Flag: Tornado! Hurricane!

Error: Authentication required to access requested resource.

 Forums >>    >> 

Topic created on: by .


  comrade     March 17, 2010 03:24.15 CDT
What OS? Windows does not have anything like that.

  djnemo     March 20, 2010 07:49.57 CDT
you mean you want to 'hibernate' the process!!!

  comrade     April 6, 2010 00:17.04 CDT
Yes, hibernating the process is another way to call it. Though hibernate is a bit more specific... in hibernation you can throw certain state which you know you can rebuild under the assumption that whatever you are hibernating can be resumed back. Snapshots are more general.

  comrade     April 11, 2010 01:00.08 CDT
Look at the proceedings of the recent CanSecWest 2010 conference, in particular the "Full Process Analysis and Reconstitution of a Virtual Machine from the Native Host" presentation by Jamie Butler. A summary of it can be found here:
http://www.sophos.com/blogs/chetw/g/2010/03/30/cansecwest-2010-day-3-summary/

Essentially Jamie described a technique by which he derived process state from a VM snapshot.

  dzzie     April 12, 2010 17:11.39 CDT
i think dennis elsner had an ida plugin for this. never tried it but comes with source

http://old.idapalace.net/plugins6.html

  tosanjay     August 3, 2010 16:35.03 CDT
i don't know if it is addressing your query, but I recall Pydbg debugger which has a method for taking snapshot of the running process and later resume the process from that point onwards. it is: pydbg.process_snapshot()

Note: Registration is required to post to the forums.

There are 28,224 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
cmathieu
Feb/07
Hacker Carnival

waleedassar
Feb/06
OllyDbg v1.10 And Hardware ...

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

waleedassar
Jan/13
An OllyDbg Bug Disables Sof...

More ...


Recent Blog Comments
waleedassar on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/05
Yet Another Anti-Debug Trick

trolotou on:
Feb/05
Doudoune Moncler -Pennies F...

waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit