![]() |
|
|||||||
| View Poll Results: Would you use this debugger? | |||
| Yes (mainly x32) |
|
97 | 29.04% |
Not at all
|
|
25 | 7.49% |
| Yes, if it gets better (please post feature suggestions) |
|
90 | 26.95% |
| Yes (mainly x64) |
|
122 | 36.53% |
| Voters: 334. You may not vote on this poll | |||
![]() |
|
|
Thread Tools | Display Modes |
|
|
|
#2
|
||||
|
||||
|
update backup need fix .
after u make some changes to source code ,and reload target in the debugger again the BP ( which u put it before ) will still and take its place as int3 .program will failed .
__________________
Ur Best Friend Ahmadmansoor Always My Best Friend: Aaron & JMI & ZeNiX |
| The Following User Gave Reputation+1 to ahmadmansoor For This Useful Post: | ||
mr.exodia (03-16-2014) | ||
| The Following User Says Thank You to ahmadmansoor For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#3
|
|||
|
|||
|
I read somewhere that you can use commands based on the TitanEngine itself - does this include for instance DumpProcess by any chance?
I tried using Scylla's process dumper, but its no good for me as it keeps creating this messed up dump... The best would be to have a proper dumper like OllyDumpEx, which produces a very good dumped executable on PE32 ![]() Anyways, back to my question; is there any chance I can use TitanEngine's DumpProcess within the x64_Dbg for this purpose? |
| The Following User Says Thank You to n00b For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#5
|
|||
|
|||
|
@n00b: currently i didnt implement this command, but take a look at the plugin engine. its easy to add a command.
greetingd |
| The Following User Gave Reputation+1 to mr.exodia For This Useful Post: | ||
n00b (03-28-2014) | ||
| The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#6
|
|||
|
|||
|
Yeah, it simply won't run when dumped - I also tried with another tool, which dumps the process aswell - and it ran, but the size increased exponentially to say the least... Went from 40mb to 70mb...
|
| The Following User Says Thank You to n00b For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#7
|
|||
|
|||
|
@n00b: I'll create a small plugin for you to see if its working. Will do that after the new release of x64dbg
![]() Greetings |
| The Following User Gave Reputation+1 to mr.exodia For This Useful Post: | ||
n00b (03-29-2014) | ||
| The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#8
|
|||
|
|||
|
Thank you so much mate, that would be really helpful indeed
![]() @Carbon: The tool I used which managed to create a working dump, is VSD v1.0 x64
|
| The Following User Says Thank You to n00b For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#9
|
|||
|
|||
|
@mr.exodia: So, I'm trying to create my own plugin here - and I was curious, how do I get the current RIP of any process through a plugin?
I have checked both example plugin, and the TitanHide plugin for clues - even looked quickly at the headers which to include... I'm not the most experienced coder of plugins, so I apoligize for looking too noobish - hehe ![]() Big regards
|
| The Following User Says Thank You to n00b For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#10
|
|||
|
|||
|
@n00b: Thanks for the interest. You can either use the Bridge export 'DbgValFromString' or you can use TitanEngine (just call GetContextData).
some example code: Code:
//Bridge
//you can also use 'CIP' for an architecture-independent IP register
duint rip=DbgValFromString("RIP"); //"RIP" can be anything that's an expression
//TitanEngine
rip=GetContextData(UE_RIP);
@everyone: V1.2ALPHA is out! Changelog: - many small crash fixes (stack overflows etc) - many fixes regarding the Dump window - different dump views - bugs with valfromstring fixed (now much faster) - latest development version of TitanEngine Community Edition (many, many, many fixes) - simple thread view - project design overview (x64_dbg_sceme.vsd), useful for plugin developers - TLS callback support - informative window title - user preferences (eg on which events to break) - bug with the recent file list fixed - ignore exception ranges - debug strings are now displayed (escaped) - added 'xor' command - many fixes in the script engine - simple stack display Download: https://bitbucket.org/mrexodia/x64_dbg/downloads Greetings, Mr. eXoDia |
| The Following 4 Users Gave Reputation+1 to mr.exodia For This Useful Post: | ||
| The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#11
|
|||
|
|||
|
Sorry, I could not edit my previous post anymore..
Attached an example plugin (DumpProcess), I tested it for a simple DLL + EXE and it appears to work fine. Feel free to (ab)use it however you like. EDIT: @n00b, seems like I've misread your question. To get the RIP of any process, you should use the function GetThreadContext, enum the threads in a process using CreateToolhelp32Snapshot & Thread32Next and then get the RIP of the thread you're interested in... Greetings, Mr. eXoDia |
| The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#12
|
|||
|
|||
|
V1.3ALPHA is out!
Changelog: - added reference searching 'ref value[,page]' - added string reference searching (little button in the upper-right or the command 'strref [page]' - fixed a bug when you removed all ignored exception ranges. Download: https://bitbucket.org/mrexodia/x64_dbg/downloads Greetings, Mr. eXoDia |
| The Following 4 Users Gave Reputation+1 to mr.exodia For This Useful Post: | ||
| The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#13
|
|||
|
|||
|
V1.5ALPHA is out (lol, kinda spamming)
Changelog: - fixed some bugs with references - added the 'Previous (-)' and 'Next (+)' function (to get back to your previous address of interest). This has a maximum depth of 1024, but it's easy to change this to any other value, since I use dynamic arrays Download: https://bitbucket.org/mrexodia/x64_dbg/downloads Greetings, Mr. eXoDia |
| The Following 5 Users Gave Reputation+1 to mr.exodia For This Useful Post: | ||
ahmadmansoor (04-09-2014), chessgod101 (04-11-2014), cjack (04-08-2014), Sir.V65j (04-17-2014), uranus64 (04-09-2014) | ||
| The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#14
|
|||
|
|||
|
@stev: ... ok thats the download link I provided.
|
| The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#15
|
||||
|
||||
|
Hi mr.exodia,
I have a machine who has a hard disk more than one tera, partitioned into multiple disk drive (disk drive letter: c, d, e, f ... p) x64_dbg display "error starting process (invalid pe?)!" when I try to debug something in disk drive (letter: M, N, O or P) it works fine on (disk drive letter: C,D,E.......L)
__________________
Computer Forensics |
| The Following User Says Thank You to Insid3Code For This Useful Post: | ||
Indigo (07-19-2019) | ||
![]() |
| Tags |
| bit, debugger, x32, x64, x64_dbg |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Debug with x64dbg | dnvthv | General Discussion | 2 | 03-22-2025 21:49 |
| Add .lib file on x64dbg ? | LaDidi | General Discussion | 0 | 02-18-2022 14:39 |
| DBG2AP - x64dbg plugin | Agmcz | Community Tools | 1 | 06-15-2019 07:14 |
| nfd - x64dbg plugin | hors | Community Tools | 2 | 04-01-2018 08:18 |
| x64dbg python | Storm Shadow | Developer Section | 6 | 08-04-2017 15:29 |