Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-18-2005, 23:15
hobferret's Avatar
hobferret hobferret is offline
Senile Member
 
Join Date: Apr 2003
Location: Alien area near Albuquerque, NM
Posts: 302
Rept. Given: 42
Rept. Rcvd 58 Times in 34 Posts
Thanks Given: 0
Thanks Rcvd at 19 Times in 19 Posts
hobferret Reputation: 58
Another Ollydbg question DLL loading in Program

Hey there it's me again

Being as I am only just "getting" converted to Olly, I have what is probably a very simple question for you guys

When I was messing around with a program for ivanov, I wanted the program to break on access to vboxb410.dll. The only way I managed it was to set a break on "new modules (DLL), but that breaks on every dll it loads.

So how the hell can you get it to break on a specific DLL

Any reply will be appreciated, no matter how "daft" it may be

/hobferret
Reply With Quote
  #2  
Old 06-19-2005, 00:12
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
you can use DllBreakEx for that task. it's an olly plugin.
Reply With Quote
  #3  
Old 06-19-2005, 02:13
hobferret's Avatar
hobferret hobferret is offline
Senile Member
 
Join Date: Apr 2003
Location: Alien area near Albuquerque, NM
Posts: 302
Rept. Given: 42
Rept. Rcvd 58 Times in 34 Posts
Thanks Given: 0
Thanks Rcvd at 19 Times in 19 Posts
hobferret Reputation: 58
Cheers MaRKuS-DJM

I will see if it kick's ass

/hobferret
Reply With Quote
  #4  
Old 06-19-2005, 03:31
hobferret's Avatar
hobferret hobferret is offline
Senile Member
 
Join Date: Apr 2003
Location: Alien area near Albuquerque, NM
Posts: 302
Rept. Given: 42
Rept. Rcvd 58 Times in 34 Posts
Thanks Given: 0
Thanks Rcvd at 19 Times in 19 Posts
hobferret Reputation: 58
OK MaRKuS

That only let's you know a DLL is being loaded

It don't stop the process, get my drift

/hobferret
Reply With Quote
  #5  
Old 06-19-2005, 04:06
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
did you also check the option break on new modules in olly options? it should stop at the corresponding dll then.
Reply With Quote
  #6  
Old 06-19-2005, 18:24
hobferret's Avatar
hobferret hobferret is offline
Senile Member
 
Join Date: Apr 2003
Location: Alien area near Albuquerque, NM
Posts: 302
Rept. Given: 42
Rept. Rcvd 58 Times in 34 Posts
Thanks Given: 0
Thanks Rcvd at 19 Times in 19 Posts
hobferret Reputation: 58
MaRKuS-DJM mate

Rite, when I do as you suggest it does break on the DLL loading, a msgbox tells me so

OK having gotten that far, how do I now get to the program

You can't click on anything until you get rid of the msgbox, so pray tell me what I am doing wrong

Obviously after getting rid of the msgbox the program just runs, I need to be able to stop the God darn thing

If I can't get this to work I think I will have to revert to SICE, it's most likely me being as I'm a noob with Olly

/hobferret
Reply With Quote
  #7  
Old 06-19-2005, 18:36
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
ok, if all doesn't work, i can suggest another way.
1. search for the dll in executable modules
2. right click on it and then go to follow entry
3. in CPU-window, you are on the entry-point now
4. right click in CPU-window, Breakpoint > Hardware, on execution.
5. next time it starts you will break when the entrypoint of the dll is touched.
Reply With Quote
  #8  
Old 06-19-2005, 19:02
hobferret's Avatar
hobferret hobferret is offline
Senile Member
 
Join Date: Apr 2003
Location: Alien area near Albuquerque, NM
Posts: 302
Rept. Given: 42
Rept. Rcvd 58 Times in 34 Posts
Thanks Given: 0
Thanks Rcvd at 19 Times in 19 Posts
hobferret Reputation: 58
Cheers mate

That works, however, I need to do a little more work, because I keep getting Vbox injection error and then terminates

Anyways, thanks, I'm sure I will ger round it now

/hobferret
Reply With Quote
  #9  
Old 06-19-2005, 21:46
JuneMouse
 
Posts: n/a
hey its me again hope you remember me from 1847
may be you could try my plugin ntGlobalFlag
take a look at the using tls in ollydbg thread in this forum its still in view some 10 15 posts below for a link
but it too will stop on all dlls init routine you will be forced to f9 till you are on your required dll
Reply With Quote
  #10  
Old 06-19-2005, 23:32
hobferret's Avatar
hobferret hobferret is offline
Senile Member
 
Join Date: Apr 2003
Location: Alien area near Albuquerque, NM
Posts: 302
Rept. Given: 42
Rept. Rcvd 58 Times in 34 Posts
Thanks Given: 0
Thanks Rcvd at 19 Times in 19 Posts
hobferret Reputation: 58
Hey JuneMouse

I assume you mean this "NtGlobalFlag v 1.1 OllyDbgPlugin", thanks for the info, but my memory from 1847 is rather vague. I know there was "soft ice" around then but no olly's.

Well I'll give it a try anyways

/hobferret
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Plugin loading problem of using ollydbg suddenLy General Discussion 0 03-25-2014 21:17
Ollydbg loading problem hobferret General Discussion 5 07-07-2008 20:40
Question on IDA's Edit|Patch program? boya General Discussion 2 10-23-2004 01:36
OllyDbg question butter General Discussion 2 05-07-2004 10:30


All times are GMT +8. The time now is 05:57.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )