Esta vez prometo no dejarme llevar por mi pluma, ¿o debería decir mejor mi teclado?, y en esta entrada únicamente me haré eco de la release de un módulo de python a priori bastante interesante.
Se tata de winAppDbg y su mayor atractivo es la posibilidad de utilizarlo en nuestros propios scripts para implementar tareas de debugging de aplicaciones win32. ¿Resultará interesante como 'framework' para análisis de malware?, sólo el tiempo dirá.
Corto y pego el contenido del mensaje enviado a bugtraq:
What is WinAppDbg?
==================
The WinAppDbg python module allows developers to quickly code instrumentation scripts in Python under a Windows environment.
It uses ctypes to wrap many Win32 API calls related to debugging, and provides an object-oriented abstraction layer to manipulate threads, libraries and processes, attach your script as a debugger, trace execution, hook API calls, handle events in your debugee and set breakpoints of different kinds (code, hardware and memory). Additionally it has no native code at all, making it easier to maintain or modify than other debuggers on Windows.
The intended audience are QA engineers and software security auditors wishing to
test/fuzz Windows applications with quickly coded Python scripts. Several ready to use utilities are shipped and can be used for this purposes.
Current features also include disassembling x86 native code (using the open source diStorm project, see http://ragestorm.net/distorm/), debugging multiple processes simultaneously and produce a detailed log of application crashes, useful for fuzzing and automated testing.
Where can I find WinAppDbg?
===========================
The WinAppDbg project is currently hosted at Sourceforge, and can be found at:
http://winappdbg.sourceforge.net/
It's also hosted at the Python Package Index (PyPi):
http://pypi.python.org/pypi/winappdbg/1.1
Hasta pronto ;-)
miércoles, 20 de mayo de 2009
WinAppDbg v1.1 is out!
Etiquetas:
herramientas
Suscribirse a:
Enviar comentarios (Atom)
2 comentarios:
¡¡Voy a probarlo!! Ya!!
¡Pues ya nos contarás!
Me temo que con el poco tiempo libre que tengo ahora mismo todavía faltará para que pueda hincarle el diente.
Saludos
Publicar un comentario