Flag: Tornado! Hurricane!

 Forums >>  Debuggers  >>  !jc ImmDbg Command Simple Return Adress Finder for Overflows

Topic created on: August 11, 2007 07:30 CDT by kernex .

jc.py is extension pycommand script for the immdbg (immunity Debugger) .
!jc allows quick search for finding return addresses for call/jmp registers (like ollyuni).
installation : copy the jc.py into pycommands directory .
usage        : !jc <reg>  for example : !jc ESP
all results be written to the log window (view->log or alt+l)
----
update : added push <reg> / ret like findtrampoline
http://www.openrce.org/forums/posts/559

  Faithless     August 15, 2007 09:16.57 CDT
Way to go silently modifying your code so that it matches up to all the extra instructions my findtrampoline.py finds.

You originally commented it as a JMP/CALL finder. Your line:
cmd=["jmp %s" %arg, "call %s" %arg ,"push %s\nret" % arg, "push %s\nretn" % arg]
certainly didn't look like that before you saw my comparable ID script, and copied the Python over.

  kernex   August 15, 2007 15:04.50 CDT
yes , i added push%s\nret after saw your script .
i edited my post.

Note: Registration is required to post to the forums.

There are 31,056 total registered users.


Recently Created Topics
Ultimate Hacking Cha...
Jun/21
CreateMutex
May/31
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Immunity Debugger Re...
Aug/03


Recent Forum Posts
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n
OOP_RE tool available?
van7hu
Should binaries be n...
Kolisar
Problem with ollydbg
nullx42
!findtrampoline Immu...
skycrack


Recent Blog Entries
crystalwade
Jul/20
test

nieo
Mar/22
Android Application Reversing

halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit