Author Topic: Tool for examining a running process?  (Read 5884 times)

0 Members and 1 Guest are viewing this topic.

Offline taj

  • Bytes hurt
  • DBF Aficionado
  • ******
  • Posts: 4810
  • Karma: 189
  • Scene there, done that.
    • View Profile
Tool for examining a running process?
« on: September 27, 2007 »
Suppose I have  ... xyz.exe ... running on my XP machine. Is there a tool to allow me to get a memory dump of the running process...ie to look at the bytes of the exe? I'm happy to do it dynamically or use a tool to dump it and then do it offline. Assume the exe is compiled without debug.

Chris
Challenge Trophies Won:

Offline taj

  • Bytes hurt
  • DBF Aficionado
  • ******
  • Posts: 4810
  • Karma: 189
  • Scene there, done that.
    • View Profile
Re: Tool for examining a running process?
« Reply #1 on: September 27, 2007 »
Chris why dont you check:

http://www.e-evidence.info/other.html

memfetch is what you are looking for I think. Next time please try a more thorough web search - we're not here to do your home work you know!
Challenge Trophies Won:

Offline taj

  • Bytes hurt
  • DBF Aficionado
  • ******
  • Posts: 4810
  • Karma: 189
  • Scene there, done that.
    • View Profile
Re: Tool for examining a running process?
« Reply #2 on: September 27, 2007 »
Thanks Chris - Karma++.

Yes I'll try harder next time.
Challenge Trophies Won:

Offline Shockwave

  • good/evil
  • Founder Member
  • DBF Aficionado
  • ********
  • Posts: 17409
  • Karma: 498
  • evil/good
    • View Profile
    • My Homepage
Re: Tool for examining a running process?
« Reply #3 on: September 27, 2007 »
Hmm...

I guess that you could search for ollydebug and lordpe which would do the job I think. :)

If you can't get hold of them because they might be hard to find, I have them here, if you want those things then give me an email address to send them to via pm.

I won't post a link because they can easily be used for illegal stuff.
Shockwave ^ Codigos
Challenge Trophies Won:

Offline taj

  • Bytes hurt
  • DBF Aficionado
  • ******
  • Posts: 4810
  • Karma: 189
  • Scene there, done that.
    • View Profile
Re: Tool for examining a running process?
« Reply #4 on: September 27, 2007 »
Hmm...

I guess that you could search for ollydebug and lordpe which would do the job I think. :)

Dont they just work on exe files, not on processes? Or am I wrong?

No I just checked I am infact wrong, ollydebug can attach to a running process.
BTW shockie a c compiler can be used for hacking too so I dont get the logic of not posting a link  :stirrer:
« Last Edit: September 27, 2007 by chris »
Challenge Trophies Won:

Offline Shockwave

  • good/evil
  • Founder Member
  • DBF Aficionado
  • ********
  • Posts: 17409
  • Karma: 498
  • evil/good
    • View Profile
    • My Homepage
Re: Tool for examining a running process?
« Reply #5 on: September 27, 2007 »
Ah sorry Chris, I mis-read your intention I thought you wanted it to see what was happening in a program.

Shockwave ^ Codigos
Challenge Trophies Won:

Offline slippy

  • Atari ST
  • ***
  • Posts: 172
  • Karma: 42
    • View Profile
Re: Tool for examining a running process?
« Reply #6 on: September 27, 2007 »
and what's up with the little tool called procdump? ... I've heard of a few years ago ... it's quite old but could be of use for you ... you might check this :)

just google for "procdump" ...

SLiPPY

Offline Jim

  • Founder Member
  • DBF Aficionado
  • ********
  • Posts: 5301
  • Karma: 402
    • View Profile
Re: Tool for examining a running process?
« Reply #7 on: September 27, 2007 »
PE Explorer?
Challenge Trophies Won:

Offline rain_storm

  • Here comes the Rain
  • DBF Aficionado
  • ******
  • Posts: 3088
  • Karma: 182
  • Rain never hurt nobody
    • View Profile
    • org_100h
Re: Tool for examining a running process?
« Reply #8 on: October 17, 2007 »
You should try IDA Pro Advanced it will allow you to do a memory dump at any stage during execution. You can attach processes manually or let the program do that itself. But of course IDA Pro is not free.

Challenge Trophies Won:

Offline Jim

  • Founder Member
  • DBF Aficionado
  • ********
  • Posts: 5301
  • Karma: 402
    • View Profile
Re: Tool for examining a running process?
« Reply #9 on: October 17, 2007 »
It's not free, in fact it's bloody expensive.  But it is totally superb!

Jim
Challenge Trophies Won:

Offline spitfire

  • Amiga 1200
  • ****
  • Posts: 275
  • Karma: 9
    • View Profile
Re: Tool for examining a running process?
« Reply #10 on: October 17, 2007 »
If you have visual studio, spy++ is quite nice for win32 apps. Look under the tools subdirectory in VS start menu directory.

Offline taj

  • Bytes hurt
  • DBF Aficionado
  • ******
  • Posts: 4810
  • Karma: 189
  • Scene there, done that.
    • View Profile
Re: Tool for examining a running process?
« Reply #11 on: October 17, 2007 »
If you have visual studio, spy++ is quite nice for win32 apps. Look under the tools subdirectory in VS start menu directory.

Thanks spitfire, I'll try that aswell as ollydebug.
Challenge Trophies Won: