Flag: Tornado! Hurricane!

OpenRCE Article Comments: Process Stalker vs. MS05-030

Article Abstract Process Stalker is a tool-set I put together that is capable of visually producing run-time profiles, state mapping and tracing. The goal of a successful stalk is to provide the reverse engineer with a targeted and intuitive interface to run-time block-level trace data.

This article serves as an intro-by-example to Process Stalker (Note: Process Stalker has since been deprecated by PaiMei) by providing a walk-through of the MS05-030 Microsoft Outlook Express NNTP Response Parsing Buffer Overflow Vulnerability. Further details, source code, binaries and manuals are available in the bundled Process Stalker archive available from the downloads page.

Full Article ...    Printer Friendly ...

Article Comments
fluxist Posted: Monday, July 11 2005 23:38.32 CDT
I am very impressed with the Process Stalker toolset and this article as well. Its so rare to read a really well written article of this nature. Keep up the good work! Im totally psyched to try out the toolset...

pedram Posted: Tuesday, July 12 2005 11:18.52 CDT
Much appreciated, thanks. There are some bug fixes I have made in response to community feedback that will be included in an updated release tomorrow. They are:

- gml.py: Fixed bug in parsing of GDE saved GML files.
- ps_state_mapper.py: Fixed bug in handling of filename arguments containing directory modifiers. ex: './seh.gml' and '../seh.gml'.
- process_stalker.exe: Replaced reliance on DebugActiveProcessStop() and DebugSetProcessKillOnExit() function resolution with dynamic function loading. This was preventing the tracer from running on systems that don't support the API such as Windows 2000.


Add New Comment
Comment:










Active in Last 5 Minutes
sacspc

There are 29,955 total registered users.


Recently Created Topics
pydbg bp_set_mem
Jun/18
Disassembling Motoro...
Jun/13
ida plugin writing f...
Jun/02
New version of RE-Go...
May/29
Decompiling raw bina...
May/22
Incorrect bitness wh...
May/20
PaiMei stalker modul...
May/19
Attach to program us...
May/13
IDA PRO how to make ...
May/12
FACT: OpenRCE is dead.
May/08


Recent Forum Posts
pydbg bp_set_mem
kitochou
pydbg, memory breakp...
kitochou
Good Binary Code Pro...
alton
Int 3 anti debug?
SteveIRQL
Attach to program us...
SteveIRQL
Ollydbg 2.0 - Plugin...
openrce...
IDA PRO how to make ...
codeinject
FACT: OpenRCE is dead.
codeinject
IDA Resource Viewer ...
r2x64
FACT: OpenRCE is dead.
djnemo


Recent Blog Entries
26yyg1kf
Jun/19
your muscles get larger Men...

26yyg1kf
Jun/19
Mens 2011 Vibram Classic fo...

26yyg1kf
Jun/19
Vivo Barefoots up to Discou...

kitochou
Jun/18
pydbg

lowpriority
Apr/13
OllyMigrate Plugin for Olly...

More ...


Recent Blog Comments
newlulu on:
Jun/10
Branch tracing and LBR acce...

newlulu on:
Jun/10
Advanced debugging techniques

newlulu on:
Jun/10
2 anti-trace mechanisms spe...

newlulu on:
Jun/10
OllyMigrate Plugin for Olly...

clarisonic on:
Apr/03
New version of Ollydbg!

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit