Flag: Tornado! Hurricane!

 Forums >>  IDA Pro  >>  ida plugin writing for dynamic analisis

Topic created on: June 2, 2013 09:34 CDT by aj3423 .

Hi,
I have a simple test.exe, and three questions:

1. It takes less than 1 second for IDA to analyze test.exe, by analyze I mean all functions listed, modules found. But why it takes about 10 seconds for function analyze_area() in debug mode? Here's the code executed in debug mode:
    analyze_area(0x401000, 0x40c000); // 401000==code_seg_start  40c000==code_seg_end

2. When dynamically loading .dll, any way to get the code segment of the dll? Include the segment start and segment size.
  If I hook HT_DBG like this:

int idaapi dbg_callback(void*, int event_id, va_list va) {
  if(event_id == dbg_library_load) {
    const debug_event_t* evt = va_arg(va, const debug_event_t*);
    module_info_t mod = evt->modinfo;
    // how to get the code_segment_start and code_segment_size ?
....


Thanks.

  ohyeah521   December 26, 2013 21:03.20 CST
use these api:
idaapi.patch_byte
idaapi.patch_long
idaapi.patch_many_bytes
idaapi.patch_word

Note: Registration is required to post to the forums.

There are 31,038 total registered users.


Recently Created Topics
Ultimate Hacking Cha...
Jun/21
CreateMutex
May/31
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Immunity Debugger Re...
Aug/03


Recent Forum Posts
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n
OOP_RE tool available?
van7hu
Should binaries be n...
Kolisar
Problem with ollydbg
nullx42
!findtrampoline Immu...
skycrack


Recent Blog Entries
crystalwade
Jul/20
test

nieo
Mar/22
Android Application Reversing

halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit