Flag: Tornado! Hurricane!

IDA Plugins: Stealth

File Information
Category Open Source # Downloads Version
IDA Plugins Yes 3,080 1.0

Download from OpenRCE
MD5 Sum: 61E81DC742A4E554E049BD773BFABDCE

Last updated on Mar 28, 2006.

Author Information
Username Name E-Mail URL
  ilfak Ilfak Guilfanov ighexblogcom http://

Description Anti-anti-debugger plugin for IDA Pro. (Stealth). Version 1.0.
Hides IDA Pro from the application and disables some potentially dangerous Windows API functions.

The plugin uses one simple trick: a conditional breakpoint at the beginning of an API function so that the breakpoint condition changes the execution flow to make the function immediately return to the caller without doing anything. Here is a condition example:

(EIP=retaddr) && (EAX=0)

In other words, we jump to the 'ret' instruction and set EAX to the desired value. Zero in the condition can be replaced by any other value we want to return from the function.

There are 28,631 total registered users.


Recently Created Topics
windbg - olly/immunity
May/14
Reverse a WinRAR pac...
May/13
Add comments to resu...
May/10
can we code script ...
May/09
Type Casting Structu...
May/07
How to Reverse Engin...
May/03
Sulley on OS X (10.7)
May/01
Help me guys
May/01
IDA Resource Viewer ...
Apr/28
How do i use plugins...
Apr/27


Recent Forum Posts
windbg - olly/immunity
blowcheck
Help me guys
Olivier
Reverse a WinRAR pac...
NirIzr
windbg - olly/immunity
anonymouse
Reverse a WinRAR pac...
DriEm
Add comments to resu...
phn1x
IDA Resource Viewer ...
DriEm
Add comments to resu...
qiuhan
IDA Resource Viewer ...
waleeda...
IDA Resource Viewer ...
DriEm


Recent Blog Entries
waleedassar
Apr/20
OllyDbg NumberOfSections Crash

icegood
Apr/13
Advanced labels plugin for ...

waleedassar
Mar/31
GetModuleFileNameEx And Inf...

waleedassar
Mar/31
OllyDbg v1.10 And Wow64

waleedassar
Mar/29
OllyDbg Resource Table Pars...

More ...


Recent Blog Comments
raxen on:
Mar/27
Anti-Dumping

Dallas on:
Mar/22
ChapljaVM Code Obfuscator

Dallas on:
Mar/22
Hack stuff, get paid

Dallas on:
Mar/22
Exe Packer TAGGANT system f...

Dallas on:
Mar/22
Olly2 SystemTray Plugin

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit