Flag: Tornado! Hurricane!

OpenRCE Win32 Call Chains Database

This reference section was initially contributed to OpenRCE by pedram.

The Win32 Call Chains database attempts to provide a useful and comprehensive interface to the function call trees of the main Microsoft Windows Dynamic Link Libraries (DLLs). The data-set was originally contructed during the development of a proof of concept Windows Intrusion Prevention System (IPS), similar to NAI Entercept and Okena/Cisco CSA. The information provided here was necessary to avoid the common mistake of not hooking "deep enough" (See Phrack 62 - 0x05) and is made available in hopes that others will find it useful and expand on it. The database is sectioned by Operating System and can be browsed and searched interactively. The following quick and dirty scripts were used to generate the data-set: An interactive Java visualization is available for each module under the 'graph' link, some of them are broken and still being debugged. If someone can write a nice custom graphing applet, please share.

 Windows 2000 SP4  Windows XP SP1  Windows XP SP2
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 
 Windows 2003 SE  Windows 2003 SE SP1  
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 

There are 28,229 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
cmathieu
Feb/07
Hacker Carnival

waleedassar
Feb/06
OllyDbg v1.10 And Hardware ...

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

waleedassar
Jan/13
An OllyDbg Bug Disables Sof...

More ...


Recent Blog Comments
waleedassar on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/05
Yet Another Anti-Debug Trick

trolotou on:
Feb/05
Doudoune Moncler -Pennies F...

waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit