吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 12324|回复: 36
收起左侧

[OllyDbg 1.x Plugin] OllyDumpEx 1.80

[复制链接]
A-new 发表于 2020-2-5 10:03
OverviewThis plugin is process memory dumper for OllyDbg and Immunity Debugger.
Very simple overview:
OllyDumpEx = OllyDump + PE Dumper - obsoleted + useful features

Features
  • Various debuggers supported
  • Select to dump debugee exe, loaded dll or non-listed module
  • Search PE File from memory
  • Multiple Dump mode. Rebuild for typical PE dump, Binary for PE Carving
  • PE32+ supported (Search and Binary Dump mode only available on 32bit debugger)
  • Native 64bit process supported (IDA Pro, WinDbg and x64dbg)
  • ELF supported (both of 32bit and 64bit)
  • Standalone version available
  • Dump any address space as section even if not in original section header
  • Auto calculate many parameters (RawSize, RawOffset, VirtualOffset, ...)
Supported Debugger
  • OllyDbg version 1.10 (tested 1.10)
  • OllyDbg version 2.01 (tested 2.01)
  • Immunity Debugger version 1.8x or higher (tested 1.85)
  • IDA Pro 32bit build version 5.0 or higher (tested 6.9)
  • IDA Pro 64bit build version 7.0 or higher (tested 7.1)
  • IDA Freeware 32bit build version 5.0 (tested 5.0)
  • IDA Freeware 64bit build version 7.0 (tested 7.0.190307)
  • WinDbg version 6.x (tested 6.2)
  • x64dbg (tested 20170822 snapshot)


    v1.80 / 2020-01-06
  • Bugfix: Fix race condition when reading large amount of memory (IDA)
  • Bugfix: DYNAMICBASE not working (Standalone)
  • Bugfix: Fix UI stall race condition issue when press Back to Menu button
  • Improve: Adjust UI layout for high DPI setting
  • Improve: Add DebugPriv button for runas administrator (Standalone)
  • Improve: Add OpenFile button for carving from localfile (Standalone)
  • Improve: Resolve mapped filename if possible (Standalone,x64dbg)
  • Improve: Add ReScan marker for rescan required setting changes
  • Improve: Use segment name as module name when segment not belong to module (IDA)
  • Improve: Address range autofill use mapped address instead of image base address
  • Add: File image source use specified file when memory and address base mode selected
  • Add: Dummy image header mode for image which not have valid image header
OllyDumpEx_v1.80.zip (1 MB, 下载次数: 1235)

免费评分

参与人数 8吾爱币 +9 热心值 +8 收起 理由
cpj1203 + 1 + 1 谢谢@Thanks!
多情自古空余恨 + 1 + 1 谢谢@Thanks!
speedboy + 2 + 1 感谢发布原创作品,吾爱破解论坛因你更精彩!
ak47110 + 1 + 1 鼓励转贴优秀软件安全工具和文档!
fangchang819 + 1 + 1 谢谢@Thanks!
笙若 + 1 + 1 鼓励转贴优秀软件安全工具和文档!
很快再相见123 + 1 + 1 我很赞同!
FleTime + 1 + 1 鼓励转贴优秀软件安全工具和文档!

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

alittlebear 发表于 2020-2-5 11:23
FleTime 发表于 2020-2-5 10:23
简单说明一下,此插件是OllyDbg和Immunity Debugger的进程内存转储器。

OllyDumpEx = OllyDump + PE Dum ...

一脸懵....我还是默默的去打酱油好了....
FleTime 发表于 2020-2-5 10:23
简单说明一下,此插件是OllyDbg和Immunity Debugger的进程内存转储器。

OllyDumpEx = OllyDump + PE Dumper-已过时+有用的功能
就是长得帅 发表于 2020-2-5 10:45
littlebit 发表于 2020-2-5 11:12
厉害了,大佬,感谢分享
吾爱007 发表于 2020-2-5 11:21
感谢分享
思想者 发表于 2020-2-5 12:48
支持大作..
就是长得帅 发表于 2020-2-5 12:55
英文额吗?
cptw 发表于 2020-2-5 14:31
感谢楼主分享,但完全看不懂!
q510 发表于 2020-2-5 16:40
感谢楼主分享,只会ESP定律脱壳
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-4-16 13:35

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表