吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 24084|回复: 151
收起左侧

[Debuggers] OllyDbg 2.01 alpha 4 August 03, 2011

    [复制链接]
Hmily 发表于 2011-8-4 09:21
IDA,">OllyDbg 2.01 alpha 4 August 03, 2011


ugust 03, 2011 - OllyDbg 2.01 alpha 4. Here is Alpha 4, here is Bookmarks plugin

As you see, this version already supports plugins. New plugin interface is similar to the old (v1.10) but is not backwards compatible. It includes more than 350 API functions, 60 or so variables and many enumerations and structures that all need to be documented. This will take a while, therefore I decided to make a preliminary release. It includes plugin header file (plugin.h) and commented bookmarks source code (bookmark.c). Writing your own plugins without the documentation is a pure masochism, but at least you will be able to analyse the structure of the interface and  send me your comments, wishes and suggestions.

This is the last alpha release. After plugin documentation is ready, I will call it 2.01 beta 1. Then I will start to write OllyDbg help and finally make the full 2.01 release. Till then, I plan no major changes.

Other new features in this version:

- Patch manager, similar to 1.10
- Shortcut editor, supports weird things like Ctrl+Win+$ etc. Now you can customize and share your shortcuts. I haven't tested it on Win7, please report any found bugs and incompatibilities!
- Instant .udd file loading. In the previous versions I've postponed analysis, respectivcely reading of the .udd file till the moment when all external links are resolved. But sometimes it took plenty of time, module started execution and was unable to break on the breakpoints placed in the DLL initialization routine
- Automatic search for the SFX entry point, very raw and works only with several packers. Should be significantly more reliable than 1.10. If you tried it on some SFX and OllyDbg was unable to find real entry, please send me, if possible, the link or executable for analysis!
- "Go to" dialog lists of matching names in all modules
- Logging breakpoints can protocol multiple expressions. Here is an example: I ask OllyDbg to protocol the contents of EAX, EBX and 4 memory doublewords starting at address ESP. Expressions must be separated by commas, repeat count has form SIZE*N, N=1..32:




This is what you will see in the log when breakpoint is hit:




Many not-so-important new features:

- Thread names (MS_VC_EXCEPTION)
- UNICODE box characters clipboard mode
- Multiline debugging strings (of large size)
- On debug string, OllyDbg attempts to find call to OutputDebugString()
- INT3 breakpoints set on the first byte of edited memory area are retained
- Decoding of User Shared Data block
- Addressing relative to module base
- If plugin crashes, OllyDbg will report its name
- etc, etc.

I have received many bug reports. Some of them are solved, some are not. There is a very nasty bug that I was unable to reproduce: OllyDbg crashes with memory access violation inside the GlobalAlloc()?!! Either OllyDbg unintentionally taints internal data structures used by memory manager, or some virus scanner overreacts, or this is a bug of Windows itself? If you have any clue, please let me know.

That's all for now. I will make a short vacations, a week or so, and in order to keep my sanity will not check for new emails. Please have some patience!
http://www.ollydbg.de/odbg201d.zip
http://www.ollydbg.de/plug201d.zip


plug201d.zip

98.42 KB, 下载次数: 133, 下载积分: 吾爱币 -1 CB

odbg201d.zip

2.22 MB, 下载次数: 253, 下载积分: 吾爱币 -1 CB

免费评分

参与人数 7热心值 +7 收起 理由
297044530 + 1 恩,同样恳求老大汉化~~英文版用不来啊
19nuclear91 + 1 恳求老大汉化
hackbsky + 1 支持 ps:原版不是一般难看。。。
oo789458 + 1 大牛
skfxzxc + 1 必须支持hmily
hack幽冥 + 1 我承认我看不懂 但不妨碍我对您的评价··.
單戈亓申 + 1 期待 汉化版 老大辛苦了

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

whitefirer 发表于 2011-8-4 09:27
真是好消息~
tpsdbg 发表于 2011-8-4 09:30
wspili 发表于 2011-8-4 09:32
Smallhorse 发表于 2011-8-4 09:37
终于出来了!顶起,H大,太神了!
yhage 发表于 2011-8-4 09:39
很难得的更新,期盼正式版和汉化版
yhage 发表于 2011-8-4 09:40
很难得的更新,期盼正式版和汉化版

点评

网络延迟判定  发表于 2011-8-7 10:51
头像被屏蔽
zhang63 发表于 2011-8-4 09:41
提示: 作者被禁止或删除 内容自动屏蔽
ax123 发表于 2011-8-4 09:45
好东西 顶啊
a8987216 发表于 2011-8-4 09:47
好吧,表示我英文很差,OD更新倒是好事。
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-5-2 09:27

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表