Flag: Tornado! Hurricane!

OpenRCE Win32 Call Chains Database

This reference section was initially contributed to OpenRCE by pedram.

The Win32 Call Chains database attempts to provide a useful and comprehensive interface to the function call trees of the main Microsoft Windows Dynamic Link Libraries (DLLs). The data-set was originally contructed during the development of a proof of concept Windows Intrusion Prevention System (IPS), similar to NAI Entercept and Okena/Cisco CSA. The information provided here was necessary to avoid the common mistake of not hooking "deep enough" (See Phrack 62 - 0x05) and is made available in hopes that others will find it useful and expand on it. The database is sectioned by Operating System and can be browsed and searched interactively. The following quick and dirty scripts were used to generate the data-set: An interactive Java visualization is available for each module under the 'graph' link, some of them are broken and still being debugged. If someone can write a nice custom graphing applet, please share.

 Windows 2000 SP4  Windows XP SP1  Windows XP SP2
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 
 Windows 2003 SE  Windows 2003 SE SP1  
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 

There are 21,678 total registered users.


Recently Created Topics
PyEmu error when cal...
Sep/02
Restore Themida/Winl...
Sep/02
Anti-olly technique
Aug/30
RAR Password
Aug/29
Heap protection on W...
Aug/23
Why Inline asm in C+...
Aug/20
Bypassing OllyAdvance
Aug/17
Error in logic for g...
Aug/17
Has anyone seen this...
Aug/17
ARM Executable - Pat...
Aug/16


Recent Forum Posts
reverse engineering ...
raiden56
pydbg, memory breakp...
Researc...
RAR Password
Ineedhelp
RAR Password
cod
Heap protection on W...
voila
Heap protection on W...
j00ru
Heap protection on W...
voila
Heap protection on W...
j00ru
Heap protection on W...
psylocn
Why Inline asm in C+...
ronnie2...


Recent Blog Entries
meshmesh
Sep/01
Is it legal??

waleedassar
Aug/30
Anti-olly technique

QvasiModo
Aug/24
WinAppDbg 1.4 is out!

artemblagodarenko
Aug/18
Dataflow-0.2.0 released. Ne...

grzonu
Aug/17
Bypassing OllyAdvanced

More ...


Recent Blog Comments
tosanjay on:
Sep/02
PyEmu 0.0.2

GynvaelColdwind on:
Sep/01
Is it legal??

PeterFerrie on:
Aug/31
Anti-olly technique

dennis on:
Aug/26
Dr. Gadget IDAPython plugin

halsten on:
Aug/19
Dataflow-0.2.0 released. Ne...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit