吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 4391|回复: 4
收起左侧

[IDA Plugin] IDA Stealth Plugin v1.2 - 12/15/2009

[复制链接]
Hmily 发表于 2009-12-20 03:34
IDA Stealth Plugin
IDA Stealth is a plugin which aims to hide the IDA debugger from most common anti-debugging techniques. The plugin is composed of two files, the plugin itself and a dll which is injected into the debuggee as soon as the debugger attaches to the process. The injected dll actually implements most of the stealth techniques either by hooking system calls or by patching some flags in the remote process.



You can grab the plugin only or go for the complete package including the sources and all dependencies.
Consult the readme file on how to install, use and configure the plugin.
The plugin source code should build out of the box, see readme for details.
If you find bugs or want to suggest new features just drop me a mail or create a new forum topic.
Changelog12/15/2009 - v1.2
  • Bugfix: RDTSC driver handling; driver service was not deleted in some rare cases
  • Bugfix: RDTSC driver mode was broken due to recent BSOD fix
  • Improved: IDAStealth can hide from Themida with ultra anti debugging settings
  • Added: New stealth driver

idastealth_complete.rar

1.24 MB, 下载次数: 24, 下载积分: 吾爱币 -1 CB

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

huzhao23 发表于 2009-12-20 12:39
不知道怎么用,能说明下不?
2051314 发表于 2009-12-20 14:16
 楼主| Hmily 发表于 2009-12-20 15:16
gtboy 发表于 2009-12-20 22:12
看了下英文说明,是个防止IDA的调试被程序anti的插件
需要两个文件,一个是插件本身,另一个是注入到IDA 调试器的dll文件
能够抵抗大部分的anti-debug
技术原理:注入的dll文件采用一些技术hook系统调用或者修改被调试程序的寄存器

翻译的不是很准,呵呵
感谢Hmily牛
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-5-13 04:48

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表