<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Reverse Engineering ‘Pools of Darkness’: Part 1</title>
	<atom:link href="http://simeonpilgrim.com/blog/2009/10/04/reverse-engineering-pools-of-darkness-part-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://simeonpilgrim.com/blog/2009/10/04/reverse-engineering-pools-of-darkness-part-1/</link>
	<description></description>
	<lastBuildDate>Wed, 08 Feb 2012 23:17:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Simeon</title>
		<link>http://simeonpilgrim.com/blog/2009/10/04/reverse-engineering-pools-of-darkness-part-1/comment-page-1/#comment-3246</link>
		<dc:creator>Simeon</dc:creator>
		<pubDate>Mon, 05 Oct 2009 02:57:36 +0000</pubDate>
		<guid isPermaLink="false">http://simeonpilgrim.com/blog/?p=771#comment-3246</guid>
		<description>Well I learnt it years ago, all I was doing was searching for blog post fodder...

There is still merit, just for the fun of this is how a blind man would do it. But I&#039;m not blind any more. 

I&#039;ll give it a bash anyway.</description>
		<content:encoded><![CDATA[<p>Well I learnt it years ago, all I was doing was searching for blog post fodder&#8230;</p>
<p>There is still merit, just for the fun of this is how a blind man would do it. But I&#8217;m not blind any more. </p>
<p>I&#8217;ll give it a bash anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stu</title>
		<link>http://simeonpilgrim.com/blog/2009/10/04/reverse-engineering-pools-of-darkness-part-1/comment-page-1/#comment-3245</link>
		<dc:creator>Stu</dc:creator>
		<pubDate>Mon, 05 Oct 2009 02:44:11 +0000</pubDate>
		<guid isPermaLink="false">http://simeonpilgrim.com/blog/?p=771#comment-3245</guid>
		<description>sorry about my old school tools.. I&#039;m an old school cracker ;) dealing with this old dos stuff is like riding a bike to me...

I hope you do still post the next bits as its fun to read. sorry if I blew some of your posts away with showing you the power of unp. but hey, you learned some stuff about using dos debug.exe right? :)</description>
		<content:encoded><![CDATA[<p>sorry about my old school tools.. I&#8217;m an old school cracker ;) dealing with this old dos stuff is like riding a bike to me&#8230;</p>
<p>I hope you do still post the next bits as its fun to read. sorry if I blew some of your posts away with showing you the power of unp. but hey, you learned some stuff about using dos debug.exe right? :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simeon</title>
		<link>http://simeonpilgrim.com/blog/2009/10/04/reverse-engineering-pools-of-darkness-part-1/comment-page-1/#comment-3244</link>
		<dc:creator>Simeon</dc:creator>
		<pubDate>Mon, 05 Oct 2009 02:21:16 +0000</pubDate>
		<guid isPermaLink="false">http://simeonpilgrim.com/blog/?p=771#comment-3244</guid>
		<description>ARRRGG i hate your fancy old-school tools.

Once you load the unpacked EXE into IDA it detect that it has &quot;references to Pascal Overlays&quot; which it then magically auto loads and solves EVERYTHING.

ARRRGGGGG!!!!

The work shown in this blog post originally took a week, the next blog post in the serries took months originally.</description>
		<content:encoded><![CDATA[<p>ARRRGG i hate your fancy old-school tools.</p>
<p>Once you load the unpacked EXE into IDA it detect that it has &#8220;references to Pascal Overlays&#8221; which it then magically auto loads and solves EVERYTHING.</p>
<p>ARRRGGGGG!!!!</p>
<p>The work shown in this blog post originally took a week, the next blog post in the serries took months originally.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simeon</title>
		<link>http://simeonpilgrim.com/blog/2009/10/04/reverse-engineering-pools-of-darkness-part-1/comment-page-1/#comment-3243</link>
		<dc:creator>Simeon</dc:creator>
		<pubDate>Mon, 05 Oct 2009 02:14:18 +0000</pubDate>
		<guid isPermaLink="false">http://simeonpilgrim.com/blog/?p=771#comment-3243</guid>
		<description>Ok, Curse of the Azure bonds was packed with Exepack v4.05 or v4.06

Now trying to see if the merge overlay option works, can&#039;t get it work yet....</description>
		<content:encoded><![CDATA[<p>Ok, Curse of the Azure bonds was packed with Exepack v4.05 or v4.06</p>
<p>Now trying to see if the merge overlay option works, can&#8217;t get it work yet&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simeon</title>
		<link>http://simeonpilgrim.com/blog/2009/10/04/reverse-engineering-pools-of-darkness-part-1/comment-page-1/#comment-3242</link>
		<dc:creator>Simeon</dc:creator>
		<pubDate>Mon, 05 Oct 2009 02:01:12 +0000</pubDate>
		<guid isPermaLink="false">http://simeonpilgrim.com/blog/?p=771#comment-3242</guid>
		<description>Interesting, will differently check that out...

I know the version of Pool of Radiance that is on the AbandonWare siets, is cracked (password removed) and those versions are not packed.

I did all this original work years ago also... but your write if there is a tool to fix it up... oh man now I&#039;m going to have to check it out now.....</description>
		<content:encoded><![CDATA[<p>Interesting, will differently check that out&#8230;</p>
<p>I know the version of Pool of Radiance that is on the AbandonWare siets, is cracked (password removed) and those versions are not packed.</p>
<p>I did all this original work years ago also&#8230; but your write if there is a tool to fix it up&#8230; oh man now I&#8217;m going to have to check it out now&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stu</title>
		<link>http://simeonpilgrim.com/blog/2009/10/04/reverse-engineering-pools-of-darkness-part-1/comment-page-1/#comment-3241</link>
		<dc:creator>Stu</dc:creator>
		<pubDate>Mon, 05 Oct 2009 00:48:27 +0000</pubDate>
		<guid isPermaLink="false">http://simeonpilgrim.com/blog/?p=771#comment-3241</guid>
		<description>actually they are not scrambled they are linker packed by the MS linker, its called EXEPACK and if you ever see &quot;Packed file is corrupt&quot; this is an EXEPACK file. Its similar to PKLite, LZEXE, WWP, etc early versions would just pack relocations (each relocaiton was 4 bytes but most often all in the same segment, so it would basically do an RLE on the segment:offset runs and use only the offsetpart. later exepacks evolved into full blown pakcers like pklite, wwp etc).

to make your life easier, get &quot;unp&quot; (unprotect) and just depack it before running it through IDA...

I think all goldbox games were exepacked from Pool of Radiance to Dark Queen of Krynn. I didnt check buck rogers or FRUA, which was the last GB release.

lol sounds like you did a lot of hard work when there is a very simple answer ;) 
ftp://ftp.sac.sk/pub/sac/pack/unp411.zip</description>
		<content:encoded><![CDATA[<p>actually they are not scrambled they are linker packed by the MS linker, its called EXEPACK and if you ever see &#8220;Packed file is corrupt&#8221; this is an EXEPACK file. Its similar to PKLite, LZEXE, WWP, etc early versions would just pack relocations (each relocaiton was 4 bytes but most often all in the same segment, so it would basically do an RLE on the segment:offset runs and use only the offsetpart. later exepacks evolved into full blown pakcers like pklite, wwp etc).</p>
<p>to make your life easier, get &#8220;unp&#8221; (unprotect) and just depack it before running it through IDA&#8230;</p>
<p>I think all goldbox games were exepacked from Pool of Radiance to Dark Queen of Krynn. I didnt check buck rogers or FRUA, which was the last GB release.</p>
<p>lol sounds like you did a lot of hard work when there is a very simple answer ;)<br />
<a href="ftp://ftp.sac.sk/pub/sac/pack/unp411.zip" rel="nofollow">ftp://ftp.sac.sk/pub/sac/pack/unp411.zip</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

