首页
社区
课程
招聘
ollydbg 出了一个最新的插件!
发表于: 2004-7-26 16:45 5212

ollydbg 出了一个最新的插件!

2004-7-26 16:45
5212
b48K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3!0D9L8s2W2V1j5X3N6Q4x3X3g2%4K9h3^5K6x3X3q4K6L8h3y4G2L8h3#2#2L8X3W2@1P5g2)9J5k6h3&6W2N6q4)9J5c8X3W2F1k6r3g2^5i4K6u0W2M7r3S2H3i4K6y4r3j5h3y4@1K9h3!0F1i4K6y4p5N6Y4c8Z5M7X3g2S2k6q4)9J5y4X3k6G2M7Y4g2E0i4K6y4p5x3W2)9J5y4Y4c8G2M7r3W2U0i4K6y4p5z5o6b7I4

GODUP - Godfather+ Olly Debugger Universal Plug-in
ver. 1.0

This plug-in consist of 5 handy tools:

1. Map loader
2. Resource viewer
3. Process info
4. IDA signature loader
5. Notepad

1. Map loader - use it for loading map files produced by compiler or by
IDA. You can use it to load label names and/or to load comments from .map file.
There is no any checking if map file match currently debugged process.

2. Resource viewer - use it for looking to your resources ;-) This is
probably only viewer which works through direct memory access - means that you
can even look to resources of compressed (protected) executables.
NOTE: Still in experimental phase.

3. Process info - Give you basic information about process + try to
recognize compiler and protection mechanism. . Process info use signature file
signs.txt from PE tools v1.5 (NEOx, .Cryorb) Fell free to add your own
signatures and share it with us.

4. IDA signature loader - probably mostly wanted add on for Olly debugger -
now you can use IDA signature without IDA ;-) Just look to process info - find
your compiler and select and apply matching IDA signature. It's not problem if
you apply wrong one, you can apply another also. Only what you must do is to set
proper path to IDA signatures, and you need sigdump.exe file from IDA resource
kit.

5. Notepad - Simple but smart notepad which load your notes per process
automatically every time.

感觉不错,谁去汉化一下。 :D

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

收藏
免费 2
支持
分享
最新回复 (4)
雪    币: 4668
活跃值: (5323)
能力值: (RANK:215 )
在线值:
发帖
回帖
粉丝
2
谁能提供一下,exetools不让下
2004-7-26 17:04
0
雪    币: 898
活跃值: (4054)
能力值: ( LV9,RANK:3410 )
在线值:
发帖
回帖
粉丝
3
最初由 china 发布
谁能提供一下,exetools不让下


放到工具论坛了
http://bbs.pediy.com/showthread.php?s=&threadid=3292
2004-7-26 17:16
0
雪    币: 222
活跃值: (40)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
这东西是干吗用的呀?脱壳吗?
2004-7-26 17:46
0
雪    币: 427
活跃值: (412)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
最初由 海角虹楼 发布
这东西是干吗用的呀?脱壳吗?


主要是提供分析作用的,如资源,进程,比如什么东西加壳,最最大的好处,我可能想到了,分析多层壳,绝对是非常有用的。IDA signature loader 也非常有用。这样能为动态提供静态分析的优点。Map loader 没用过。 Notepad 记事用的,感觉作用不大。如果能写个SOFTICE的Notepad ,那就很好了。
2004-7-26 17:50
0
游客
登录 | 注册 方可回帖
返回