Flag: Tornado! Hurricane!

 Forums >>  Debuggers  >>  How to Debug debuged process using Windbg

Topic created on: September 29, 2009 13:14 CDT by Nadya .

Hi

I have this problem that I need to analyze piece of AMD64 assembly code. First process lets call it A creates and debugs process B using CreateProcessA (DEBUG_PROCESS+ DEBUG_ONLY_THIS_PROCESS), WaitForDebugEvent, ContinueDebugEvent. Piece of code that I want to analyze is inside B process and I can't analyze it statically it has to be dynamically. I was trying get inside B process using WinDbg(kernel debugging) setting int 3h inside B process but WinDbg refuses to debug debugged process, next I was trying to break on B process API's but no luck here either. Please can someone help me out, how to break inside B proces? I'm new when it comes to windbg.

  cod     September 30, 2009 23:12.37 CDT
try with "Noninvasive debugging mode"

http://msdn.microsoft.com/en-us/library/cc266358.aspx

you can try also with statically analysis of 2nd process using the memory dump, or trying to emulate process A

  Nadya   October 7, 2009 16:09.05 CDT
ok thanks for help seems "Noninvasive debugging mode" is the only way for me

  DelightedZuk     October 8, 2009 13:14.16 CDT
you can also change the flags of create process and nop all the other calls, and attach it to your debugger instead of the callee debugger.

Note: Registration is required to post to the forums.

There are 28,225 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
cmathieu
Feb/07
Hacker Carnival

waleedassar
Feb/06
OllyDbg v1.10 And Hardware ...

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

waleedassar
Jan/13
An OllyDbg Bug Disables Sof...

More ...


Recent Blog Comments
waleedassar on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/05
Yet Another Anti-Debug Trick

trolotou on:
Feb/05
Doudoune Moncler -Pennies F...

waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit