首页
社区
课程
招聘
[转帖]PhantOm Plugin 1.54
2009-10-13 14:04 14250

[转帖]PhantOm Plugin 1.54

2009-10-13 14:04
14250
好像还没看到人发,就转过来了

出处:http://tuts4you.com/download.php?view.1276



Plug-in for concealment OllyDbg (plugin with the driver). Helps from following methods of detection:

// driver - extremehide.sys

[+] NtQueryInformationProcess.
[+] SetUnhandledExceptionFilter.
[+] OpenProcess.
[+] Invalid Handle.
[+] NtSetInformationThread.
[+] RDTSC.
[+] NtYieldExecution.
[+] NtQueryObject.
[+] NtQuerySystemInformation.
[+] Windows hide.
[+] GetProcessTimes.
[+] NtSetContextThread.

// plugin - PhantOm.dll

[+] PEB BeingDebugged.
[+] PEB NtGlobalFlag.
[+] GetStartupInfo.
[+] Process Heaps.
[+] GetTickCount.
[!] Protect DRx.
[!] Hide DRx.
[!] Fake Windows version.
[!] Custom Handler.
[+] BlockInput

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

上传的附件:
收藏
点赞0
打赏
分享
最新回复 (13)
雪    币: 205
活跃值: (12)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
echale 2009-10-16 21:52
2
0
怎么没人回复呢|? 这么好的东西
雪    币: 1407
活跃值: (17)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
liangdong 2009-10-16 22:02
3
0
支持一下 还以为PhantOm更新了
雪    币: 229
活跃值: (15)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
转身 2009-11-13 19:02
4
0
感谢了哈。。。
辛苦了。。
下来试试。
雪    币: 161
活跃值: (261)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
陳明展 2009-11-14 09:00
5
0
我還是1.26 版!
感謝
雪    币: 40
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
惟我独尊 2011-5-4 22:58
6
0
网上这个版本的少
雪    币: 241
活跃值: (26)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
luyiqiang 1 2011-5-8 18:57
7
0
感谢了哈。。。
辛苦了。。
下来试试。
雪    币: 11293
活跃值: (4028)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
xie风腾 2011-7-11 15:10
8
0

收藏这个插件吧
雪    币: 57
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
liyizhu 2012-5-31 23:38
9
0
嗯 支持分享+下载收藏
雪    币: 204
活跃值: (35)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
伟伟 2013-1-19 13:56
10
0
谢谢,下来试试
雪    币: 85167
活跃值: (198500)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2013-3-3 07:24
11
0
PhantOm Plugin 1.73

by:Hellsp@wn + Archer
Plug-in for concealment of OllyDbg (plugin with the driver). Helps being detected using the following methods of detection:

// driver - extremehide.sys

[+] NtQueryInformationProcess.
[+] SetUnhandledExceptionFilter.
[+] OpenProcess.
[+] Invalid Handle.
[+] NtSetInformationThread.
[+] RDTSC.
[+] NtYieldExecution.
[+] NtQueryObject.
[+] NtQuerySystemInformation.
[+] Windows hide.
[+] GetProcessTimes.
[+] NtSetContextThread.
[+] NtSetDebugFilterState

// plugin - PhantOm.dll

[+] PEB BeingDebugged.
[+] PEB NtGlobalFlag.
[+] GetStartupInfo.
[+] Process Heaps.
[+] GetTickCount.
[+] OutputDebugString
[!] Protect DRx.
[!] Hide DRx.
[!] Fake Windows version.
[!] Custom Handler.
[+] BlockInput.
[+] INT 2d.
[+] Single-step bug.
[+] OutputDebugString.
[+] TraceFlag hide.

上传的附件:
雪    币: 2145
活跃值: (383)
能力值: ( LV9,RANK:200 )
在线值:
发帖
回帖
粉丝
疯子 4 2013-3-3 07:48
12
0
竟然有更新,林版辛苦了
雪    币: 85167
活跃值: (198500)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2013-3-3 08:11
13
0
Refactor the code.
Added support for Windows 7 86/64.
Added option x64 compatible.
Fixed a bug in the "custom handler exceptions".
Rewrote the algorithm of the plugin.
Changed the settings window.
Improved handling int 2d.
Fixed compatibility "custom handler exceptions" with curves plugins.
Fixed handling drx breakpoints.
Added TF hiding in the trace example: PUSH SS & POP SS / MOV? X, SS & MOV SS,? X
Added interception ZwQueryInformationProcess.
Added interception ZwSetInformationThread.
Added interception ZwQuerySystemInformation.
Put Option "hook some of Zw * functions" which includes all Zw interceptions.
Added check for CloseHandle with invalid handle.

雪    币: 51
活跃值: (25)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
西风X 2013-3-3 08:29
14
0
谢谢lz,分享
游客
登录 | 注册 方可回帖
返回