Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 07-29-2008, 02:39
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
How to skip BSOD?

Hello everybody.

Is there anyway to disable BSOD?
There is a protection which BSOD system by its driver when it detects debugger or any delay in its runtime.

Is there anyone who could write a plugin for OllyDbg to disable BSOD?

What's the opcode or command cause BSOD?

Best regards.
__________________
In memory of UnREal RCE...
Reply With Quote
  #2  
Old 07-29-2008, 02:50
D-Jester's Avatar
D-Jester D-Jester is offline
VIP
 
Join Date: Nov 2003
Location: Ohio, USA
Posts: 269
Rept. Given: 39
Rept. Rcvd 61 Times in 41 Posts
Thanks Given: 0
Thanks Rcvd at 4 Times in 4 Posts
D-Jester Reputation: 61
OS?

What is the fault that is being caused?
__________________
Even as darkness envelops and consumes us, wrapping around our personal worlds like the hand that grips around our necks and suffocates us, we must realize that life really is beautiful and the shadows of despair will scurry away like the fleeting roaches before the light.
Reply With Quote
  #3  
Old 07-29-2008, 04:18
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
I think I found it.

Driver uses this instruction to BSOD the system

cmp xxxx
je yyyy
int 3

I maked JE to JMP. But sometimes system hangscompletely !
I cann't fix this. Is there any suggestion?

Here is the driver.

I'll protect a file and attached it as soon as possible to challange its unpacking !
I has many bug that makes protection too hard !!!!
Attached Files
File Type: rar Driver.rar (1.8 KB, 10 views)
__________________
In memory of UnREal RCE...
Reply With Quote
  #4  
Old 09-10-2008, 01:27
SLV SLV is offline
Friend
 
Join Date: May 2005
Posts: 62
Rept. Given: 3
Rept. Rcvd 4 Times in 3 Posts
Thanks Given: 5
Thanks Rcvd at 2 Times in 2 Posts
SLV Reputation: 4
one way to "disable" BSOD is to hook KeBugCheckEx and terminate current thread. but this way is not good as all ways to skip BSOD's, because it's a normal system mechanism for determinating critical situations and if some error is caused with hardware it may have unpredictable results.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
pic 16f84 and skip security byte? hrco General Discussion 11 05-25-2004 15:40
SI+IceExt 0.6 = BSOD AnteC General Discussion 4 03-08-2004 20:52


All times are GMT +8. The time now is 19:29.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )