Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-17-2006, 01:22
ricnar456 ricnar456 is offline
Friend
 
Join Date: May 2002
Posts: 290
Rept. Given: 1
Rept. Rcvd 28 Times in 10 Posts
Thanks Given: 0
Thanks Rcvd at 52 Times in 40 Posts
ricnar456 Reputation: 28
WINDBG question

I start using windbg with vmware for cracking in kernel and user,and i think is a clean usage, but i have a question, if anyone use this method, how can be emulated the BPM comand of ollydbg, a breakpoint in a big range of memory.

I read all the help and i found windbg only has Hardware bpx and this have a range of 4 bytes maximum, but how is possible emulate the BPM command of ollydbg, for put a breakpoint in a big range of memory, changing the memory permission, there are a extension for this? Is possible?

Thanks

Ricardo Nrvaja
Reply With Quote
  #2  
Old 08-17-2006, 01:52
Jon Jon is offline
Friend
 
Join Date: Jan 2002
Posts: 53
Rept. Given: 2
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Jon Reputation: 0
Well the way Ollydbg implmented Ranged breakpoints is simply actually tracing all the instructions one by one and check for your condition (this is why its so slow) i guess the only way you can implement it in kernel is like SoftICE for 9x worked which is hooking the Paging mechanisim of Windows and paging out the region you want ... well you get the point it's not that simple but yet not too complicated requires some driver coding .

-- Jon.
Reply With Quote
  #3  
Old 08-17-2006, 02:01
OHPen's Avatar
OHPen OHPen is offline
Friend
 
Join Date: Aug 2003
Location: lost in code...
Posts: 92
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
OHPen Reputation: 0
Yes i agree with jon. Such functionality is not included in WinDbg. But as he said if you are up with driver development or writing your own debugger extension which is btw not that difficult.
I can give you the advise to read in the www.sysinternals.com forum to get more information about the topic. www.codeguru.com/forum is also a good place to ask such things.

good luck ric

regards

PAPiLLiON aka OHPen aka PiTcH_SiLoW
Reply With Quote
  #4  
Old 08-17-2006, 04:07
ricnar456 ricnar456 is offline
Friend
 
Join Date: May 2002
Posts: 290
Rept. Given: 1
Rept. Rcvd 28 Times in 10 Posts
Thanks Given: 0
Thanks Rcvd at 52 Times in 40 Posts
ricnar456 Reputation: 28
oh, i think when post, the posibility of a more easy solution, and a frequent user of windbg has solved yet.

The other option trace with condition is not added, i think windbg need one or two crackers in the programmer team, hehe.

thanks for the response

Ricardo
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
New windbg preview available Shub-Nigurrath Community Tools 2 09-01-2017 23:35
Windbg in IDA 6.5 zeuscane General Discussion 8 11-02-2014 14:13
WinDBG Virtual PC Sergey Nameless General Discussion 6 09-06-2004 16:13


All times are GMT +8. The time now is 00:21.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )