Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 03-20-2005, 21:13
elephant elephant is offline
Friend
 
Join Date: Feb 2005
Posts: 94
Rept. Given: 2
Rept. Rcvd 29 Times in 15 Posts
Thanks Given: 132
Thanks Rcvd at 127 Times in 41 Posts
elephant Reputation: 29
OllyDbg long process Module debug Vulnerability

OllyDbg will crash if a target process loads a module that contains a long name with more of 200 characters. This could be used for antidebugging purposes.

This vulnerability has been discovered by ATmaCA. Here is the original advisory from Securityfocus:

hxxp://www.securityfocus.com/archive/1/393747/2005-03-17/2005-03-23/0

Quote:
Vendor:
Oleh Yuschuk

Application:
OllyDbg
http://home.t-online.de/home/Ollydbg/

Introduction:
OllyDbg is a 32-bit assembler level analysing debugger for Microsoft® Windows®.
Emphasis on binary code analysis makes it particularly useful in cases where source
is unavailable.

Affected Versions:
1.10 (final version) and prior versions.

Overview:
In OllyDbg, if a target process loads modules that contains long name
(greater than around 200 bytes), OllyDbg will be crashed.

This hole can be used for an anti-debug method for OllyDbg.


Vendor Status:
No vendor response.

Discovery:
ATmaCA
atmaca atmacasoft com
www.atmacasoft.com
www.spyinstructors.com
Credit to Kozan

POC:
Debug this program with OllyDbg,
when the program runs, a folder that named "olly hole" will be
created on desktop and a long named dll will be created in
this folder. then it will load this and finally
olly debug will be crashed.

http://www.atmacasoft.com/exp/OllyHole.exe
Reply With Quote
  #2  
Old 04-04-2005, 21:49
kp_
 
Posts: n/a
anti debugging trick:
"hey, reverser, don't load my program into the debugger as it carries a backdoor in its filename and i hack into your machine"
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
OllyDbg - invisible process daujones General Discussion 8 03-03-2013 03:51
OllyDBG v1.10 and ImpREC v1.7f export name buffer overflow vulnerability bukkake General Discussion 0 07-28-2008 03:40
OllyDbg "INT3 AT" Format String Vulnerability sKip General Discussion 14 12-05-2006 18:00
How to debug Safedisc in OllyDbg DeeYeah General Discussion 4 01-31-2005 21:02
What to do when Ollydbg can't attach to a process? ycloud General Discussion 0 04-24-2004 19:10


All times are GMT +8. The time now is 07:24.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )