吾爱破解 - 52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 5634|回复: 5
收起左侧

[IDA Plugin] IDA-dumpDyn

[复制链接]
m4n0w4r 发表于 2019-2-2 20:01
本帖最后由 m4n0w4r 于 2019-2-2 20:02 编辑

Author: Lasha Khasaia @_qaz_qaz

Feature:
If a process allocates a dynamic memory using VirtualAlloc, HeapAlloc, new, etc. and continues execution from that address, most of times, the memory address will be different for each different execution, it means that if we comment, rename variables or set breakpoints, nothing of this will be left in the next execution because the shellcode or code section will take a different memory address.

dumpDyn.py is IDAPython plugin(script) which saves comments, names, breakpoints, functions from one execution to another.





If VirtualAlloc/VirtualAllocEx is used to allocate a dynamic memory (which is the case with most malware), you can use icons on the toolbar to save and restore your work:




In any other case(HeapAlloc, malloc, new, etc), you need to specify memory location and size:







Restore functions from undefined data:




Info:
https://github.com/secrary/IDA-scripts/tree/master/dumpDyn

dumpDyn.rar

2.84 KB, 下载次数: 13, 下载积分: 吾爱币 -1 CB

免费评分

参与人数 2吾爱币 +6 热心值 +2 收起 理由
Hmily + 5 + 1 鼓励转贴优秀软件安全工具和文档!
唯爱学习 + 1 + 1 感谢发布原创作品,吾爱破解论坛因你更精彩!

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

fq645122 发表于 2019-2-2 20:53
知道为啥别人都不评论你吗
唯爱学习 发表于 2019-2-2 20:58
linuxprobe 发表于 2019-2-3 15:39
全是英文的,你怎么不给我们翻译一下,你去哪儿弄的这些。
E式丶男孩 发表于 2019-2-3 21:30
God, how to use IDA? Do you have any tutorials?

辣皮哥 发表于 2020-11-16 20:49
        谢谢@Thanks!
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则

返回列表

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-11-24 13:29

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表