Flag: Tornado! Hurricane!

Error: Authentication required to access requested resource.

 Forums >>    >> 

Topic created on: by .


  RabidCicada     March 5, 2010 10:35.58 CST
There could be many issues at hand but:

You can manually walk the LDR_MODULE structs in the PED_LDR_DATA struct as depicted by the windows memory layout https://www.openrce.org/reference_library/files/reference/Windows%20Memory%20Layout,%20User-Kernel%20Address%20Spaces.pdf.

Any reason to expect that there is purposeful module hiding?...or could you have your tool configured wrong?

  RabidCicada     March 5, 2010 10:47.01 CST
You can also run into problems viewing all loaded modules if you are debugging at the wrong level in terms of x86/x64 on a system where the OS is x64 and the application is x86.

When that happens windows loads the application under it's syswow emulation layer.

If you are debugging using x64 Windbg you will only see the stuff that is run at x64 level (syswow etc).  If you run the x86 windbg, then windbg is also running "on top of" the syswow emulation layer but "under" your target program and you will see much more informative and expected output.

Effectively x86 Windbg thinks it's running at the normal OS level and syswow takes care of translating expected calls and structures so that it returns information as if the syswow layer was the OS.  Your entire x86 Process, the modules loaded by the target x86 process, and x86 windbg will all be loaded "on top of" the syswow layer.

As a Side note....There are ways to get the x64 windbg to see the stuff on top of the emulation layer but I forget the commands etc.

Note: Registration is required to post to the forums.

There are 28,224 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
cmathieu
Feb/07
Hacker Carnival

waleedassar
Feb/06
OllyDbg v1.10 And Hardware ...

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

waleedassar
Jan/13
An OllyDbg Bug Disables Sof...

More ...


Recent Blog Comments
waleedassar on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/05
Yet Another Anti-Debug Trick

trolotou on:
Feb/05
Doudoune Moncler -Pennies F...

waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit