Flag: Tornado! Hurricane!

OpenRCE Win32 Call Chains Database

This reference section was initially contributed to OpenRCE by pedram.

The Win32 Call Chains database attempts to provide a useful and comprehensive interface to the function call trees of the main Microsoft Windows Dynamic Link Libraries (DLLs). The data-set was originally contructed during the development of a proof of concept Windows Intrusion Prevention System (IPS), similar to NAI Entercept and Okena/Cisco CSA. The information provided here was necessary to avoid the common mistake of not hooking "deep enough" (See Phrack 62 - 0x05) and is made available in hopes that others will find it useful and expand on it. The database is sectioned by Operating System and can be browsed and searched interactively. The following quick and dirty scripts were used to generate the data-set: An interactive Java visualization is available for each module under the 'graph' link, some of them are broken and still being debugged. If someone can write a nice custom graphing applet, please share.

 Windows 2000 SP4  Windows XP SP1  Windows XP SP2
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 
 Windows 2003 SE  Windows 2003 SE SP1  
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 

There are 16,686 total registered users.


Recently Created Topics
Need to lookup funct...
Mar/17
Process Snapshot
Mar/16
SSL keyfindert plugi...
Mar/15
ApiHooks.com down
Mar/15
how to crate a PATC...
Mar/10
wsnpoem audio.dll
Mar/09
suggestions - RE tra...
Mar/09
Requesting Suggestio...
Mar/06
Force enable debug p...
Mar/05
upgrading new image ...
Mar/03


Recent Forum Posts
SSL keyfindert plugi...
Johan
ApiHooks.com down
EliCZ
SSL keyfindert plugi...
Silkut
Process Snapshot
comrade
ApiHooks.com down
hkjack
how to crate a PATC...
comrade
ApiHooks.com down
comrade
suggestions - RE tra...
enm16
wsnpoem audio.dll
zhane
suggestions - RE tra...
Silkut


Recent Blog Entries
RolfRolles
Mar/08
Compiler Optimizations for ...

ReWolf
Mar/04
When memory management goes...

thesprawler
Feb/20
log1949.txt -- Wondering ho...

thesprawler
Feb/20
log1949.log -- created on C...

thesprawler
Feb/17
Trying to reverse the firmw...

More ...


Recent Blog Comments
Boken on:
Mar/12
Compiler Optimizations for ...

wildinto on:
Mar/10
Compiler Optimizations for ...

Orr on:
Mar/10
Compiler Optimizations for ...

bughoho on:
Mar/09
Compiler Optimizations for ...

cliffwolf on:
Mar/08
Compiler Optimizations for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit