We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Windows 10, x64, 19043.1055
Jun 14 2021 (NO plugins)
This PoC will fail if you have running debugging:
#include <Windows.h> #include <iostream> const auto NTDLL = L"C:\\Windows\\system32\\ntdll.dll"; int main() { auto isOK = CreateFileW(NTDLL, 0x80000000, NULL, NULL, 0x3, 0x80, NULL); std::cout << std::hex << isOK << std::endl; system("pause"); }
No response
The text was updated successfully, but these errors were encountered:
I might be wrong but I think this is x64dbg/TitanEngine#5
Sorry, something went wrong.
Hmm... Actually I guess you could be right. I'll test it again soon. However, this is not about the process itself. It is about system library.
Add an AntiDebugHandle test (and make sure it doesn't trigger)
869617a
References: - x64dbg/x64dbg#2749 - x64dbg/x64dbg#1364 - x64dbg/TitanEngine#5 - x64dbg/x64dbg#2504
Fix an anti-debug trick used by GuLoader
ffb6de5
Closes #2749 Closes #2504
Successfully merging a pull request may close this issue.
Operating System
Windows 10, x64, 19043.1055
x64dbg Version
Jun 14 2021 (NO plugins)
Describe the issue
This PoC will fail if you have running debugging:
Steps to reproduce
Attachments
No response
The text was updated successfully, but these errors were encountered: