Go Back   Exetools > General > General Discussion


Thread Tools Display Modes
Old 08-02-2004, 16:12
TQN TQN is offline
Join Date: Apr 2003
Location: Vietnam
Posts: 350
Rept. Given: 142
Rept. Rcvd 21 Times in 13 Posts
Thanks Given: 176
Thanks Rcvd at 146 Times in 47 Posts
TQN Reputation: 21
Another way to detect OllyDbg and another debugger

Hi all !
When I trying UnhandledExceptionFilter of xDREAM, I have detected a method which Windows uses to detect a app is being debugged (I dont know once else already have found it). The plugin of xDREAM patch the result of the call of NtQueryInformationProcess. Windows call NtQueryInformationProcess with ProcessInformationClass is 7 (DebugPort) to detect a app is being debugged. For example: open a exe with Visual studio or OllyDbg, open TaskManager, and kill the debugged exe, Windows will warning: "Program being debugged" or "Access denied". Search in my copy of Win2k source code, at the ntos folder, the function _EndTask of TaskManager uses this way.
I wrote a small C program, compiled with VS .NET 2003, and test the exe with OllyDbg, VS, VS .NET, IDAPro debugger, WinDbg and TD32. The app will detect it is debugged. But with SoftIce, the app could not detect.
But I can not use NtSetInformationProcess to clear the debug port value because it can only be set when debug port is zero.
Hope I will receive your idea !
Attached Files
File Type: rar TestDbg.rar (15.8 KB, 32 views)
Reply With Quote
Old 08-02-2004, 23:52
Jay Jay is offline
Join Date: Feb 2002
Posts: 249
Rept. Given: 31
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 15
Thanks Rcvd at 13 Times in 5 Posts
Jay Reputation: 3

I think this method was discussed a while back on woodman
Reply With Quote
Old 08-03-2004, 09:12
JMI JMI is offline
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 96 Times in 94 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
Which references a thread here:


and around and around we go.

Reply With Quote

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Using RtlAdjustPrivilege to detect debugger. Insid3Code Source Code 2 03-05-2015 13:35
Unseen Debugger Detection (Ollydbg) Peter[Pan] General Discussion 27 10-17-2005 09:34

All times are GMT +8. The time now is 13:58.

Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )