首页
社区
课程
招聘
[转帖]PhantOm Plugin 1.54
发表于: 2009-10-13 14:04 14828

[转帖]PhantOm Plugin 1.54

2009-10-13 14:04
14828
好像还没看到人发,就转过来了

出处:http://tuts4you.com/download.php?view.1276



Plug-in for concealment OllyDbg (plugin with the driver). Helps from following methods of detection:

// driver - extremehide.sys

[+] NtQueryInformationProcess.
[+] SetUnhandledExceptionFilter.
[+] OpenProcess.
[+] Invalid Handle.
[+] NtSetInformationThread.
[+] RDTSC.
[+] NtYieldExecution.
[+] NtQueryObject.
[+] NtQuerySystemInformation.
[+] Windows hide.
[+] GetProcessTimes.
[+] NtSetContextThread.

// plugin - PhantOm.dll

[+] PEB BeingDebugged.
[+] PEB NtGlobalFlag.
[+] GetStartupInfo.
[+] Process Heaps.
[+] GetTickCount.
[!] Protect DRx.
[!] Hide DRx.
[!] Fake Windows version.
[!] Custom Handler.
[+] BlockInput

[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!

上传的附件:
收藏
免费 0
支持
分享
最新回复 (13)
雪    币: 205
活跃值: (12)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
2
怎么没人回复呢|? 这么好的东西
2009-10-16 21:52
0
雪    币: 1407
活跃值: (17)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
3
支持一下 还以为PhantOm更新了
2009-10-16 22:02
0
雪    币: 229
活跃值: (15)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
感谢了哈。。。
辛苦了。。
下来试试。
2009-11-13 19:02
0
雪    币: 161
活跃值: (261)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
我還是1.26 版!
感謝
2009-11-14 09:00
0
雪    币: 40
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
6
网上这个版本的少
2011-5-4 22:58
0
雪    币: 241
活跃值: (31)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
7
感谢了哈。。。
辛苦了。。
下来试试。
2011-5-8 18:57
0
雪    币: 12352
活跃值: (5118)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
8

收藏这个插件吧
2011-7-11 15:10
0
雪    币: 57
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
9
嗯 支持分享+下载收藏
2012-5-31 23:38
0
雪    币: 204
活跃值: (35)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
10
谢谢,下来试试
2013-1-19 13:56
0
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
11
PhantOm Plugin 1.73

by:Hellsp@wn + Archer
Plug-in for concealment of OllyDbg (plugin with the driver). Helps being detected using the following methods of detection:

// driver - extremehide.sys

[+] NtQueryInformationProcess.
[+] SetUnhandledExceptionFilter.
[+] OpenProcess.
[+] Invalid Handle.
[+] NtSetInformationThread.
[+] RDTSC.
[+] NtYieldExecution.
[+] NtQueryObject.
[+] NtQuerySystemInformation.
[+] Windows hide.
[+] GetProcessTimes.
[+] NtSetContextThread.
[+] NtSetDebugFilterState

// plugin - PhantOm.dll

[+] PEB BeingDebugged.
[+] PEB NtGlobalFlag.
[+] GetStartupInfo.
[+] Process Heaps.
[+] GetTickCount.
[+] OutputDebugString
[!] Protect DRx.
[!] Hide DRx.
[!] Fake Windows version.
[!] Custom Handler.
[+] BlockInput.
[+] INT 2d.
[+] Single-step bug.
[+] OutputDebugString.
[+] TraceFlag hide.

上传的附件:
2013-3-3 07:24
0
雪    币: 2242
活跃值: (488)
能力值: ( LV9,RANK:200 )
在线值:
发帖
回帖
粉丝
12
竟然有更新,林版辛苦了
2013-3-3 07:48
0
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
13
Refactor the code.
Added support for Windows 7 86/64.
Added option x64 compatible.
Fixed a bug in the "custom handler exceptions".
Rewrote the algorithm of the plugin.
Changed the settings window.
Improved handling int 2d.
Fixed compatibility "custom handler exceptions" with curves plugins.
Fixed handling drx breakpoints.
Added TF hiding in the trace example: PUSH SS & POP SS / MOV? X, SS & MOV SS,? X
Added interception ZwQueryInformationProcess.
Added interception ZwSetInformationThread.
Added interception ZwQuerySystemInformation.
Put Option "hook some of Zw * functions" which includes all Zw interceptions.
Added check for CloseHandle with invalid handle.

2013-3-3 08:11
0
雪    币: 51
活跃值: (25)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
14
谢谢lz,分享
2013-3-3 08:29
0
游客
登录 | 注册 方可回帖
返回
//