吾爱破解 - 52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 7245|回复: 9
收起左侧

[OllyDbg 1.x Plugin] OllyDumpEx v1.40

[复制链接]
风吹屁屁凉 发表于 2014-12-19 14:18
Overview
This plugin is process memory dumper for OllyDbg and Immunity Debugger.
Very simple overview:
OllyDumpEx = OllyDump + PE Dumper - obsoleted + useful features

Features
Various debuggers supported
Select to dump debugee exe, loaded dll or non-listed module
Search MZ/PE Signature from memory
Multiple Dump mode. Rebuild for typical PE dump, Binary for PE Carving
PE32+ supported (Search and Binary Dump mode only available on 32bit debugger)
Native 64bit process supported (IDA Pro, WinDbg and x64_dbg)
Dump any address space as section even if not in original section header
Add dummy section to keep PE format consistency
Fix RVA in DataDirectory to follow ImageBase change
Auto calculate many parameters (RawSize, RawOffset, VirtualOffset, ...)


Supported Debugger
OllyDbg version 1.10 (tested 1.10)
OllyDbg version 2.01 (tested 2.01)
Immunity Debugger version 1.7x or lower (tested 1.73)
Immunity Debugger version 1.8x or higher (tested 1.85)
IDA Pro Retail version 5.0 or higher (tested 6.6)
IDA Pro Freeware version 5.0 (tested 5.0)
WinDbg version 6.x (tested 6.2)
x64_dbg version 2.x (tested 2.2alpha)

Download
This archive file contains plugin DLLs for each debuggers.
OllyDumpEx.zip
Version: v1.40
MD5 : eb36d3271f6c0f98ad0ff9603011965a
SHA1: 7479afef0211e415d7a3b87e88da941223e7bf9a

Recent Changes
- v1.40 / 2014-12-17
Add: Support x64_dbg plugin interface (both 32bit and 64bit)
Improve: Enable NXCOMPAT and DYNAMICBASE for plugin binaries
- v1.30 / 2013-06-28
Add: Support WinDbg plugin interface (both 32bit and 64bit)
Improve: Add plugin name and version directory to archive file
Bugfix: Data after section headers in PE Header has been ignored
Bugfix: Fix SizeOfHeaders inconsistency
- v1.20 / 2013-05-27
Add: Support IDA Pro plugin interface (both Retail and Freeware version)
Add: Support native 64bit process dump (IDA Pro only)
Improve: Change dialog position to center of parent window
Improve: Add debug toggle menu to dialog system menu
Improve: Section size handling single section belongs to multiple memory segments
Bugfix: Zero virtual size section handling
- v1.12 / 2013-04-02
Improve: Update to OllyDbg 2 latest version PDK (2.01h)
Improve: Tested with latest version of debuggers
Bugfix: Search greater than 0x7FFFFFFF memory address failed
- v1.10 / 2013-03-24
Add: Search type All Memory
Add: Binary dump mode (no rebuild PE header, for before load image)
Add: PE32+ support (Binary dump mode only)
Add: Memory Address/Size parameters editable (dump source address)
Improve: Add info message for Relocation Flag and EXE/DLL type
Improve: Large PE Header handling (larger than 0x1000)
Improve: Check SectionAlignment and FileAlignment consistency
Improve: Reduce search memory usage (not depend on target memory size)
Improve: Detect PE Header across different type pages (parse and search)
Bugfix: Improper owner window handle
Bugfix: Section not listed when belong memory range not exists
Bugfix: Almost features broken when memory window sort order changed
- v1.00 / 2013-03-12
Add: Selectable Base PE Header (Module/Memory/Address)
Add: Search PE Header from memory
Improve: PE Source default change Disk to Memory
Improve: ASLR aware (except PE Source from Disk mode)
Improve: Clear DynamicBase DllCharacteristics flag with Disable Relocation option
Improve: PE Header parse and modify more carefully (corrupt PE handling)
Improve: Inherit selected address from memory window
Bugfix: Fix Virtual Offset feature cause crash (divide by zero)
Bugfix: Parse invalid sections cause crash
- v0.92 / 2012-10-09
Improve: Support OllyDbg version 2 plugin new interface
- v0.90 / 2011-08-24
Add: Support OllyDbg version 2 plugin interface (EXPERIMENTAL)
Improve: Rewrite Wide/Multibyte-Character support code
Improve: Decode CopyOnWrite page attribute
Bugfix: Detect working directory
- v0.80 / 2011-07-15
Add: Support Immunity Debugger version 1.8x or higher
Improve: Data Directory rebuild option (check rewrite range)
Improve: Always round up PE header size to 0x1000 (ImportRec not extend itself)
Bugfix: TLS Data Directory ignored

OllyDumpEx.zip

379.75 KB, 下载次数: 228, 下载积分: 吾爱币 -1 CB

免费评分

参与人数 1热心值 +1 收起 理由
caijunqill + 1 鼓励转贴优秀软件安全工具和文档!

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

陌路难相忘 发表于 2014-12-19 14:46
没看太懂  但是不影响俺顶贴的美德
asd2702539 发表于 2014-12-19 14:56
caijunqill 发表于 2014-12-19 20:44
haoer6238 发表于 2015-8-27 08:58
挺好的工具。
liubaoch 发表于 2015-10-6 00:25
收藏一个,谢谢提供。
xiawan 发表于 2015-12-17 15:56
。。。先去找机器翻译了
xiawan 发表于 2015-12-17 16:12
有些od用了IDAFicator 2.0.1.9 这个为什么会奔溃啊,大神?
wolfwang2008 发表于 2016-10-13 08:28
直接解压使用么?
菜鸟学者 发表于 2017-8-1 09:22
下载了 谢谢
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则

返回列表

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-12-23 20:12

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表