吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn




查看: 4383|回复: 3

[OllyDbg 1.x Plugin] SigMaker v0.4

Hmily 发表于 2011-3-4 17:56
Author: P47R!CK
Version: 0.4
Support: http://forum.tuts4you.com/index.php?showtopic=25196

This plugin is meant to help you create signatures. You can choose from a variety of styles to suit your needs and you can now also test your signatures.

The supported styles are:

* Code style ( to use with dwFindPattern )
* PB Style ( the style that punkbuster uses )
* Tabris style ( for further info click HERE)
* Text style ( used by Olly, IDA and Op Searcher )

There is also the option to get an offset from the current address which will look like this:

* modulename + offset

clearly you will have to use GetModuleHandle or LoadLibrary to convert the name into an address....

Here is what the options do:

"include short jumps" this option will include short jumps as such as "jmp 10" ( EB 0A )
"Include data" adds data as such as the 5 of mov eax, 5
"include eip related data" will add info that modifies the program flow and stack pointer such as "retn C"
"Add additional info" adds information about the module in which your signature is situated in
"include relative addresses" will add relative offsets to your signature as such as the 8 in this instruction "mov eax,[ecx+8]"
"include unsafe data" is currently disabled because my register tracking code( to determine if the constant is an address ) doesn't work yet.

The last 2 options should be self-explanatory.

The only thing I should mention is that you can double click the results to jump the associated address.

SigMaker v0.4.rar

45.4 KB, 下载次数: 94, 下载积分: 吾爱币 -1 CB


532098613 发表于 2011-3-4 18:37
提示: 作者被禁止或删除 内容自动屏蔽
Kiζs~乄 发表于 2011-3-4 20:37
大哥 每次加个中文说明不行吗 不用太详细 就说它是干什么的就行
tdl6 发表于 2011-3-4 21:44
Kiζs~乄 发表于 2011-3-4 20:37
大哥 每次加个中文说明不行吗 不用太详细 就说它是干什么的就行

就是啊 不晓得是干啥子用的
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-5-29 10:06

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表