首页
社区
课程
招聘
[转帖]Swordfish 1.3 by Insid3Code
发表于: 2013-6-16 23:57 7896

[转帖]Swordfish 1.3 by Insid3Code

2013-6-16 23:57
7896
Swordfish 1.3 by Insid3Code
- OllyDbg supported release: 201h

FEATURES:

Tools:
[+] Clear udd files

Hide debugger:
[+] PEB!BeingDebugged
[+] PEB!NtGlobalFlags
[+] PEB!HeapFlags
[+] Find OD Windows bypass
[+] CheckRemoteDebuggerPresent
[+] GetClassInfo(A-W-ExA-ExW)
[+] FindWindow(A-W-ExA-ExW)
[+] GetTikCount
[+] NtQueryPerformanceCounter
[+] Apply custom HideDbg config from external file (*.hdbg)

Set breakpoints (hard coded):
[+] user32.GetWindowTextW
[+] user32.GetDlgItemTextW
[+] user32.MessageBoxIndirectW
[+] user32.MessageBoxTimeoutW
[+] user32.SoftModalMessageBox
[+] user32.CreateWindowExW
[+] user32.ShowWindow
[+] kernel32.CreateFileW
[+] kernel32.OpenFile
[+] kernel32.ReadFile
[+] kernel32.WriteFile
[+] kernel32.LoadLibraryW
[+] kernel32.MoveFileW
[+] kernel32.DeleteFileW
[+] advapi32.RegOpenKeyExW
[+] advapi32.RegCloseKey
[+] advapi32.RegQueryValueExW
[+] advapi32.RegSetValueExW
[+] kernel32.CreateToolhelp32Snapshot
[+] kernel32.Process32FirstW
[+] kernel32.Module32FirstW
[+] Kernel32.Toolhelp32ReadProcessMemory
[+] kernel32.OpenProcess
[+] kernel32.WriteProcessMemory
[+] kernel32.ReadProcessMemory
[+] kernel32.CreateProcessW
[+] kernel32.VirtualProtectEx
[+] advapi32.OpenSCManagerW
[+] advapi32.OpenServiceW
[+] advapi32.StartServiceW
[+] advapi32.DeleteService
[+] msvbvm60.ThunRTMain
[+] msvbvm60.rtcMsgBox
[+] msvbvm60.__vbaStrCmp
[+] msvbvm60.__vbaStrComp
[+] msvbvm60.__vbaFreeStr
[+] msvbvm60.__vbaFileOpen
[+] msvbvm60.__vbaInputFile
[+] msvbvm60.__vbaWriteFile
[+] msvbvm60.__vbaStrCompVar
[+] msvbvm60.__vbaStrTextCmp
[+] msvbvm60.__vbaFileSeek
[+] msvbvm60.__vbaFileClose
[+] msvbvm60.__vbaVarTstEq

[+] Set API Bpts from external file (*.bpts)
[+] Set Offset Bpts from external file (*.bpts)


[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

上传的附件:
收藏
免费 1
支持
分享
最新回复 (1)
雪    币: 563
活跃值: (95)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
设置断点挺方便 谢了
2013-6-27 20:59
0
游客
登录 | 注册 方可回帖
返回
//