Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 12-14-2005, 13:10
winndy winndy is offline
VIP
 
Join Date: Sep 2005
Posts: 236
Rept. Given: 104
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 27
Thanks Rcvd at 16 Times in 13 Posts
winndy Reputation: 26
Debug drivers -OllyDBG?SoftICE?

I tried to dubug hddUsbMonitor v2.37.
But it need to debug drivers.

I got this from a forum .
It says you cannot debug drivers using OD.
Quote:
And that drivers run in ring0. OllyDbg is a ring3 debugger, so it
can't debug drivers - even though NT drivers are PE files. It's a fine
tool for ring3 debugging, though.
I even could not load .sys to OD.
Will this function be added in OD 2.0?

SoftICE is powerful,But OD is more convenient.

Is there any tuts talking Debug drivers using SoftICE.


Regards
Reply With Quote
  #2  
Old 12-14-2005, 13:24
toro toro is offline
VIP
 
Join Date: Aug 2004
Posts: 189
Rept. Given: 4
Rept. Rcvd 97 Times in 34 Posts
Thanks Given: 29
Thanks Rcvd at 160 Times in 51 Posts
toro Reputation: 97
hi
if you have more than one pc, use visual softice. its convenient too.
Reply With Quote
  #3  
Old 12-14-2005, 13:38
just4urim
 
Posts: n/a
Hi winndy ,

I've worked with SoftICE , i think it's the most powerful debugger for device drivers. And as toro said , the Visual SoftICE is realy the best . Even if you haven't more than 1 PC , don't be worried ! Install a VMware on your PC and use it as your second PC then the connection could be stablished via a COM port.
Try the SoftICE , it would be valuable.

Regards,
Just4UriM
Reply With Quote
  #4  
Old 12-14-2005, 22:40
JuneMouse
 
Posts: n/a
as you rightly say ollydbg is a user mode debugger so it cannot debug drivers
to debug drivers you need a kernel mode debugger if you are comfortable with softice then you can use that as others have recommended
else get windbg from microsoft (its free and consist of both and use mode debugger aks windbg.exe and a kernel mode debugger kdb)
to use kdb you would need two pcs connected through one would act as host and other client if you dont have two pcs you can install one of those virtual machine ware (vmware virtual pc ) and debug drivers

take a look at the link below for configuring vmware to be used as second pc

http://silverstr.ufies.org/lotr0/windbg-vmware.html

http://www.catch22.net/tuts/vmware.asp

though windbg and kdbs gui is kinda fuzzy to use at first if you get used to it
it proves to be an excellent debugger

if you dont want to debug but just analyze some functions statically (dead listing approach) then getting the file loaded into ida should do a nice job
or get livekd from sysinternals and use it in conjunction with windbg to poke
Reply With Quote
  #5  
Old 12-15-2005, 02:09
Maximus Maximus is offline
Friend
 
Join Date: Nov 2005
Posts: 39
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Maximus Reputation: 0
Well, you could give a try to Syser Debugger.
It is an interesting attempt, and it features both a r3 and a r0 debugger.
It is not character-based too, and seems very a very powerful attempt to me. Try to see if it works fine for you.
www.sysersoft.com
it is made by 2(?) cool chinese guys, and its manual is... in chinese!!
Anyway, sice commands are accepted.
Give it a look, might be good 4u.
Reply With Quote
  #6  
Old 12-15-2005, 11:59
nskSem
 
Posts: n/a
A little note: when my friend research "StarForce", he sad he easily used OD, but it was on Win95/98, not on NT.

Last edited by nskSem; 12-15-2005 at 12:51.
Reply With Quote
  #7  
Old 12-15-2005, 22:09
winndy winndy is offline
VIP
 
Join Date: Sep 2005
Posts: 236
Rept. Given: 104
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 27
Thanks Rcvd at 16 Times in 13 Posts
winndy Reputation: 26
Hi,everybody

I really appreciate your help.
I'll see and try .

Thanks again
-----

Yours truly
winndy
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
SoftICE crashes with NVIDIA 81.x/82.x drivers Kerlingen General Discussion 17 03-11-2006 15:22
OllyDbg long process Module debug Vulnerability elephant General Discussion 1 04-04-2005 21:49
How to debug Safedisc in OllyDbg DeeYeah General Discussion 4 01-31-2005 21:02
How to debug kernel Drivers?? loman General Discussion 14 06-18-2004 21:31


All times are GMT +8. The time now is 18:08.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )