HOME    FORUMS    MEMBERS    RECENT POSTS    LOG IN  
Баннер 1   Баннер 2

ANTICHAT — форум по информационной безопасности, OSINT и технологиям

ANTICHAT — русскоязычное сообщество по безопасности, OSINT и программированию. Форум ранее работал на доменах antichat.ru, antichat.com и antichat.club, и теперь снова доступен на новом адресе — forum.antichat.xyz.
Форум восстановлен и продолжает развитие: доступны архивные темы, добавляются новые обсуждения и материалы.
⚠️ Старые аккаунты восстановить невозможно — необходимо зарегистрироваться заново.
Вернуться   Форум АНТИЧАТ > ПРОГРАММИРОВАНИЕ > Реверсинг
   
Ответ
 
Опции темы Поиск в этой теме Опции просмотра

  #61  
Старый 11.09.2008, 18:11
0x0c0de
Постоянный
Регистрация: 25.05.2007
Сообщений: 448
Провел на форуме:
4226446

Репутация: 1564
Отправить сообщение для 0x0c0de с помощью ICQ
По умолчанию

[Immunity Dbg Plugins]

1.IMM-PhantOm.v.1.30
2.IMMHideDebugger.v1.24
3.IMMODbgScript.ENGLISH.1.65

http://reversengineering.wordpress.com/2008/09/11/3-new-plugins-for-immunity-debugger/
 
Ответить с цитированием

  #62  
Старый 13.09.2008, 21:43
0x0c0de
Постоянный
Регистрация: 25.05.2007
Сообщений: 448
Провел на форуме:
4226446

Репутация: 1564
Отправить сообщение для 0x0c0de с помощью ICQ
По умолчанию

[X3 0.1]

Мелочь, а приятно

Цитата:
A plugin which gives you quick access to RegEdit, Calculator and EnableDebugPrivilege.
http://tuts4you.com/download.php?view.2474
 
Ответить с цитированием

  #63  
Старый 21.09.2008, 12:00
0x0c0de
Постоянный
Регистрация: 25.05.2007
Сообщений: 448
Провел на форуме:
4226446

Репутация: 1564
Отправить сообщение для 0x0c0de с помощью ICQ
По умолчанию

1. [AMDUMPV62 V2.2]

Цитата:
Dumper for ActiveMark 6.2 -FULL Sources and TWO Tutorials included-
2. [ ArmaG3ddon V1.5.1]

Цитата:
Armag3ddon Armadillo unpacking tool designed specifically to deal with the many protection features available in versions 3.78 thru 6.04 (see readme.txt for details)
download

http://arteam.accessroot.com/releases.html
 
Ответить с цитированием

  #64  
Старый 24.09.2008, 12:09
ProTeuS
Познавший АНТИЧАТ
Регистрация: 26.11.2004
Сообщений: 1,367
Провел на форуме:
4226592

Репутация: 2175


Отправить сообщение для ProTeuS с помощью ICQ
По умолчанию

PatchDiff Ida 5.2 Plugin

Description
PatchDiff2 is a plugin for the Windows version of the IDA dissassembler that can analyze two IDB files and find the differences between both. PatchDiff2 is free and fully integrates with the latest version of IDA (5.2).
The plugin can perform the following tasks :
Display the list of identical functions
Display the list of matched functions
Display the list of unmatched functions (with the CRC)
Display a flow graph for identical and matched functions
The main purpose of this plugin is to be fast and give accurate results when working on a security patch or a hotfix. Therefore this tool is not made to find similar functions between two different programs.
Patchdiff2 supports all processors that IDA can handle and is available in two versions: 32 bit and a 64 bit.

patchdiff2 is freely distributed to the community by Tenable Network Security in the hope it will be useful to you and help research engineers to better analyze different patches. However, Tenable does not provide support for this tool and offers no garantee regarding its use or output. Please read the end-user license agreement before using this program.

demo video: http://cgi.tenablesecurity.com/tenable/pdiff2.swf.html
download: http://cgi.tenablesecurity.com/tenable/patchdiff.php
 
Ответить с цитированием

Kartoffel 1.4
  #65  
Старый 25.09.2008, 09:13
neprovad
Постоянный
Регистрация: 19.10.2007
Сообщений: 794
Провел на форуме:
1013791

Репутация: 711


По умолчанию Kartoffel 1.4

Kartoffel 1.4
Kartoffel - command-line утилита для проверки драйверов на уязвимости к входным и выходным данным как своих так и сторонних. На официальном сайте, помимо самой программы, есть видео, показывающее принципы и методы работы.
Сайт
 
Ответить с цитированием

  #66  
Старый 28.09.2008, 17:36
0x0c0de
Постоянный
Регистрация: 25.05.2007
Сообщений: 448
Провел на форуме:
4226446

Репутация: 1564
Отправить сообщение для 0x0c0de с помощью ICQ
По умолчанию

Плагин для IDA, название говорит само за себя

[DePack APLIB-LZMA 0.1]

download
http://tuts4you.com/download.php?view.2485
 
Ответить с цитированием

  #67  
Старый 31.10.2008, 23:27
balt
Banned
Регистрация: 30.10.2008
Сообщений: 8
Провел на форуме:
339315

Репутация: 16
По умолчанию

dup 2.18 Final
replaced WinExec API by ShellExecute for Windows Vista
-bugfix in Dialog for editing S&R Pattern Occurrence
-added check for skin button IDs
-improved window resizing engine
-added option “trim to path” for Registry Paths
-loader can save now targetfilepath to inifile when its not in same folder
-added TitchySID player for .sid file playback
-added new option for attached files: overwrite existing file
-added support for disabled patch button skin
-added multilanguage support
-fixed bug with tooltip width. long hexpatterns are displayed now in multiple lines
-compiled with new MASM v10
-bugfix when executing attached files
-bugfix for resource (skin) updater
-strings for patcher.exe can be modifed now inside a skin

Download!

Syser Debugger 1.99.1900.1095

Syser Debugger is designed for Windows NT Family based on X86 platform. It is a core-level debugger with full-graphical interfaces and supports assembly debugging and source code debugging. Syser Debugger is able to debug Windows applications and Windows drivers. Don’t leech from kopona.netSyser Debugger perfectly combines the functions of IDA Pro, Softice and Ollydbg, which makes operations easier and faster and provides powerful functions. It supports multi-CPU and Intel Hyper-Threaded processors.

Features:
- Supports color disassembly.
- Source code debugging supports syntax coloring.
- Source code debugging supports collapsing mapping between source code and assembly instructions.
- Supports dynamic loading and unloading.
- entire keyboards operations support. (If is doing not have mouse equipment situation all operations all to be allowed to use keyboard to operate)
- Full mouse action support (if no keyboard is available, all operations can be performed through mouse commands).
- Commands are Softice-compatible
- Multi-language support, fully implemented unicode at low level.
- Supports plug-ins.
- Supports multi-CPU and Intel Hyper-Threaded processors.
- Supports startup scripts (similar to batch files).
- Supports clipboard function, able to copy data from Ring 3 debugger to Ring 0 debugger.
- Fully supports PDB debugging symbol files.
- Automatically load drivers to debug.
- Supports comments adding when debugging.
- Supports bookmark function.
- Don’t leech from kopona.net.
- Address navigation is supported in disassembly windows and users can browse different functions quickly by double-clicking.
- Source code debugging supports quick view of variables and users can view variable types and values by moving cursor over variable names.
- Syser is the perfect combination of IDA and Softice functions.
- Supports address cross-reference lists.
- Supports data reference lists.
- Supports the advanced processing modes of pointing devices, such as TouchPad, TrackPoint.
- Supports multiple data windows.
- Supports multiple code windows to facilitate the browsing of assembly code.
- Supports run trace mode for ollydbg.

PEiD

PEiD is special in some aspects when compared to other identifiers already out there!

1. It has a superb GUI and the interface is really intuitive and simple.
2. Detection rates are amongst the best given by any other identifier.
3. Special scanning modes for *advanced* detections of modified and unknown files.
4. Shell integration, Command line support, Always on top and Drag’n'Drop capabilities.
5. Multiple file and directory scanning with recursion.
6. Task viewer and controller.
7. Plugin Interface with plugins like Generic OEP Finder and Krypto ANALyzer.
8. Extra scanning techniques used for even better detections.
9. Heuristic Scanning options.
10. New PE details, Imports, Exports and TLS viewers
11. New built in quick disassembler.
12. New built in hex viewer.
13. External signature interface which can be updated by the user.

There are 3 different and unique scanning modes in PEiD.

The *Normal Mode* scans the PE files at their Entry Point for all documented signatures. This is what all other identifiers also do.

The *Deep Mode* scans the PE file’s Entry Point containing section for all the documented signatures. This ensures detection of around 80% of modified and scrambled files.

The *Hardcore Mode* does a complete scan of the entire PE file for the documented signatures. You should use this mode as a last option as the small signatures often tend to occur a lot in many files and so erroneous outputs may result.

The scanner’s inbuilt scanning techniques have error control methods which generally ensure correct outputs even if the last mode is chosen. The first two methods produce almost instantaneous outputs but the last method is a bit slow due to obvious reasons!
Download!
 
Ответить с цитированием

  #68  
Старый 09.11.2008, 23:27
balt
Banned
Регистрация: 30.10.2008
Сообщений: 8
Провел на форуме:
339315

Репутация: 16
По умолчанию

OllyDbg modified :


OllyDbg - BoomBox


OllyDbg - Chinese

OllyDbg - CiM’s


OllyDbg - Diablo’s


http://rapidshare.com/files/25395171/request.php_2


http://letitbit.net/download/6bb5753...dated.rar.html

OllyDbg - ExeCryptor
http://rapidshare.com/files/25395311/request.php_553

OllyDbg - Hacnho’s
http://rapidshare.com/files/25395639/request.php_4


OllyDbg - OllyICE


http://rapidshare.com/files/25395646/request.php_5

ollyice 2007.9.21


http://rapidshare.com/files/60720683...E2007.9.21.rar

bigice 5
http://rapidshare.com/files/26791856/bigice5.zip

ollyice 2008.1.1
http://rapidshare.com/files/11555017...CE_2008.1.1.7z
http://letitbit.net/download/b2ab7b7...8.1.1.rar.html



OllyICE v1.10


http://rapidshare.com/files/13279083....10_update.rar


OllyICE TheMida MOD. By EvOlUtIoN

http://letitbit.net/download/90b2a39...UtIoN.rar.html
http://rapidshare.com/files/13814919..._EvOlUtIoN.rar


OllyDbg - Shadow
http://rapidshare.com/files/25395640/request.php_6

OllyDbg - Unmodified!

http://rapidshare.com/files/25395641/request.php_1

OllyDbg-flyODBG

http://rapidshare.com/files/26789936/flyjnop790.zip

ollydbg - ricardo nar.

http://rapidshare.com/files/26791858/ricarcdon.zip

OllyDbg_SLV edition

http://rapidshare.com/files/26791862/slv.zip

OllyDbg -Arabic
http://rapidshare.com/files/26791864/ice1_3.zip

Ollydbg - xp
http://rapidshare.com/files/26771160/ollydbg_110_xp.rar

Ollydbg - greenstyle

http://rapidshare.com/files/26436069..._20jnop790.rar

OllyDbg - armadillo
http://rapidshare.com/files/34817803...th_20tools.zip

OllyDbg - xp+ dct
http://rapidshare.com/files/34821367...20xp_20DCT.zip

OllyDbg - ADO
http://rapidshare.com/files/34821368/ODbgADO.zip

OllyDbg - SND
http://rapidshare.com/files/34821374/ODbgSnD.zip

OllyDbg -D2K2
http://rapidshare.com/files/34821377/ODbgD2k2.zip

OllyDbg - DeFixed

http://rapidshare.com/files/39044055...ed_Edition.rar


OllyDbg - DeFixed v2 (foff)

http://rapidshare.com/files/60718378...Edition_v2.rar

OllyDbg - ExeCryptor

http://rapidshare.com/files/39851301/exec.olly.zip

olly bronco (mod. for execryptor )


http://rapidshare.com/files/66345462....10_Bronco.rar

olly YPOGEiOS DOX DiViSiON

http://rapidshare.com/files/66345700...d-YPOGEiOS.rar

OllyDbg’ - Snd version all plugins and olly patched :


http://rapidshare.com/files/44123914...g_Beta_Full.7z

the 0dbg for Themida/WinLicense V1.9.3.0

http://rapidshare.com/files/50611549/The0DBG.exe


HanOlly

http://rapidshare.com/files/64369450...hemida_1.9.rar

ollydbg modified for themida 1.9.5

http://rapidshare.com/files/65716863...emida1.9.5.EXE

ollydbg modified for themida and execryptor

http://letitbit.net/download/d35cd71...MODBG.rar.html

ollydng Sabre Gold
http://rapidshare.com/files/98483227...abre-_Gold.rar

DarkOlly
http://rapidshare.com/files/137296680/DarkOlly.7z

OllyDbg 1.10 - kamal

http://letitbit.net/download/9e844d4...kamal.rar.html

OllyDbg v1.10 LifeODBG v1.4

http://letitbit.net/download/686a953...-v1.4.rar.html

OllyDBG The_Best_version

http://rapidshare.com/files/14254448...st_version.rar

http://letitbit.net/download/ffb7455...rsion.rar.html

OllyDbg 2

http://rapidshare.com/files/64369705...-_20_oct07.exe


OllyDbg v2.00 Alpha 4

http://letitbit.net/download/a51bdc7...pha-4.zip.html

OllyDbg v2.00 Alpha Sabre-Gold

http://letitbit.net/download/3571634...-Gold.rar.html

oLLYdbg 2.00 g

http://letitbit.net/download/0768f76...g200g.zip.html


> all patches for OllyDbg 1.x<

http://rapidshare.com/files/35977772...l_patches_.rar
 
Ответить с цитированием

  #69  
Старый 24.11.2008, 17:31
ZUNAMI
Новичок
Регистрация: 17.09.2007
Сообщений: 24
Провел на форуме:
52992

Репутация: 15
По умолчанию

OllyDbg 1.10:
----------------------------------------------------------------------
+ New look
+ Modified code for almost perfect hiding
+ Win32 API help reference
+ Modified code for expanded windows
+ Modified code for %s overflow RCE exploit
+ Modified code to make symbols load properly
+ OllyDRX Plugin Patcher
+ Plugin Development Kit & Script Editor v2.0

Tools:
----------------------------------------------------------------------
DUP2.18.3 + DRX Skins
LordPE Deluxe b
PEiD 0.95 + Database
Resource Hacker 3.4.0.79
.NET Reflector 5.1.4.0
DeDe 3.50.02 Build 1619
ASCII-Tabelle (PDF)
Universal Extractor 1.6
VB Decompiler Lite 6.0
Import Reconstructor 1.7c
Wark 1.3
PE Tools 1.5.400
VeoVeo 3.4
TeLock 0.98
MASM v10
WinASM v5.1.5.0
CrypTool 1.4.21
Hiew 7.26 *removed*
W32Dsm 8.93 + BratPatch 3 final + new look *removed*

Plugins:
----------------------------------------------------------------------
+BP-OLLY Ver 2.0 beta 4
Olly Advanced 1.25 Master Edition
AnalyzeThis! v0.1
Bookmark v1.06
CommandBar 3.20.110
ODbgScript v1.64.3
OllyDump v3.00.110
Olly TBar Manager (Gold)
Olly More Menu 1.3b
DataRipper 1.3
CleanupEx 1.12.108

Scripts:
----------------------------------------------------------------------
629 Scripts

Unpackers:
----------------------------------------------------------------------
Stripper 2.11 RC2
DilloDIE 1.6
Unpacker Execryptor 1.0 RC1
UnThemida 2.0
Themida/WinLicense Unpacker 2.0

DOWNLOAD LITE:
h++p://depositfiles.com/files/ft5n6vn58
h++p://w18.easy-share.com/1702463352.html
h++p://www.filefactory.com/file/ac9034/n/OllyDRX-lite_rar
h++p://www.megaupload.com/de/?d=U7MRQDMS
h++p://www8.zippyshare.com/v/75599538/file.html
h++p://rapidshare.com/files/164776142/OllyDRX-lite.rar.html
h++p://uploaded.to/?id=1512vy
h++p://www.zshare.net/download/51462688fc5d1b2b/
DOWNLOAD FULL :
h++p://www.filefactory.com/file/fb07d8/n/OllyDRX-final_rar
h++p://www7.zippyshare.com/v/15221987/file.html
h++p://rapidshare.com/files/164774793/OllyDRX-final.rar.html
h++p://uploaded.to/?id=qo8hz5
h++p://w18.easy-share.com/1702463283.html
h++p://www.megaupload.com/de/?d=E149X23L
h++p://www.zshare.net/download/514630138c46ce01/

PASSWORD:derox

Последний раз редактировалось ZUNAMI; 02.12.2008 в 15:17..
 
Ответить с цитированием

  #70  
Старый 28.11.2008, 21:51
0x0c0de
Постоянный
Регистрация: 25.05.2007
Сообщений: 448
Провел на форуме:
4226446

Репутация: 1564
Отправить сообщение для 0x0c0de с помощью ICQ
По умолчанию

[c32asm 0.8.8]
Цитата:
A W32Dasm alternative disassembler in English and Chinese. Unfortunately this tool is no longer in development, 0.4.12 is the last known official version released. However various individuals have continued adding slight improvements and bug fixes to it. This is the result of one of those continues works which has now reached version 0.8.8.

c32asm disassembler supports the following features:

Import functions list
Export functions list
Strings list
Jump trace
Hex editor
API Lookup
http://tuts4you.com/download.php?view.1130

скрин

http://img370.imageshack.us/my.php?image=sccrch1.jpg

в ini только язык на english сменить C32ASM.INI
language=0
 
Ответить с цитированием
Ответ



Похожие темы
Тема Автор Раздел Ответов Последнее сообщение
Microsoft разработала новый инструментарий для борьбы со спамом Dracula4ever Мировые новости. Обсуждения. 2 17.07.2006 20:14



Здесь присутствуют: 1 (пользователей: 0 , гостей: 1)
 


Быстрый переход




ANTICHAT.XYZ