首页
社区
课程
招聘
[下载]The Narliest Windbg Extension Evar!
发表于: 2011-2-23 09:49 3602

[下载]The Narliest Windbg Extension Evar!

2011-2-23 09:49
3602
This windbg extension is intended to be able to:

list /SafeSEH, /GS, DEP, and ASLR info about all loaded modules
search for ROP gadgets
other misc utils
Currently, only listing info about loaded modules is implemented. Go to the downloads section to get the most recently compiled extension and pdb. For those of you who might download and use this extension, it would be worth it to check back every now and then for a new release, as a lot is currently in the works (or you could ping me directly). Also, if you find a bug with this extension, please let me know.

Example:

To "install", download one of the zips from the download page, extract narly.dll, and copy it in to the winext folder for windbg. The path to the winext folder usually looks something like this

C:\Program Files\Debugging Tools for Windows (x86)\winextAfter you do that, you can .load narly to load the extension into windbg:

0:018> .load narly

下载ab2K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3y4G2k6r3g2Q4x3X3g2Y4L8$3!0Y4L8r3g2Q4x3X3g2U0L8$3#2Q4x3V1k6H3i4K6u0r3L8X3q4J5L8s2W2Q4x3V1k6V1L8%4N6F1L8r3!0S2k6s2y4Q4x3V1k6V1k6i4c8S2K9h3I4Q4x3@1k6F1j5h3#2W2i4K6y4p5L8X3q4J5L8s2W2Q4y4h3j5H3i4K6u0W2x3g2)9J5k6i4A6A6M7q4)9J5y4X3y4S2L8W2)9K6c8o6u0Q4x3U0k6I4i4K6y4p5
narly_0.1.zip

总的来说就是windbg的扩展,可以检测SEH GS DEP ASLR等,ROP检测没有看到,估计后续版本会实现吧。。。。标记一下

[培训]传播安全知识、拓宽行业人脉——看雪讲师团队等你加入!

上传的附件:
收藏
免费 0
支持
分享
最新回复 (0)
游客
登录 | 注册 方可回帖
返回