Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #8  
Old 12-30-2017, 08:02
Stingered Stingered is offline
Banned User
 
Join Date: Dec 2017
Posts: 257
Rept. Given: 0
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 296
Thanks Rcvd at 181 Times in 90 Posts
Stingered Reputation: 3
I personally don't use this DLL, but...

Quote:
Originally Posted by gabri3l View Post
Recent paper released by Forcepoint uses StrongOD as an example of the risks around relying on an unsupported plugin (that specifically calls home).

TLDR; They identify a vulnerability in the update file StrongOD looks for on startup and sinkhole the domain that StrongOD used to call home in order to capture the IP addresses of Olly users.

hxxps://blogs.forcepoint.com/security-labs/freeman-perils-abandonware
...now you have forced my to stop being lazy and check all my plugins!

(IOW, TY!!!)

Of course, I had a copy - just in case and checked it: StrongOD v0.4.8.892.rar

.text:1000F874 push offset aHttpWww_crackl ; "http://www.cracklife.com/sod/update.txt"...

.text:1000F88F mov ecx, offset aHttpWww_crackl ; "http://www.cracklife.com/sod/update.txt"...

.text:1000F8AB mov esi, offset aHttpWww_crackl ; "http://www.cracklife.com/sod/update.txt"...

.rdata:100436C0 aHttpWww_crackl db 'http://www.cracklife.com/sod/update.txt',0 ; DATA XREF: sub_1000F7B0+C4o

Last edited by Stingered; 12-30-2017 at 08:04. Reason: spelling
Reply With Quote
The Following User Says Thank You to Stingered For This Useful Post:
niculaita (12-31-2017)
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
OllyDBG v1.10 plugin -StrongOD v0.4.5 [2011.08.10 v0.4.5.808] ZeNiX Community Tools 61 10-03-2013 04:57
Plugin+ Configuration for olly 2.01 Conquest General Discussion 4 03-25-2013 00:04
StrongOD plugin [NtSC] General Discussion 8 08-29-2010 11:00


All times are GMT +8. The time now is 03:55.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )