Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 01-24-2011, 19:39
djbobo
 
Posts: n/a
if you are C programmer, I suggest try Boomerang and Hex-Rays Decompiler.
both give you C like text.
Reply With Quote
  #17  
Old 01-26-2011, 03:57
piccolo piccolo is offline
Friend
 
Join Date: Jul 2006
Posts: 28
Rept. Given: 4
Rept. Rcvd 3 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
piccolo Reputation: 3
An odd one which is sometimes forgotten but which isnt at all bad is to use the open watcom compiler with its debugger. It is totally free and it used to be a payware thing... Just check the open watcom site for it..
Reply With Quote
  #18  
Old 01-31-2011, 21:21
Evilcry Evilcry is offline
Friend
 
Join Date: Jan 2009
Posts: 59
Rept. Given: 4
Rept. Rcvd 16 Times in 10 Posts
Thanks Given: 3
Thanks Rcvd at 42 Times in 19 Posts
Evilcry Reputation: 16
Debugger choice depends on complexity and particular context, basically OllyDbg2 cover a wide range of situations.

But for complex environment debugging WinDbg + scripting is "the best", both on ring3 and ring0 situations.

It's a bit unfriendly for a beginner, but I strongly suggest to learn also this debugger

Easy drivers, can be debugged with Syser.
Reply With Quote
  #19  
Old 02-01-2011, 18:47
_C0d3r_
 
Posts: n/a
Also ImmunityDebugger is pretty good: basically is OllyDbg with some tweak such as a built-in pythonAPI, a function graphing tool and a heap analysis tool.

Ida pro is really powerfull, but not as immediate and easy to use as OllyDbg; moreover, OllyDbg's plugins are actually useful.

Is now really outdated, but also W32DASM used to be good.

Finally, as stated above, if you want to get a bit more "in" the OS, there's Syser for your comfort. Syser is SoftIce's little up-to-date brother (as they say "Softice is left. Syser will continue.").
Reply With Quote
  #20  
Old 03-08-2011, 04:01
amigo amigo is offline
Friend
 
Join Date: Dec 2002
Posts: 30
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
amigo Reputation: 0
I am untreatable fan of Softice . It is possible to run Softice under Vista also (it's better - after little exports modification in Vista kernel files), although it has only basic functionality and is not as stable as under systems it was designated for. But you can easy Ctrl-D at any time to view the ring0 code and you can trace through the code. The processes list, changing contextes - don't work So it's necessary to make old simple tricks as inserting INT3 in the start of the debugged file - to get into proper context to set breakpoints in debugged process. All it is reasonable only if you are interested in ring0 code tracing. For ring3 tracing you have a lot of other debuggers as listed above
Reply With Quote
  #21  
Old 03-10-2011, 10:38
cnbragon cnbragon is offline
Friend
 
Join Date: Nov 2010
Posts: 26
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 3
Thanks Rcvd at 1 Time in 1 Post
cnbragon Reputation: 1
windbg is powerful on kernel debugging, ollydbg is powerful on application debugging and reverse engineering.
Reply With Quote
  #22  
Old 03-16-2011, 21:11
kamy
 
Posts: n/a
one vote for Olly
Reply With Quote
  #23  
Old 04-29-2011, 20:03
LaDidi LaDidi is offline
VIP
 
Join Date: Aug 2004
Posts: 222
Rept. Given: 2
Rept. Rcvd 11 Times in 10 Posts
Thanks Given: 64
Thanks Rcvd at 54 Times in 29 Posts
LaDidi Reputation: 11
OllyDbg 1.1 is the best for RING-3 debugging
IDA is a good assistant...
Reply With Quote
  #24  
Old 04-29-2011, 20:22
Git's Avatar
Git Git is offline
Old Git
 
Join Date: Mar 2002
Location: Torino
Posts: 1,116
Rept. Given: 220
Rept. Rcvd 265 Times in 157 Posts
Thanks Given: 110
Thanks Rcvd at 220 Times in 126 Posts
Git Reputation: 200-299 Git Reputation: 200-299 Git Reputation: 200-299
The microsoft kernel debugger makes OD look like a toy.

Git
Reply With Quote
  #25  
Old 05-08-2011, 19:29
o_o o_o is offline
Friend
 
Join Date: Oct 2005
Posts: 15
Rept. Given: 6
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 0 Times in 0 Posts
o_o Reputation: 0
I second OllyDbg for every day use.
WinDbg for r0 work.
Reply With Quote
  #26  
Old 05-14-2011, 18:43
greengo greengo is offline
Friend
 
Join Date: Sep 2010
Posts: 21
Rept. Given: 11
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
greengo Reputation: 0
OllyDbg & Scripts & ImmunityDebugger
Reply With Quote
  #27  
Old 05-16-2011, 20:16
hosiminh hosiminh is offline
Friend
 
Join Date: Aug 2004
Posts: 202
Rept. Given: 2
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 4 Times in 4 Posts
hosiminh Reputation: 1
Quote:
Originally Posted by mostafaebady View Post
Hi
ollydbg I think the best option is to crack software such facilities is very wide, which is the only surprise is that 64-bit programs and does not support NET.
You are right about x64 and wrong about .net
OD can run .net app (x32), although you wont see anything similar to ildasm or any other .net disassembler/debugger .
I was even able to fish a serial on some stupid app (forgot name).
Reply With Quote
  #28  
Old 05-17-2011, 21:26
RaptorFactor RaptorFactor is offline
Friend
 
Join Date: May 2011
Posts: 5
Rept. Given: 0
Rept. Rcvd 2 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
RaptorFactor Reputation: 2
WinDbg is the most powerful debugger by far imo, however it's nowhere near as user-friendly as some of the alternatives.

It depends what you're trying to do tbh.

If you're debugging your own code which you wrote using VS, then I'd use the builtin VS debugger for that.
If you're debugging regular non-packed/obfuscated applications and you don't mind a bit of a learning curve, then I'd use WinDbg.
If you're debugging x64 native applications then I'd use WinDbg.
If you're debugging heavily packed and/or obfuscated targets (x86 native) then OllyDbg is probably the way to go (due to the large amount of helpful plugins to remove some of the more tedious work).
If you're doing kernel debugging then I'd use WinDbg.
etc

Others obviously have other preferences. I'd suggest just giving the most popular tools a try and finding what you're most comfortable with. It's all about finding and using the best tool for the job.
Reply With Quote
  #29  
Old 05-20-2011, 18:35
wx69wx
 
Posts: n/a
i like od,but is there a update version for win7?

Last edited by wx69wx; 05-20-2011 at 18:44.
Reply With Quote
  #30  
Old 05-22-2011, 20:19
RaptorFactor RaptorFactor is offline
Friend
 
Join Date: May 2011
Posts: 5
Rept. Given: 0
Rept. Rcvd 2 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
RaptorFactor Reputation: 2
Quote:
Originally Posted by wx69wx View Post
i like od,but is there a update version for win7?
Not sure what you mean, as I don't recall OllyDbg 1.x beign 'broken' on Windows 7 (though I haven't used it in a long time, so I'm unsure). However, OllyDbg 2.0 has been released as of this year, and I've successfully used it on my Windows 7 x64 machine.

http://www.ollydbg.de/version2.html
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Best debugger for DOS? Taitch General Discussion 13 10-21-2010 13:46
IDA Pro 5.1 Mac OS X Debugger Preview prt General Discussion 1 01-17-2007 00:41


All times are GMT +8. The time now is 03:48.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )