📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Debuggers  >>  Exceptions catching in OllyDbg

Topic created on: February 26, 2006 16:43 CST by alojzy .

Another problem I met today is when apps catches Access Violation. OllyDbg (on WinXP SP2) breaks but EIP doesn't point to instruction which causes exception :/ Any idea ?
On Windows 2000 it works properly.

I also installed the latest SoftIce. On XP SP2 It doesn't catch exception at all.

  alojzy     February 26, 2006 19:24.52 CST
:) I solved problem for SoftICE, 'early boot' option must be on.

  anonymouse     February 27, 2006 11:46.34 CST
Log data, item 0
Address=00401592
Message=Access violation when writing to [008B1000]

ther eip is logged and shown

the info window

DS:[008B1000]=???
Jump from MEM_TEST+0C2
except2.MEM_TEST+0B4


registers
EAX 0000000D
ECX 00001001
EDX 00140608
EBX 004020F1 ASCII "008B0FFFh ...  "
ESP 0012FA88
EBP 0012FB30
ESI 004020E6 ASCII "Writing to 008B0FFFh ...  "
EDI 008B1000
EIP 00401592 except2.00401592

how do you it doesnt catch exception at all ?
have you asked ollydbg to pass exception to the program itself ? in that case ollydbg wont stop on exceptions and it will be automatically handled

  alojzy     February 27, 2006 13:59.49 CST
Hi anonymous ;)
wow openrce.org works after attaching.. this is fuckin exception :P
Try with flickr.com .. gmail.com or any other!

  alojzy     February 27, 2006 14:06.25 CST
Another situation where OllyDbg fails - Java..
Does anybody have experience with debugging browser executing java applet?
  

  aeppert     February 27, 2006 16:14.31 CST
Not surprising Olly fails while debugging a JVM through a browser.  I have gotten this to work via Windbg in the past, but I honestly had to stand on my head a few times over (has been quite awhile ago.)  My attempts with Olly ended up an utter failure, not sure if it is a threading issue or a shear size problem with Olly when it comes to this situation.

  warl0ck     March 2, 2006 11:53.14 CST
I think applets and everything go too deep into the browser
its not ie alone, but also active x controls and all that.

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit