Flag: Tornado! Hurricane!

 Forums >>  Debuggers  >>  Non invasive debugging ?

Topic created on: July 2, 2009 13:25 CDT by sft .

Hey,
I'm trying to debug some application but it seems to be quite restricted while being debugged, I've stripped most of it's protections (it's win32-based PE) yet the debugger keeps failing at debugging what's needed
I've digged a bit and found that there's something called "non-invasive debugging" is there any debugger out implemented that way (beside windbg) for win32 ?

Thanks in advance

  GynvaelColdwind     July 2, 2009 14:09.52 CDT
Hi,

Check this out:
http://deneke.biz/obsidian

Hmm, I wouldn't call it 'non-invasive' (the author calls it non-itrusive, but its almost the same), but it's interesting anyway, since it is not using Debugger API nor ring0 tricks.

However I did have some trouble using it ;< Hope you'll have better luck!

Take care!
G.C.

  Soul12     July 2, 2009 17:22.09 CDT
or you could take a look here

http://www.reverse-engineering.info/PE_Information/Crackers_Guide_To_Program_Flow.pdf

  Soul12     July 2, 2009 17:22.10 CDT
<ups double post>

  PeterFerrie     July 5, 2009 00:39.26 CDT
CreateToolhelp32Snapshot is very intrusive, since it inserts a thread in the target process, in order to gather certain information about that process.  This new thread is detected easily by the target process, and can cause a hostile reaction.  NtQueryInformationProcess should be used instead.

Note: Registration is required to post to the forums.

There are 28,212 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
Ludwig
Feb/04
chi on sale

Ludwig
Feb/04
Monster In The Vicinity Of ...

Ludwig
Feb/04
Supra footwear Online

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

More ...


Recent Blog Comments
waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

NirIzr on:
Jan/31
Yet Another Anti-Debug Trick

jackchen on:
Jan/10
nike mercurial vapor iii

waleedassar on:
Dec/27
A new Anti-Olly trick.

PeterFerrie on:
Dec/27
A new Anti-Olly trick.

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit