<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://www.woodmann.com/collaborative/tools/skins/common/feed.css?97"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Collaborative RCE Tool Library - OllyDbg Extensions (including sub-categories)</title>
		<link>http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/OllyDbg_Extensions/feed?recursive=1&amp;feed_type=rss</link>
		<description>Update Notification Feed for Category: OllyDbg Extensions (and its sub-categories)</description>
		<language>en</language>
		<generator>MediaWiki 1.11.2 via dELTA feed generator</generator>
		<lastBuildDate>Fri, 03 Sep 2010 10:11:08 GMT</lastBuildDate>
		<item>
			<title>Tool Added: Virtualized Olly for Win7</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Virtualized_Olly_for_Win7</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Custom_Versions&quot;&gt;OllyDbg Custom Versions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;May 23, 2010&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Some beloved plugins for Olly stopped working when used with Windows7.&lt;br /&gt;Among these are OllyAdvanced and Conditional Branch Logger just to name two of them.&lt;br /&gt;To overcome this issue, I virtualized Olly and now the plugins are working again :).&lt;br /&gt;You can customize this Olly as usual. Note, that you have to set the Plugins- and UDD-directory when starting it for the first time. Unfortunately there is a small shortcoming - Every part of a plugin that is driver-based is NOT working. This is due to the fact, that drivers cannot be virtualized. &lt;br /&gt;For instance, while everything else in OllyAdvanced is working, it's driver-based Anti-RTDSC is not. But that does not hinder the plugin to work great. The same goes for other plugins that have drivers involved. Sorry for that, virtualization nowadays is pretty good but not perfect.&lt;br /&gt;Also, there may be an issue with non-latin charactersets which I'm unable to confirm because I haven't got a non-latin Windows.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 23 May 2010 20:19:33 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: FullDisasm</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/FullDisasm</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;3.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;May 6, 2010&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;This plugin replaces the default OllyDbg disassembly routine with an engine which supports MMX, FPU, SSE, SSE2, SSE3, SSSE3, SSE4.1 and SSE4.2, AES , CLMUL instructions and undocumented instructions called &amp;quot;aliases&amp;quot;. Displays processor support for these technologies. Allows disassembling globally or only on selected lines in Masm, Nasm ,GoAsm syntax and AT&amp;amp;T Syntax. Available as a plugin for OllyDbg or Immunity Debugger.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Thu, 06 May 2010 21:42:05 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Hide Debugger</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Hide_Debugger</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.24&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;April 19, 2006&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;This plugin hides OllyDbg from many debugger detection tricks.&lt;br /&gt;&lt;br /&gt;(source code was released on February 24, 2010, and is now included in the download above)&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 21 Mar 2010 15:33:00 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Conditional Branch Logger</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Conditional_Branch_Logger</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Code_Coverage_Tools&quot;&gt;Code Coverage Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Profiler_Tools&quot;&gt;Profiler Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Tracers&quot;&gt;Tracers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;June 13, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Conditional Branch Logger is a plugin which gives control and logging capabilities for conditional branch instructions over the full user address space of a process. Useful for execution path analysis and finding differences in code flow as a result of changing inputs or conditions. It is also possible to log conditional jumps in system dlls before the Entry Point of the target is reached. Numerous options are available for fine tuning the logging ranges and manipulating breakpoints.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 21 Mar 2010 14:25:06 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: SnD Crypto Scanner (Olly/Immunity Plugin)</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/SnD_Crypto_Scanner_%28Olly/Immunity_Plugin%29</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Crypto_Tools&quot;&gt;Crypto Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.5 (beta)&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 30, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;A scanner for crypto signatures as an Olly/Immunity Plugin:&lt;br /&gt;&lt;br /&gt;(Following text from the forum thread)&lt;br /&gt;Been coding this for a while and now kinda got bored with it so releasing it as a beta. Sure I'll go back to it again later... just need to do something else now.&lt;br /&gt;&lt;br /&gt;Hopefully you will find this useful - the advantage of having it as a plugin means that breakpoints can easily be set where required, and signatures can be located quickly.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Setting Breakpoints:&lt;br /&gt;The buttons try and use a little bit (not much :P) intelligence when setting breakpoints. In the data section, &amp;quot;hardware on access&amp;quot; or &amp;quot;memory access&amp;quot; breakpoints are set on the specific VA referenced. In the code section, a 'hardware on execution' breakpoint is set at the beginning of the disassembled line the referenced dword is on. Hope that makes a little sense :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Limitations:&lt;br /&gt;Signatures are either made up of dwords or byte sequences. This gives 2 main weaknesses:&lt;br /&gt;- some algorithms use similar dwords, distinguishing between them is not always simple.&lt;br /&gt;- the algorithm finds the first instance of a given dword in a signature. If you have code which has multiple algorithms which use some of the same dwords, the referenced VA will always point to the first instance in the file.&lt;br /&gt;&lt;br /&gt;Without doing some in depth analysis, its impossible to determine which algorithm uses a specific instance of a dword. This tool is therefore only going to make analysis a little easier, not do it for you.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Future Development:&lt;br /&gt;Currently the plugin uses the plugin API to get the current file name and then reads it into allocated memory. It does not read memory inside Olly. This means packed files will need to be unpacked and the unpacked instance debugged. In future I plan to give an option to either scan the file or memory (perhaps even a specified memory range).&lt;br /&gt;&lt;br /&gt;If you have an idea for development, want to add signatures or just want to tell me how crap this is, please go for it :)&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Fri, 18 Dec 2009 08:35:33 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: CodeDoctor</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/CodeDoctor</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Deobfuscation_Tools&quot;&gt;Deobfuscation Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:IDA_Extensions&quot;&gt;IDA Extensions&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Resource_Editors&quot;&gt;Resource Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Unpacking_Tools&quot;&gt;Unpacking Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.90&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 12, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&amp;lt;nowiki&amp;gt;CodeDoctor is a plugin for Olly and IDA.&lt;br /&gt;&lt;br /&gt;History:&lt;br /&gt;11.11.2009 - 0.90 - initial public release&lt;br /&gt;&lt;br /&gt;________________________________________________________________________________&lt;br /&gt;Functions:&lt;br /&gt;&lt;br /&gt;1) Deobfuscate&lt;br /&gt;&lt;br /&gt;Select instructions in disasm window and execute this command. It will try &lt;br /&gt;to clear the code from junk instructions.&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;&lt;br /&gt;Original:&lt;br /&gt;00874372    57                      PUSH EDI                                     &lt;br /&gt;00874373    BF 352AAF6A             MOV EDI,6AAF2A35&lt;br /&gt;00874378    81E7 0D152A41           AND EDI,412A150D&lt;br /&gt;0087437E    81F7 01002A40           XOR EDI,402A0001&lt;br /&gt;00874384    01FB                    ADD EBX,EDI                                 &lt;br /&gt;00874386    5F                      POP EDI                                     &lt;br /&gt;&lt;br /&gt;Deobfuscated:&lt;br /&gt;00874372    83C3 04                 ADD EBX,4&lt;br /&gt;&lt;br /&gt;________________________________________________________&lt;br /&gt;&lt;br /&gt;2) Deobfuscate - Single Step&lt;br /&gt;&lt;br /&gt;This works like previous command, but does one transformation at a time&lt;br /&gt;_______________________________________________________&lt;br /&gt;&lt;br /&gt;3) Move NOPs to bottom&lt;br /&gt;&lt;br /&gt;Converts this:&lt;br /&gt;&lt;br /&gt;00874396    50                      PUSH EAX&lt;br /&gt;00874397    90                      NOP&lt;br /&gt;00874398    90                      NOP&lt;br /&gt;00874399    52                      PUSH EDX                                    &lt;br /&gt;0087439A    BA 3F976B00             MOV EDX,somesoft.006B973F&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;to this:&lt;br /&gt;&lt;br /&gt;00874396    50                      PUSH EAX&lt;br /&gt;00874397    52                      PUSH EDX                                    &lt;br /&gt;00874398    BA 3F976B00             MOV EDX,somesoft.006B973F&lt;br /&gt;0087439D    90                      NOP&lt;br /&gt;0087439E    90                      NOP&lt;br /&gt;&lt;br /&gt;Limitations: it breaks all jumps and calls pointing inwards&lt;br /&gt;________________________________________________________&lt;br /&gt;&lt;br /&gt;4) Undo / Redo&lt;br /&gt;&lt;br /&gt;Undo or Redo last operation (from one of the above functions)&lt;br /&gt;&lt;br /&gt;________________________________________________________&lt;br /&gt;&lt;br /&gt;5) Retrieve Jumpy function&lt;br /&gt;&lt;br /&gt;This will statically parse instructions and follow all jumps. This is useful&lt;br /&gt;for situations, when program jumps here and there and here and there... When&lt;br /&gt;it encounters some instruction, that can't be followed, it stop and copies&lt;br /&gt;all parsed instruction to an allocated place in memory.&lt;br /&gt;&lt;br /&gt;Use settings to set some parameters:&lt;br /&gt;Step over calls - if set, it will step over calls, otherwise it will follow them&lt;br /&gt;Step over jccs - dtto, but for Jccs&lt;br /&gt;Deobfuscate - it will deobfuscate instruction, when it encounters Jcc, RET, &lt;br /&gt;  JMP reg/exp, CALL reg/exp; useful for multi-branch&lt;br /&gt;  &lt;br /&gt;Example:&lt;br /&gt;&lt;br /&gt;Original:&lt;br /&gt;00874389   /EB 05                   JMP SHORT somesoft.00874390&lt;br /&gt;0087438B&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Thu, 12 Nov 2009 16:24:49 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Plugins Manager</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Plugins_Manager</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.2.0.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;September 20, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;A simple plugin for OllyDBG 1.10 to manage its other loaded plugins.&lt;br /&gt;&lt;br /&gt;Features:&lt;br /&gt;+ Ease of use:&lt;br /&gt;    Takes a simple double click to toggle the state of a plugin from Enabled to Disabled. The action can be also achieved&lt;br /&gt;    through a drop down menu.&lt;br /&gt;&lt;br /&gt;+ Directly compatible with major OllyDBG customized editions:&lt;br /&gt;    Directly supported by OllyICE, OllySnD, OllyDRX, DeFixed ...&lt;br /&gt;    No need for any patching work (as long as OllyDBG.exe exists)&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 22 Sep 2009 03:09:33 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: MemoryDump</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/MemoryDump</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.9a&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;August 10, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Plugin is intended to save/load bytes from momory dump window of the process in &lt;br /&gt; various forms. In the dump window right click and select 'Memory Dump' in the popup menu &lt;br /&gt; pick your choice.&lt;br /&gt;&lt;br /&gt; Possible choices are:&lt;br /&gt;&lt;br /&gt; - Load Dump&lt;br /&gt;    Allows to fill process' memory with data from a file. (Be sure what you are &lt;br /&gt;    doing, overwriting the process memory may cause you a lot of trouble.)&lt;br /&gt;&lt;br /&gt; - Save Dump&lt;br /&gt;    Copies selected bytes from dump into a file.&lt;br /&gt;			&lt;br /&gt; - Clipboard(Text)&lt;br /&gt;    Copies selected bytes from dump into a clipboard (text only).&lt;br /&gt;&lt;br /&gt; - Delphi/Pascal Table&lt;br /&gt;    Generates table of selected bytes which can be easily used in Delphi/Pascal&lt;br /&gt;&lt;br /&gt; - C/C++ Table&lt;br /&gt;    Generates table of selected bytes which can be easily used in C/C++&lt;br /&gt;&lt;br /&gt; - ASM Table&lt;br /&gt;    Generates table of selected bytes which can be easily used in Assembler &lt;br /&gt;    (MASM Tested)&lt;br /&gt;&lt;br /&gt; - Visual Basic Table&lt;br /&gt;    Generates table of selected bytes which can be easily used in Visual Basic &lt;br /&gt;&lt;br /&gt; - Range Dump (ALT+R)&lt;br /&gt;    Dumps Range of defined bytes by: &lt;br /&gt;&lt;br /&gt;	- Lenght : Tick End Address/Lenght&lt;br /&gt;        - End Address : Untick End Address/Lenght&lt;br /&gt;&lt;br /&gt;    Xor Dump With: Self-explanatory &lt;br /&gt;	&lt;br /&gt;    Button with [&amp;lt;] symbol enters address of last byte clicked(not selected) in the dump,&lt;br /&gt;    it's more convenient than entering addresses manually.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; - Xor Selection&lt;br /&gt;    Xors Selection and shows dumped data in Olly's window. This window cannot be used &lt;br /&gt;    for another byte manipulation with plugin because dump is created in your Win's &lt;br /&gt;    temporary folder and not in memory.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; - Quick Dump (ALT+Q)&lt;br /&gt;     Allows quickly select and dump data, mark the start(SHIFT+1) and the end(SHIFT+2) of &lt;br /&gt;     the block in dump window, then just press (ALT+Q).&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 11 Aug 2009 10:19:47 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: OllyBkmrX</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/OllyBkmrX</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.0.0.3&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 28, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Ollydbg bookmarking plugin&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 29 Mar 2009 10:47:36 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: AttachExtended</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/AttachExtended</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 4, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;This is a really small plugin that I have written for improving attach feature of OllyDbg.&lt;br /&gt;With this plugin,you can attach to process by identifing its PID directly,not only selecting process list. In addition,you can find PID of process by dragging a small cursor on each window(This can be used on some protection which remove process from process list like GameGuard).&lt;br /&gt;&lt;br /&gt;Please let me know about Bugs, and your suggestions for more process attaching options.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Wed, 04 Mar 2009 20:49:27 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Olly Advanced</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Olly_Advanced</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.26 Beta 12&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 13, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;A very complete selection of anti-debug settings, bugfixes and additional options for OllyDbg. Includes Help file for v1.26 Beta 5.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Thu, 05 Feb 2009 11:05:43 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: PhantOm</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/PhantOm</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.54&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;January 7, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Plugin (with driver) for hiding OllyDbg from following methods of detection:&lt;br /&gt;&lt;br /&gt;// driver - extremehide.sys&lt;br /&gt;&lt;br /&gt;[+] NtQueryInformationProcess.&lt;br /&gt;[+] SetUnhandledExceptionFilter.&lt;br /&gt;[+] OpenProcess.&lt;br /&gt;[+] Invalid Handle.&lt;br /&gt;[+] NtSetInformationThread.&lt;br /&gt;[+] RDTSC.&lt;br /&gt;[+] NtYieldExecution.&lt;br /&gt;[+] NtQueryObject.&lt;br /&gt;[+] NtQuerySystemInformation.&lt;br /&gt;[+] Windows hide.&lt;br /&gt;[+] GetProcessTimes.&lt;br /&gt;[+] NtSetContextThread.&lt;br /&gt;&lt;br /&gt;// plugin - PhantOm.dll&lt;br /&gt;&lt;br /&gt;[+] PEB BeingDebugged.&lt;br /&gt;[+] PEB NtGlobalFlag.&lt;br /&gt;[+] GetStartupInfo.&lt;br /&gt;[+] Process Heaps.&lt;br /&gt;[+] GetTickCount.&lt;br /&gt;[!] Protect DRx.&lt;br /&gt;[!] Hide DRx.&lt;br /&gt;[!] Fake Windows version.&lt;br /&gt;[!] Custom Handler.&lt;br /&gt;[+] BlockInput&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What's new - 1.30&lt;br /&gt;[*] Captions of main and CPU windows can be manually set (CAPTEXT and PRETEXT in OllyDbg's ini-file). By default, they are named &amp;quot;PhantOm&amp;quot; and &amp;quot;o_O&amp;quot;.&lt;br /&gt;[*] Fixed some bugs in &amp;quot;custom handler exceptions&amp;quot; feature&lt;br /&gt;[*] Other minor fixes&lt;br /&gt;&lt;br /&gt;What's new - 1.26&lt;br /&gt;[*] Fixed bug with loading driver&lt;br /&gt;[*] Fixed bug with memory breakpoints&lt;br /&gt; (Now, when &amp;quot;custom handler exceptions&amp;quot; option is &lt;br /&gt; checked - memory breapoints on access/write will work, &lt;br /&gt; but break-on-access won't work)&lt;br /&gt;[*] Fixed bug with updating plugin (after previous version)&lt;br /&gt;&lt;br /&gt;What's new - 1.25&lt;br /&gt;[*] Now you can manually set names of services (HIDENAME and RDTSCNAME)&lt;br /&gt;[*] Fixed some minor bugs&lt;br /&gt;[*] Fixed bug with memory breakpoints&lt;br /&gt;&lt;br /&gt;What's new - 1.20&lt;br /&gt;[*] Added own exception handler (C0000005)&lt;br /&gt;[*] Added option to change caption of main OllyDbg window&lt;br /&gt;[*] Added own exception handler (OUTPUT_DEBUG_STRING_EVENT)&lt;br /&gt;[*] Impoved removing of int 3 breakpoint at EP, when pause is set to &amp;quot;system breakpoint&amp;quot;&lt;br /&gt;[*] Added hook for BlockInput (only for Windows XP)&lt;br /&gt;[*] Added own exception handler (C0000094)&lt;br /&gt;[*] Added hide from GetStartupInfo&lt;br /&gt;[*] Fixed bug with plugin options&lt;br /&gt;[*] Added protection from detecting driver&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Mon, 26 Jan 2009 14:01:18 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: OllyStepNSearch</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/OllyStepNSearch</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.6.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 13, 2006&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;This plugin allows you to search for a given text string being referenced by the running code of a program, by automatically stepping through the debugged program and performing this analysis for each executed instruction.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Fri, 23 Jan 2009 20:13:58 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: Games Invader</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Games_Invader</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 1, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;I coded this plugin to help games hackers working on OllyDbg, it allows you to cheat games with OllyDbg.&lt;br /&gt;&lt;br /&gt;+Ability to choose memory types to scan.&lt;br /&gt;+Ability to determine the scanned memory scope.&lt;br /&gt;+Can scan for [Exact values], [Values bigger than x], [Values smaller than x] or [values between x,y] .&lt;br /&gt;+Scanning Algorithm optimized, now it's very fast than the old version.&lt;br /&gt;+Auto update for found values.&lt;br /&gt;+Known bugs fixed.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Thu, 22 Jan 2009 15:08:16 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: OllyHeapTrace</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/OllyHeapTrace</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;February 23, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;OllyHeapTrace is a plugin for OllyDbg (version 1.10) to trace the heap operations being performed by a process. It will monitor heap allocations and frees for multiple heaps, as well as operations such as creating or destroying heaps and reallocations. All parameters as well as return values are recorded and the trace is highlighted with a unique colour for each heap being traced.&lt;br /&gt;&lt;br /&gt;The primary purpose of this plugin is to aid in the debugging of heap overflows where you wish to be able to control the heap layout to overwrite a specific structure such as a chunk header, critical section structure or some application specific data. By tracing the heap operations performed during actions you can control (for example opening a connection, sending a packet, closing a connection) you can begin to predict the heap operations and thus control the heap layout.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 02 Nov 2008 05:32:42 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: BlkLabel</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/BlkLabel</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;September 30, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;BlkLabel is a bulk labelling plugIn for OllyDbg.&lt;br /&gt;&lt;br /&gt;The objective is to take a Memory Map listing from a compilation and extract all Label-Address (Symbol-Address) pairs from such a (text) file. These are then fed into OllyDbg such that it will display Symbols rather than Memory Addresses. This renders OllyDbg's presentations about as readable as is possible in a Debugging Environment.&lt;br /&gt;&lt;br /&gt;The precursor is, of course, the availability of a Memory Map in textual format. Most IDEs (Linkers) should be able to produce that.&lt;br /&gt;&lt;br /&gt;This is the link:&lt;br /&gt;&lt;br /&gt;http://www.VeronicaChapman.com/OllyDbg/BlkLabel.zip&lt;br /&gt;&lt;br /&gt;There is a ReadMe that explains the package. The PlugIn comes with a Help File that explains everything anyway (as far as I can see).&lt;br /&gt;&lt;br /&gt;The main PlugIn (BlkLabel.dll) calls a Sub-Plugin (SubLabel.dll). All of the reformatting to support the extraction of Label-Address pairs for a specific Memory Map File Format is contained within SubLabel.dll. Write a different one of those, and you can decipher the Memory Map File of your choice. You just need to create an Export to handle (maybe translate) each Character, and another to decipher each Text Record. BlkLabel itself handles all the rest.&lt;br /&gt;&lt;br /&gt;Oh. There's just one small thing. The Source Code is contained in the package, but the PlugIn is written in Clarion ... so I don't know if it will be much use to you but if it is you are welcome to use it.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Fri, 24 Oct 2008 21:52:17 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Modified Command Line Plugin</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Modified_Command_Line_Plugin</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;April 23, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Useful new features added to default Cmdline.dll plugin:&lt;br /&gt;LOADDLL - load a dll into the context of the debugee.&lt;br /&gt;LOADPDB - load PDB symbol files into Olly directly from Microsoft server.&lt;br /&gt;LOADPLUGIN - load a plugin dynamically without restarting Olly. Bypasses 32 plugin limit.&lt;br /&gt;PRINT - allows multiple expressions to be output to log window per conditional breakpoint.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Mon, 18 Aug 2008 19:47:40 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Uhooker</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Uhooker</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.3&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;December 17, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;The Universal Hooker is a tool to intercept execution of programs. It enables the user to intercept calls to API calls inside DLLs, and also arbitrary addresses within the executable file in memory. Requires Python interpreter. Zip file includes the online documentation and script examples, but see author link for latest updates.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sat, 02 Aug 2008 11:11:40 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: AttachAnyway</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/AttachAnyway</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Extensions&quot;&gt;OllyDbg Extensions&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.3&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;September 7, 2005&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;AttachAnyway is a PoC OllyDbg plugin designed to show how to remove a process' hook on NtContinue by the anti-debugger-attach method devised by Piotr Bania here:&lt;br /&gt;&lt;br /&gt;http://pb.specialised.info/all/anti-dattach.asm&lt;br /&gt;&lt;br /&gt;This is not intended to be a universal plugin for all anti-attach methods, just one example of how you can do it. It works by enumerating all processes, searching their virtual memory space for a JMP hook on the NtContinue method, then replacing the jump with the original bytes from a non-hooked process, then calling the OllyDbg Attachtoactiveprocess API.&lt;br /&gt;&lt;br /&gt;attach-test.exe is an assembled version of Piotr's anti-dattach.asm you can use to test the plugin with.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Thu, 19 Jun 2008 08:55:30 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Immunity Debugger</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Immunity_Debugger</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:OllyDbg_Custom_Versions&quot;&gt;OllyDbg Custom Versions&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Ring_3_Debuggers&quot;&gt;Ring 3 Debuggers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.6&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 27, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Immunity Debugger is based on OllyDbg.&lt;br /&gt;&lt;br /&gt;Immunity Debugger is a powerful new way to write exploits, analyze malware, and reverse engineer binary files. It builds on a solid user interface with function graphing, the industry's first heap analysis tool built specifically for heap creation, and a large and well supported Python API for easy extensibility.&lt;br /&gt;&lt;br /&gt;* A debugger with functionality designed specifically for the security industry&lt;br /&gt;* Cuts exploit development time by 50%&lt;br /&gt;* Simple, understandable interfaces&lt;br /&gt;* Robust and powerful scripting language for automating intelligent debugging&lt;br /&gt;* Lightweight and fast debugging to prevent corruption during complex analysis&lt;br /&gt;* Connectivity to fuzzers and exploit development tools&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Mon, 02 Jun 2008 14:01:18 GMT</pubDate>								</item>
	</channel>
</rss>