[Tips]Make IDA display all function's adress as rebased (maybe i'm out of date) menu

User Tag List

Results 1 to 7 of 7
  1. #1
    demonguy's Avatar Member
    Reputation
    2
    Join Date
    Feb 2012
    Posts
    111
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    [Tips]Make IDA display all function's adress as rebased (maybe i'm out of date)

    1.Be sure your current active window is "IDA-View"
    2.Use menu command "Edit"->"Segments"->"Rebase Program" . and rebases to 0x0
    3.wait for a moment and all adress wil be displayed as rebased...

    i don't know why all masters in this forum don't do this, maybe there is a particular reason?

    [Tips]Make IDA display all function's adress as rebased (maybe i'm out of date)
  2. #2
    Bananenbrot's Avatar Contributor
    Reputation
    153
    Join Date
    Nov 2009
    Posts
    384
    Thanks G/R
    1/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    If you try to debug with ida, it will always rebase to wow.exe's base address. It happens that wow.exe's default image base is 0x400000. So if ida is currently rebased at that position, you don't have to wait each time when you start to debug.

  3. #3
    demonguy's Avatar Member
    Reputation
    2
    Join Date
    Feb 2012
    Posts
    111
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    But it's really strange, each time i debug with IDA, it will always be rebased to a random address such as 0x11C0000, often more than 0x1000000, How to force it to rebase on 0x400000?

  4. #4
    _Mike's Avatar Contributor
    Reputation
    310
    Join Date
    Apr 2008
    Posts
    531
    Thanks G/R
    0/2
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by demonguy View Post
    But it's really strange, each time i debug with IDA, it will always be rebased to a random address such as 0x11C0000, often more than 0x1000000, How to force it to rebase on 0x400000?
    Disable ASLR.
    If you have visual studio (or just editbin.exe) installed, open up a VS command prompt and enter
    'editbin /dynamicbase:no wow.exe'

    Or find some other PE editor which can do the same.

  5. #5
    Bananenbrot's Avatar Contributor
    Reputation
    153
    Join Date
    Nov 2009
    Posts
    384
    Thanks G/R
    1/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Or use setdllcharacteristics « Didier Stevens. Credits to Cypher. Or go with _Mike's suggestion, seems to be even easier.

  6. #6
    DrakeFish's Avatar Lazy Leecher

    Reputation
    634
    Join Date
    Nov 2008
    Posts
    569
    Thanks G/R
    0/14
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    To disable ASLR, you can also download EMET, a Microsoft tool that allows disabling ASLR on specific EXE's (or globally).

    Link: Download EMET from Official Microsoft Download Center

    edit: I may have spoke too soon, I just tried app-specific ASLR on WoW and it seems like it doesn't work. However, disabling ASLR system-wide should work.
    Last edited by DrakeFish; 10-26-2012 at 09:28 PM.

  7. #7
    sitnspinlock's Avatar Elite User CoreCoins Purchaser
    Reputation
    398
    Join Date
    Sep 2010
    Posts
    439
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by DrakeFish View Post
    To disable ASLR, you can also download EMET, a Microsoft tool that allows disabling ASLR on specific EXE's (or globally).

    Link: Download EMET from Official Microsoft Download Center

    edit: I may have spoke too soon, I just tried app-specific ASLR on WoW and it seems like it doesn't work. However, disabling ASLR system-wide should work.
    it does, and needs to. for legacy applications without relocations

Similar Threads

  1. [Small tip] Makeing gold easily.
    By snugglepants in forum World of Warcraft Guides
    Replies: 5
    Last Post: 11-02-2008, 12:51 PM
  2. [Tip] Making easy gold with the Auction House
    By Eski in forum World of Warcraft Guides
    Replies: 33
    Last Post: 09-01-2008, 05:54 AM
  3. [Tip] Make some gold when you're bored
    By Sabens in forum World of Warcraft Guides
    Replies: 13
    Last Post: 08-13-2008, 09:23 AM
  4. Tip: make loads of gold when WOTLK comes out.
    By Hyourin in forum World of Warcraft Guides
    Replies: 17
    Last Post: 08-06-2008, 01:30 PM
  5. Can you make it so all undead looks like this dood
    By gr33ksoldi3r in forum WoW ME Questions and Requests
    Replies: 2
    Last Post: 07-21-2007, 08:19 PM
All times are GMT -5. The time now is 01:50 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search