Flag: Tornado! Hurricane!

Blogs >> joestewart's Blog

Created: Friday, August 26 2005 13:24.26 CDT Modified: Wednesday, September 7 2005 17:09.20 CDT
Printer Friendly ...
Anti-anti-dattach OllyDbg Plugin
Author: joestewart # Views: 2727

Piotr recently came up with a cool technique to hook NtContinue in order to prevent debugger attaching (see Piotr's blog for more details).

For fun, I've written an OllyDbg plugin called AttachAnyway to bypass Piotr's anti-dattach protection and allow you to attach to a protected process. It's pretty straightforward, it just enumerates all processes, looking for a hook on the first 5 bytes of NtContinue, and if it finds one, lets you restore the original code and call OllyDbg's Attachtoactiveprocess export. Nothing particularly earth-shattering, but perhaps more code examples like this could inspire more people to write OllyDbg plugins. :)

It should be available in the OpenRCE downloads section soon, but for now you can get it from:

http://www.joestewart.org/tools/attachanyway.zip

Also included in the zip file is an assembled version of Piotr's anti-dattach.asm for testing purposes, along with the source code to the plugin.




Add New Comment
Comment:









There are 31,314 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
hi!
Jul/01
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit