Flag: Tornado! Hurricane!

 Forums >>  Debuggers  >>  !jc ImmDbg Command Simple Return Adress Finder for Overflows

Topic created on: August 11, 2007 07:30 CDT by kernex .

jc.py is extension pycommand script for the immdbg (immunity Debugger) .
!jc allows quick search for finding return addresses for call/jmp registers (like ollyuni).
installation : copy the jc.py into pycommands directory .
usage        : !jc <reg>  for example : !jc ESP
all results be written to the log window (view->log or alt+l)
----
update : added push <reg> / ret like findtrampoline
http://www.openrce.org/forums/posts/559

  Faithless     August 15, 2007 09:16.57 CDT
Way to go silently modifying your code so that it matches up to all the extra instructions my findtrampoline.py finds.

You originally commented it as a JMP/CALL finder. Your line:
cmd=["jmp %s" %arg, "call %s" %arg ,"push %s\nret" % arg, "push %s\nretn" % arg]
certainly didn't look like that before you saw my comparable ID script, and copied the Python over.

  kernex   August 15, 2007 15:04.50 CDT
yes , i added push%s\nret after saw your script .
i edited my post.

Note: Registration is required to post to the forums.

There are 28,220 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
waleedassar
Feb/06
OllyDbg v1.10 And Hardware ...

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

waleedassar
Jan/13
An OllyDbg Bug Disables Sof...

waleedassar
Jan/01
Another OllyDbg Anti-Debug ...

More ...


Recent Blog Comments
NirIzr on:
Feb/05
Yet Another Anti-Debug Trick

trolotou on:
Feb/05
Doudoune Moncler -Pennies F...

waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

NirIzr on:
Jan/31
Yet Another Anti-Debug Trick

jackchen on:
Jan/10
nike mercurial vapor iii

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit