Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Vista
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Focus On: Vista
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Binary Analysis
Back to list
|
Post reply
Debugger Detection Functions
May 24 2007 08:35PM
Gleyson Melo (gleysonmelo gmail com)
(4 replies)
Re: Debugger Detection Functions
May 24 2007 09:21PM
Steve Coleman (Steve Coleman jhuapl edu)
Here are a few good refs to look at:
http://www.rootkit.com/newsread.php?newsid=669
http://www.rootkit.com/newsread.php?newsid=284
http://www.codebreakers-journal.com/index.php?option=com_content&task=vi
ew&id=251&Itemid=96
http://rdist.root.org/2007/04/19/anti-debugger-techniques-are-overrated/
I know there are more in my bookmarks and papers, but I don't have the
time to dig them out right now. These should at least get you started. ;)
Gleyson Melo wrote:
> I know about the IsDebuggerPresent API function, but I don't know
> about others.
--
Steve Coleman
Johns Hopkins University / Applied Physics Laboratory
[ reply ]
Re: Debugger Detection Functions
May 24 2007 09:11PM
Gerry Eisenhaur (gerrye gmail com)
Re: Debugger Detection Functions
May 24 2007 09:06PM
Greg Hunt (gregory hunt gmail com)
Re: Debugger Detection Functions
May 24 2007 09:00PM
Dennis (dennis backtrace de)
Privacy Statement
Copyright 2007, SecurityFocus
http://www.rootkit.com/newsread.php?newsid=669
http://www.rootkit.com/newsread.php?newsid=284
http://www.codebreakers-journal.com/index.php?option=com_content&task=vi
ew&id=251&Itemid=96
http://rdist.root.org/2007/04/19/anti-debugger-techniques-are-overrated/
I know there are more in my bookmarks and papers, but I don't have the
time to dig them out right now. These should at least get you started. ;)
Gleyson Melo wrote:
> I know about the IsDebuggerPresent API function, but I don't know
> about others.
--
Steve Coleman
Johns Hopkins University / Applied Physics Laboratory
[ reply ]