamic Link Library.
I'll be Going into as Much Depth, as Possible.
1.) Files
- Dynamic Link Library Loader (Included)
- Visual C++
- Min - Basic C++/C# Knowledge
Firstly We'll be Making a "WIN32 Console Application"
New > Project > WIN32 Console Application > Enter a Project Name
After that You'll be Presented with a New Window in the C++ Client.
Application Setting(s) > Empty Project
Now, Right Click your Project Name, and Press "Add".
Proceed by Clicking the ".cpp", and Give it a Name, (ie: "Main.cpp")
I'll Comment, and Break this Code down via Comments (//) for Everyone to Understand.
Highly Commented Code
Code:
#include "Windows.h" //Include a File from our Headers Libary, Called "Windows.h".
#include <Iostream> //Include a File from our Headers Libary, Called "Iostream".
int kJNRDumper() //Define our Function with a Simple Integer as a Main Body
{
DWORD Error; //Create a DWORD with the Name "Error"
HINSTANCE kDynamicLinkLibary = LoadLibraryA("myFile.dll");//Allow our Variable to Hold the LoadLibraryA, for Easy Programming.
if(kDynamicLinkLibary != 0)//If Our Variable "kDynamicLinkLibary" That Hold Our LoadLibraryA Function Open our "myFile.dll"
{
printf("LoadLibraryA: Loaded a File, It's now Ready for a Dump."); //Print Some Text in our WIN32 Console Application that the Libary has Loaded.
}
else //Else if it Diden't LoadLibraryA (ie. Coulden't Find "myFile.dll", GetLastError, and Print a Message to our WIN32 Console Application that the Libary has Failed.
{
Error = GetLastError(); //Our DWORD Will Hold the Function "GetLastError();" -> MSDN it, to Learn About it.
printf("LoadLibraryA: Can't load the File, Terminating Process\n"); //Print Some Text in our WIN32 Console Application that the Library has Failed to Load the Library.
}
system("pause");
return 0;
}
Proceed to Compile it in "Release Mode".
Then Close Down C++ (Optional), And Proceed to Going via the Default C++ Projects Directory.
The Location of the WIN32 Console Application will Appear Here.
"\Documents\Visual Studio 2008\Projects\myProjectName\Release\"
Grab the Executable File, that we Created within the C++ Client,
Now Place the Program Next to the Dynamic Link Library File you wish To "Execute"
And Rename the Dynamic Link Library you wish to "Dump", to "myFile.dll".
Lets, Open our Fresh Copy of Our WIN32 Program.
Now, We've Got our Program Up and Running, if it has Loaded the Dynamic Link Library You'll Receive a Message, "LoadLibraryA: Loaded a File, It's now Ready for a Dump."
Now, Open up your Favourite Dumping Program, if You Dont Really have a Favourite.
I'd Strongly Recommend OllyDbg, as well as Using the Plugin "PEDumper.dll", Google the Plugins, as i Dont Feel I'm in the Position to Provide a an Offsite Link (If this is Anything like UC)
After You've Opened OllyDbg Attach it to our Dyanmic Link Libary "myFile.exe"
Unless You've Renamed it in C++ Client.
Now, We'll Proceed to Dumping the File, In OllyDbg, Press "File > Attach"
Click on the Program, in my Case it's "myLoader",
Then at the Top, Press "Plugins", and Then, Click "OllyDbg PE Dumper > Dump a Process"
Under "Pick a Module (Drop Down Box within the OllyDbg PE Dumper Window",
Press and Look for your Dynamic Link Libary, in our Case/Mine it's "myFile.dll"
Press Dump, and the File will Dump, Save the File as a .DLL (Dynamic Link Library).
Now You've Successfully made a Dump of a Dynamic Link Library,
Congratulations, Give your Self a Pat on the Back
Thank you for Reading/Studying this and Hopefully You've Learnt atleast Somthing :P
Keep a Eye out from More Tutorails from Me / Bases / Code Snippets / Bypasses.
Please Contribute & Ask Questions, I'd be More then Welcome to Help, and Give some Constructive Criticism.
Credits,
kJNR
MSDN
Cheers,
kJNR
.
).