Jump to content


Photo
- - - - -

Collection Of OllyDbg Bugs And Exploits


  • Please log in to reply
6 replies to this topic

#1 waliedassar

waliedassar

    Member

  • (Full Member)
  • 86 posts
  • Gender:Male
  • Interests:Reverse code engineering, malware analysis, and security research.

Posted 02 March 2012 - 12:30 PM

Here are some of the publicly disclosed OllyDbg bugs and exploits.

http://code.google.c.../downloads/list

I will keep updating it as long as bugs and exploits are being disclosed.

For further information:
http://waleedassar.blogspot.com/

#2 Mr. eXoDia

Mr. eXoDia

    Freedom!

  • (Full Member)
  • 656 posts
  • Gender:Male

Posted 02 March 2012 - 03:16 PM

Very interesting blog, added to my link page... Keep up the good work!

Edited by Mr. eXoDia, 02 March 2012 - 03:21 PM.

noProtection (database with program protection information, pm for an account!)

TPoDT is dead!

Armadillo Version Detector, Inline Helper, Key Generator, Key Analyzer, Environment Variable Finder

#3 waliedassar

waliedassar

    Member

  • (Full Member)
  • 86 posts
  • Gender:Male
  • Interests:Reverse code engineering, malware analysis, and security research.

Posted 02 March 2012 - 04:05 PM

It is an honor, Mr.eXoDia.

#4 Teddy Rogers

Teddy Rogers

    Site Administrator

  • (Administrator)
  • 9,967 posts
  • Gender:Male
  • Location:Australia

Posted 02 March 2012 - 11:01 PM

Your always finding new and interesting anti tricks Waliedassar! You should start working with Oleh... Posted Image

Ted.

Posted Image
I would love to change the world, but they won't give me the source code...


#5 Loki

Loki

    In the Shadows :)

  • (Team Moderator)
  • 3,665 posts
  • Gender:Male
  • Location:Behind you
  • Interests:Stuff. Lots and lots of stuff.

Posted 05 March 2012 - 03:02 AM

+1

Been subscribed to the blog for a while. Good stuff :)
Posted Image

If there's anyone near when we collide we throw them in the middle... they can pick sides. As the plans turn into compromise, the promises all turn to lies, the spite builds up and it can't get through, passive me agressive you. I know i nag, i moan i know... but with a plan like this it's way too slow. In the time it took to get this there i could have made this work, but all i had was the hope that pieces would take shape and we could watch them all fall into place.

#6 waliedassar

waliedassar

    Member

  • (Full Member)
  • 86 posts
  • Gender:Male
  • Interests:Reverse code engineering, malware analysis, and security research.

Posted 07 March 2012 - 01:07 PM

A minor issue in OllyDbg v2.01 while parsing the TLS info has been found. The collection has been updated.

For further details:
http://waleedassar.b...-callbacks.html
http://ollybugs.goog...es/fake_tls.exe

#7 waliedassar

waliedassar

    Member

  • (Full Member)
  • 86 posts
  • Gender:Male
  • Interests:Reverse code engineering, malware analysis, and security research.

Posted 18 March 2012 - 06:01 PM

A practical Proof of concept for the "%s%s%s.exe" format string bug has been created. The bug also affects the latest version of OllyDbg.

You can find it here
http://code.google.c...me=asterisk.exe




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users