Exetools  

Go Back   Exetools > General > Community Tools

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 10-03-2013, 15:43
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
Quote:
Originally Posted by ferrit.rce View Post
I've debugged thousands of hours with 1.1 and that was the reason why I've decided to use the new version
Even if it has also some bugs it has 2 advantages for me:
1. It's not crashing so much
2. Oleh will fix these problems
I agree with you, but lack of some features pushes me to use v1.10, specially for unpacking. But because of lack of comprehensive workable anti-anti plugin, I'm in trouble

I think you need do some modification in you code for OD1.1 PDK, API patching is the same. Isn't it?
__________________
In memory of UnREal RCE...
Reply With Quote
  #2  
Old 10-03-2013, 18:38
ferrit.rce's Avatar
ferrit.rce ferrit.rce is offline
VIP
 
Join Date: Sep 2013
Location: Switzerland
Posts: 42
Rept. Given: 10
Rept. Rcvd 101 Times in 23 Posts
Thanks Given: 0
Thanks Rcvd at 5 Times in 4 Posts
ferrit.rce Reputation: 100-199 ferrit.rce Reputation: 100-199
API patching is exactly the same but the PDK interface and feature set is really different. A lot of used new features doesn't exist on 1.1. I can take a look at once again but can't promise anything...
BTW what is missing from 2.x?

Quote:
Originally Posted by Newbie_Cracker View Post
I agree with you, but lack of some features pushes me to use v1.10, specially for unpacking. But because of lack of comprehensive workable anti-anti plugin, I'm in trouble

I think you need do some modification in you code for OD1.1 PDK, API patching is the same. Isn't it?
Reply With Quote
The Following User Gave Reputation+1 to ferrit.rce For This Useful Post:
Newbie_Cracker (10-04-2013)
  #3  
Old 10-04-2013, 01:27
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
Quote:
Originally Posted by ferrit.rce View Post
API patching is exactly the same but the PDK interface and feature set is really different. A lot of used new features doesn't exist on 1.1. I can take a look at once again but can't promise anything...
BTW what is missing from 2.x?
Thanks for checking the possibility.

For the features, it's not the right topic to discuss about the features missing but small things that I use heavily:

- Mem BP on Write on PE sections,memory regions (very handy for unpacking, reversing)
- Handles window button (I hate extra clicks)
- Patches window (not critical, but comes handy sometimes)


I've found some bugs but now remember these:

- Show Symbolic address is too stupid in OD2.x for CALL DWORD[adr]. If you press space on such codes OD shows

CALL DWORD PTR DS:[<&KERNEL32.GetSystemTimeAsFileTime>] instead of CALL DWORD PTR DS:[4080AC].

I really hate it !

- Some unknown exception while loading packed files.
- OD2.x fails to show pe sections seperately in Execryptor packed files, even in unpacked files (interesting bug)

and all plugins which exist for OD 1.1

So I still use OD1.10
__________________
In memory of UnREal RCE...
Reply With Quote
  #4  
Old 10-22-2013, 13:55
quygia128's Avatar
quygia128 quygia128 is offline
Family
 
Join Date: Apr 2011
Location: SomeWhere
Posts: 109
Rept. Given: 243
Rept. Rcvd 182 Times in 47 Posts
Thanks Given: 122
Thanks Rcvd at 30 Times in 19 Posts
quygia128 Reputation: 100-199 quygia128 Reputation: 100-199
Quote:
Originally Posted by Newbie_Cracker View Post

I've found some bugs but now remember these:

- Show Symbolic address is too stupid in OD2.x for CALL DWORD[adr]. If you press space on such codes OD shows

CALL DWORD PTR DS:[<&KERNEL32.GetSystemTimeAsFileTime>] instead of CALL DWORD PTR DS:[4080AC].

I really hate it !
I will code a plugin to Fix this problem automatic way when you run OllyDbg, please wait.

BR,
quygia128
Reply With Quote
  #5  
Old 10-23-2013, 14:25
ferrit.rce's Avatar
ferrit.rce ferrit.rce is offline
VIP
 
Join Date: Sep 2013
Location: Switzerland
Posts: 42
Rept. Given: 10
Rept. Rcvd 101 Times in 23 Posts
Thanks Given: 0
Thanks Rcvd at 5 Times in 4 Posts
ferrit.rce Reputation: 100-199 ferrit.rce Reputation: 100-199
New v1.6 is out. Changes:
Code:
- CreateThread
- Version information resource added
Attached Files
File Type: zip OllyExt_1.6.zip (127.6 KB, 49 views)
Reply With Quote
The Following 7 Users Gave Reputation+1 to ferrit.rce For This Useful Post:
ahmadmansoor (10-23-2013), evlncrn8 (10-24-2013), nikre (10-23-2013), quygia128 (10-23-2013), sendersu (10-23-2013), TQN (10-24-2013), wilson bibe (10-23-2013)
Reply

Tags
anti-anti-debug, anti-debug, ollydbg, ollyext, plugin

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
DEF plugin for OllyDbg 2.XX wilson bibe Community Tools 2 07-22-2014 09:01


All times are GMT +8. The time now is 16:09.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )