📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Debuggers  >>  OllyDBG Settings

Topic created on: January 19, 2007 12:24 CST by DennisRand .

Hey there

Does any of you know a paper or something that describes the best way to configure OllyDBG when handling Malware?

  pedram     January 19, 2007 12:36.47 CST
Depends on the malware really. In the least you should be using the Hide Debugger plugin.

  DennisRand     January 19, 2007 12:44.09 CST
Thanks Pedram

  fileoffset     January 23, 2007 00:55.15 CST
You might also want to modify the OllyDbg class and window names and at the very least, turn off - let the target program handle - all exceptions, at least to begin with.

  Anordem     January 23, 2007 07:17.50 CST
Hi,

I think that you should know your tools before using them on malwares. There is no "best way" to configure OllyDbg. Your configuration might suit your need.

For example, you could uncheck all exceptions handling in "Debugging Options -> Exceptions" to break on all SEH tricks. You could also check "system Breakpoint" in Events option to break before the entry point and handle TLS. You could choose to break on new thread or new module. It's up to you ! And to malware.

But if you ask this question, I think that you should learn how to use OllyDbg first.

  streamline   March 15, 2007 20:11.24 CDT
maybe you could use ollydbg and the maleware in a vmware enviroment (depending on the maleware and protection of course) this would save you from causing damage to your system hopefullly.

Greetz

  pedram     March 15, 2007 20:13.20 CDT
You'll definitely want to install this bad ass plug-in as well:

http://www.openrce.org/downloads/details/241/Olly_Advanced

  drew     March 15, 2007 20:59.46 CDT
> pedram: You\'ll definitely want to install this bad ass plug-in as well:
>
> http://www.openrce.org/downloads/details/241/Olly_Advanced

Nice tool!  It looks like I should clean out half a dozen of my olly plugins and replace them with olly_advanced.

  anonymouse     March 16, 2007 01:56.44 CDT
pedram you have a little bit older version on your downloads there are atleast 6 more revision iirc the beta is 12 now ive uploaded the 1.26 beta 12 to my repo
check it out and if it has a few more improvements and update the download

oops repo upload says cant process upload :(

Error: Failed processing upload to repository.

ill mail you the rar

edit

possibly some ghost views or lack of sleep i can promise that the download was 1.26 version 6 when i read your message but the link in above post shows beta 12

so sorry for dumb posts

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit