-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/628/rafal-wojtczuks-user-mode-single-stepping-100x-faster-than-debuggers/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
call $+5
pop ebp
mov eax, [ebp+5]
cmp eax, 0xBADDEED
jnz you're tracing me
High speed is good of course, but single-steps
are usually only needed on truly nasty code,
and in truly nasty code heavy modification of
the target address space should be avoided.
in a way you're right, but if they implemented their tracer well, then 'call $+5' will result in the 'real' eip and thus your trick won't work.