Debugger: not hidden?

Need Help With an Existing Feature in Memory Hacking Software? Ask Here

Moderators: g3nuin3, SpeedWing, WhiteHat, mezzo

Debugger: not hidden?

Postby cobr_h » Tue Dec 15, 2009 11:57 am

I am still studying more things on MHS, asm, debugging, OEP and such...

Now am barely trying to attach a debugger to the cabal game process (protected by x-trap). Nice. I can run the disassembler, see code, but when I try to start debugging, it always crashes (either x-trap or cabalmain.exe's themida finds the debugger and kills itself).

It seems there is no way (already found) to hide a debugger from that themida? Tried already ollydbg with some plugins. Was quite sure MHS's own debugger would be able to follow the process' current instruction pointer (dunno how people like to call it in english) in order to catch an event (disconnection from game) and prevent it from happening as it does normally.

Any suggestion on how could I accomplish this? :)
cobr_h
Acker
 
Posts: 72
Joined: Wed Dec 02, 2009 6:15 am

Re: Debugger: not hidden?

Postby L. Spiro » Tue Dec 15, 2009 12:07 pm

A kernel-mode debugger can be hidden. MHS does not and probably never will use a kernel-mode debugger.


L. Spiro
Our songs remind you of songs you’ve never heard.
User avatar
L. Spiro
L. Spiro
 
Posts: 3129
Joined: Mon Jul 17, 2006 10:14 pm
Location: Tokyo, Japan

Re: Debugger: not hidden?

Postby cobr_h » Wed Dec 16, 2009 12:56 am

okie, thanks
cobr_h
Acker
 
Posts: 72
Joined: Wed Dec 02, 2009 6:15 am


Return to Help

Who is online

Users browsing this forum: No registered users and 0 guests