Showing posts with label debug. Show all posts
Showing posts with label debug. Show all posts

Wednesday, July 6, 2011

Windbg Script for Kernelcallbacks under x86 Architecture

$$ x86 Kernel Callback Finder for CreateProcess/LoadImage/CreateThread/Registry

$$ Frank Boldewin / www.reconstructer.org



.printf "\nCreateProcess Callbacks:\n"

.printf "------------------------\n"



aS CPNAddr  "nt!PspCreateProcessNotifyRoutine";

aS CPNCount "poi(nt!PspCreateProcessNotifyRoutineCount)";

aS Counter  "@$t0";



.block

{

  .for (r ${Counter} = 0; ${Counter} < ${CPNCount}; r ${Counter} = ${Counter} + 1)

  {

    .printf "Callback: %d - Address: 0x%08x\n", ${Counter}+1, poi(((dwo(${CPNAddr} + ${Counter} *4))&-8)+4);

  }

}



.printf "\nLoadImage Callbacks:\n"

.printf "--------------------\n"



aS LINAddr  "nt!PspLoadImageNotifyRoutine";

aS LINCount "poi(nt!PspLoadImageNotifyRoutineCount)";



.block

{

  .for (r ${Counter} = 0; ${Counter} < ${LINCount}; r ${Counter} = ${Counter} + 1)

  {

    .printf "Callback: %d - Address: 0x%08x\n", ${Counter}+1, poi(((dwo(${LINAddr} + ${Counter} *4))&-8)+4);

  }

}



.printf "\nCreateThread Callbacks:\n"

.printf "-----------------------\n"



aS CTNAddr  "nt!PspCreateThreadNotifyRoutine";

aS CTNCount "poi(nt!PspCreateThreadNotifyRoutineCount)";



.block

{

  .for (r ${Counter} = 0; ${Counter} < ${CTNCount}; r ${Counter} = ${Counter} + 1)

  {

    .printf "Callback: %d - Address: 0x%08x\n", ${Counter}+1, poi(((dwo(${CTNAddr} + ${Counter} *4))&-8)+4);

  }

}



.printf "\nRegistry (CMP) Callbacks:\n"

.printf "-------------------------\n"



aS CMNAddr  "nt!CmpCallBackVector";

aS CMNCount "poi(nt!CmpCallBackCount)";



.block

{

  .for (r ${Counter} = 0; ${Counter} < ${CMNCount}; r ${Counter} = ${Counter} + 1)

  {

    .printf "Callback: %d - Address: 0x%08x\n", ${Counter}+1, poi(((dwo(${CMNAddr} + ${Counter} *4))&-8)+4);  

  }

}



ad ${/v:CPNAddr};

ad ${/v:CPNCount};

ad ${/v:LINAddr};

ad ${/v:LINCount};

ad ${/v:CTNAddr};

ad ${/v:CTNCount};

ad ${/v:CMNAddr};

ad ${/v:CMNCount};

ad ${/v:Counter};

Friday, November 26, 2010

IDA tut's

download link = http://www.mediafire.com/?w74a6zrb5j4p8gz
pss = e-omidfar.blogspot.com

Disassembling Code - IDA Pro And SoftICE

download link = http://www.mediafire.com/?0zjy3de2hka8tor
pass = e-omidfar.blogspot.com

Hacker Debugging Uncovered





download link = http://www.mediafire.com/?q7u2509iuc2bl7l
pass = e-omidfar.blogspot.com

Debugging Applications For Microsoft. NET And Microsoft Windows


download link = http://www.mediafire.com/?wcgdanwdp1y5bpt
pass = e-omidfar.blogspot.com

Reversing Secrets of Reverse Engineering

pages : 619
download = http://bl4ckh4t.persiangig.com/blog/Reversing.%20Secrets%20of%20Reverse%20Engineering%20.rar
pass : e-omidfar.blogspot.com