首页
社区
课程
招聘
[转帖]OllyDumpEx v0.92 / 2012-10-09
发表于: 2012-10-28 06:22 15212

[转帖]OllyDumpEx v0.92 / 2012-10-09

2012-10-28 06:22
15212
This plugin is process memory dumper for OllyDbg and Immunity Debugger.

Very simple overview:

OllyDumpEx = OllyDump + PE Dumper - obsoluted + useful features

Features

· OllyDbg version 2 plugin interface supported (EXPERIMENTAL)
· Select to dump debugee exe or loaded dll
· Dump any address space as section even if not in original section header
· Add dummy section to keep PE format consistency
· Fix RVA in DataDirectory to follow ImageBase change
· Auto calculate many parameters (RawSize, RawOffset, VirtualOffset, ...)

Screenshot



Supported Debugger

· OllyDbg version 1.10 (tested 1.10)
· OllyDbg version 2.01 EXPERIMENTAL (tested 2.01 alpha 4)
· Immunity Debugger version 1.7x or (tested 1.73)
· Immunity Debugger version 1.8x or higher (tested 1.83)

This archive file contains plugin DLLs for each debuggers.

- v0.70 / 2011-07-01

Add: Support Immunity Debugger version 1.7x or lower
Improve: Data Directory rebuild option (support ImportTable)
Improve: Image Base Address alignment checking
Improve: Virtual Offset Address alignment checking

- v0.80 / 2011-07-15

Add: Support Immunity Debugger version 1.8x or higher
Improve: Data Directory rebuild option (check rewrite range)
Improve: Always round up PE header size to 0x1000 (ImportRec not extend itself)
Bugfix: TLS Data Directory ignored

- v0.90 / 2011-08-24

Add: Support OllyDbg version 2 plugin interface (EXPERIMENTAL)
Improve: Rewrite Wide/Multibyte-Character support code
Improve: Decode CopyOnWrite page attribute
Bugfix: Detect working directory

- v0.92 / 2012-10-09

Improve: Support OllyDbg version 2 plugin new interface  

http://low-priority.appspot.com/ollydumpex/OllyDumpEx.zip

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

收藏
免费 0
支持
分享
最新回复 (7)
雪    币: 3279
活跃值: (1997)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
此处删除,只是作测试安全宝对敏感词的拦截。
2012-10-28 06:36
0
雪    币: 2882
活跃值: (1279)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
yjd
3
唯一一张截图,竟然是看不到-_-!!。。
2012-10-28 09:16
0
雪    币: 768
活跃值: (530)
能力值: ( LV13,RANK:460 )
在线值:
发帖
回帖
粉丝
4
支持2.0插件
2012-10-28 09:20
0
雪    币: 107
活跃值: (404)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
有点意思的插件
2012-10-28 12:00
0
雪    币: 8906
活跃值: (4223)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
6
谁能本地一个不?
2012-10-29 23:38
0
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
7
論壇
_http://bbs.pediy.com/showpost.php?p=1111134&postcount=14
上传的附件:
2012-10-29 23:46
0
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
8
http://bbs.pediy.com/showthread.php?t=140295
上传的附件:
2012-10-29 23:47
0
游客
登录 | 注册 方可回帖
返回
//