<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://www.woodmann.com/collaborative/tools/skins/common/feed.css?97"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.woodmann.com/collaborative/tools/index.php?title=PhantOm&amp;action=feed&amp;feed=atom</id>
		<title>Collaborative RCE Tool Library - PhantOm</title>
		<link rel="self" type="application/atom+xml" href="http://www.woodmann.com/collaborative/tools/index.php?title=PhantOm&amp;action=feed&amp;feed=atom"/>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/PhantOm"/>
		<updated>2009-11-21T22:22:39Z</updated>
		<subtitle>Update Notification Feed for PhantOm</subtitle>
		<generator>MediaWiki 1.11.2 via WikiArticleFeeds 0.6.3 (+ dELTA mods)</generator>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/PhantOm</id>
		<title> Tool Updated: PhantOm </title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/PhantOm"/>
				<updated>2009-11-21T22:22:00Z</updated>
		
		<summary type="html">
&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.54&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;January 7, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Plugin (with driver) for hiding OllyDbg from following methods of detection:&lt;br /&gt;&lt;br /&gt;// driver - extremehide.sys&lt;br /&gt;&lt;br /&gt;[+] NtQueryInformationProcess.&lt;br /&gt;[+] SetUnhandledExceptionFilter.&lt;br /&gt;[+] OpenProcess.&lt;br /&gt;[+] Invalid Handle.&lt;br /&gt;[+] NtSetInformationThread.&lt;br /&gt;[+] RDTSC.&lt;br /&gt;[+] NtYieldExecution.&lt;br /&gt;[+] NtQueryObject.&lt;br /&gt;[+] NtQuerySystemInformation.&lt;br /&gt;[+] Windows hide.&lt;br /&gt;[+] GetProcessTimes.&lt;br /&gt;[+] NtSetContextThread.&lt;br /&gt;&lt;br /&gt;// plugin - PhantOm.dll&lt;br /&gt;&lt;br /&gt;[+] PEB BeingDebugged.&lt;br /&gt;[+] PEB NtGlobalFlag.&lt;br /&gt;[+] GetStartupInfo.&lt;br /&gt;[+] Process Heaps.&lt;br /&gt;[+] GetTickCount.&lt;br /&gt;[!] Protect DRx.&lt;br /&gt;[!] Hide DRx.&lt;br /&gt;[!] Fake Windows version.&lt;br /&gt;[!] Custom Handler.&lt;br /&gt;[+] BlockInput&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What's new - 1.30&lt;br /&gt;[*] Captions of main and CPU windows can be manually set (CAPTEXT and PRETEXT in OllyDbg's ini-file). By default, they are named &amp;quot;PhantOm&amp;quot; and &amp;quot;o_O&amp;quot;.&lt;br /&gt;[*] Fixed some bugs in &amp;quot;custom handler exceptions&amp;quot; feature&lt;br /&gt;[*] Other minor fixes&lt;br /&gt;&lt;br /&gt;What's new - 1.26&lt;br /&gt;[*] Fixed bug with loading driver&lt;br /&gt;[*] Fixed bug with memory breakpoints&lt;br /&gt; (Now, when &amp;quot;custom handler exceptions&amp;quot; option is &lt;br /&gt; checked - memory breapoints on access/write will work, &lt;br /&gt; but break-on-access won't work)&lt;br /&gt;[*] Fixed bug with updating plugin (after previous version)&lt;br /&gt;&lt;br /&gt;What's new - 1.25&lt;br /&gt;[*] Now you can manually set names of services (HIDENAME and RDTSCNAME)&lt;br /&gt;[*] Fixed some minor bugs&lt;br /&gt;[*] Fixed bug with memory breakpoints&lt;br /&gt;&lt;br /&gt;What's new - 1.20&lt;br /&gt;[*] Added own exception handler (C0000005)&lt;br /&gt;[*] Added option to change caption of main OllyDbg window&lt;br /&gt;[*] Added own exception handler (OUTPUT_DEBUG_STRING_EVENT)&lt;br /&gt;[*] Impoved removing of int 3 breakpoint at EP, when pause is set to &amp;quot;system breakpoint&amp;quot;&lt;br /&gt;[*] Added hook for BlockInput (only for Windows XP)&lt;br /&gt;[*] Added own exception handler (C0000094)&lt;br /&gt;[*] Added hide from GetStartupInfo&lt;br /&gt;[*] Fixed bug with plugin options&lt;br /&gt;[*] Added protection from detecting driver&lt;/i&gt;
&lt;/p&gt;
&lt;pre&gt;</summary>
			</entry>

	</feed>