-
-
[转帖]OllyStepNSearch_V0_6_1
-
发表于: 2007-10-30 10:50 5746
-
From:EXETOOLS
by:taos
by:taos
And this is my contribution:
http://www.didierstevens.com/files/software/OllyStepNSearch_V0_6_1.zip
This plugin allows you to search for a given text when automatically
stepping through the debugged program.
When the plugin is enabled, it will step automatically through the debugged
program once a step command (like Step Into) is issued.
Enabling the plugin is done with the “Options” menu command.
After enabling, press F7 to start.
After each step, the plugin will check which registers have changed.
If a changed register points to an ASCII string, it is logged.
If a search string has been defined and it is contained in the ASCII string
pointed to by the register or the Information pane, the stepping is paused.
Comparison is case sensitive.
A search string is defined by entering it with the “Options” menu command.
It is remembered in the OllyDbg INI file.
Entering an empty string disables the break on string command.
OllyStepNSearch can search in strings pointed to by registers (search in registers toggle)
and it can search in the Information pane of the CPU window (search in information toggle).
Read the “Information window” help section of the OllyDbg v1.10 help file if you’re not familiar
with the Information pane.
If the search string is not found, debugging is resumed. If the current address
is lower than the limit address (by default 0×10000000) a step into command is
issued. A step over command is issued if the current address is higher than the
limit address, or if the current command is a call/jump to an address higher
than the limit address.
The limit address can be changed in the Options dialog.
The plugin can be disabled automatically when the search string is found (Disable after break toggle).
I added this option because I usually want to single step after finding the search string,
but often forgot to disable the plugin before single stepping.
Restarting the debugged program disables the plugin.
Debugging example:
Start OllyDbg and load the ftp.exe program (in system32 directory)
Start the OllyStepNSearch plugin “Options” menu command
Enter “google” as Search string (without the double quotes, of course)
Enable StepNSearch
Click OK
Press F7 to start debugging
Go to the FTP window and type “open google.com” and press enter
The StepNSearch plugin will stop debugging when a register points to a string containing google. On my Windows XP SP2, this happens when EAX points to “open google.com”.
You can continue with F7 and see how ftp.exe parses the “open google.com” command
赞赏
他的文章
- [转帖]IDM.Computer.Solutions.UltraEdit.Enterprise.v2024.1.0.36.x64.Incl.Keyfilemaker-BTCR 1739
- [转帖]IDM.Computer.Solutions.UEStudio.Enterprise.v2024.1.0.36.x64.Incl.Keyfilemaker-BTCR 1748
- [转帖]IDM.Computer.Solutions.UltraFinder.Enterprise.v2023.0.0.17.x64.Incl.Keyfilemaker-BTCR 1631
- [转帖]JEB Decompiler 5.20.0.202411121942 mod by CXV 1633
- [转帖]Tenorshare.4uKey.for.Android.v2.1.1-AMPED 926
谁下载
风雨无阻
FishSeeWater
萝卜
ldljlzw
fxyang
VolX
ylp1332
nOpnOp
uyhj
foto
xblan
Xacs
dhtfish
freezer
asdmusic
option
vrowang123
sagas
天涯怪客
mmqiang
KernelKiller
droiyan
zhupf
crystalxp
brightsm
亚尔迪
虎之王
swqswq
tonyfu
gxs
springz
yzjsdn
lhtzty
luohb
samisgod
colword
einsteinzl
youilove
jnop
nop
smartqiu
lopera
xxdoc
werzdas
Nooby
一撇胡
iawen
qweerw
ruffy
mbaightttt
河边渔者
chaotozhu
sanfang
大拇指
zxjshk
康东
caxfan
yuantingfa
gstwsjy
zhzhzhzh
ttdia
cmdxhz
loudy
ljyljr
qdxwbb
manandgod
小男孩xnh
jojoling
mycaipeng
wuwowen
Isaev
yang建
njyogi
CuteSnail
路过人间
FthGroup
流行风
daxie
prolead
llyyhh
curclew
hjmqwaszx
水中月
yinchao
dfcun
rockyoo
chengpj
adbrave
hbhzga
未签收
深圳海涛
gqsgxyfn
人很老实
cybman
goodbadboy
liai
xuyiming
starstarst
zhengjf
看原图
赞赏
雪币:
留言: