@hyperdbg

@hyperdbg / Public archive of HyperDbg Telegram messages.

  • 2025

    • Mar 2025 (385)
    • Feb 2025 (220)
    • Jan 2025 (167)
  • 2024

    • Dec 2024 (72)
    • Nov 2024 (235)
    • Oct 2024 (83)
    • Sep 2024 (263)
    • Aug 2024 (332)
    • Jul 2024 (403)
    • Jun 2024 (570)
    • May 2024 (245)
    • Apr 2024 (156)
    • Mar 2024 (90)
    • Feb 2024 (134)
    • Jan 2024 (309)
  • 2023

    • Dec 2023 (62)
    • Nov 2023 (326)
    • Oct 2023 (76)
    • Sep 2023 (315)
    • Aug 2023 (757)
    • Jul 2023 (2215)
    • Jun 2023 (778)
    • May 2023 (300)
    • Apr 2023 (1)
    • Feb 2023 (5)
    • Jan 2023 (1)
  • 2022

    • Nov 2022 (1)
    • Oct 2022 (2)
    • Sep 2022 (1)
    • Aug 2022 (1)
    • Jul 2022 (39)
    • Jun 2022 (23)
    • May 2022 (256)
  • 2021

    • Dec 2021 (1)
    • Oct 2021 (82)
    • Jun 2021 (1)
    • Feb 2021 (1)
    • Jan 2021 (2)
  • 2020

    • Dec 2020 (1)
    • Nov 2020 (2)
RSS feed.    Made with tg-archive
  • 01 October 2023 (28 messages)
  • @6388476678 #4965 12:51 AM, 01 Oct 2023
    hey
    is there a specific protocol I need to configure in order to get the serial connection working?
  • @6388476678 #4966 12:51 AM, 01 Oct 2023
    i'm trying to setup a communication between 2 physical machines
  • @6388476678 #4967 12:51 AM, 01 Oct 2023
    for that I'm using a program called "Serial to Ethernet Connector"
  • @6388476678 #4968 12:51 AM, 01 Oct 2023

    photo_2023-10-01_00-51-56.jpg
  • @6388476678 #4969 12:51 AM, 01 Oct 2023
    it just hangs there
  • @HughEverett #4970 04:15 AM, 01 Oct 2023
    Hi,
    The physical serial device proved to be problematic most likely because of verification of packets. You have to wait until we add the support to kdnet in the future version. Right now, you can use it on VMware serial devices.
  • @HughEverett #4971 04:17 AM, 01 Oct 2023
    Another option is using HyperDbg in VMI mode, but in the VMI Mode, you couldn't pause or step debuggee.
  • @HughEverett ↶ Reply to #4801 #4972 04:21 AM, 01 Oct 2023
    Also, we super appreciate if anybody can help with this. šŸ™‚
  • @6388476678 ↶ Reply to #4971 #4973 05:08 AM, 01 Oct 2023
    I just wanted to trace some calls, VMI did the job
  • @6388476678 #4974 05:09 AM, 01 Oct 2023
    Also
  • @6388476678 #4975 05:09 AM, 01 Oct 2023
    Very nice project
  • @6388476678 #4976 03:42 PM, 01 Oct 2023

    photo_2023-10-01_15-42-31.jpg
  • @6388476678 #4977 03:42 PM, 01 Oct 2023
    I have symbols for kernel32 loaded
  • @6388476678 #4978 03:42 PM, 01 Oct 2023
    what am I doing wrong?
  • @prekvapko #4979 04:10 PM, 01 Oct 2023
    aren't you missing the underscore for the symbol?
  • @6388476678 ↶ Reply to #4979 #4980 04:31 PM, 01 Oct 2023
    like this?

    photo_2023-10-01_16-31-44.jpg
  • @prekvapko #4981 04:32 PM, 01 Oct 2023
    ah i see
  • @prekvapko #4982 04:32 PM, 01 Oct 2023
    just use VA then
  • @prekvapko #4983 04:32 PM, 01 Oct 2023

    photo_2023-10-01_16-32-18.jpg
  • @prekvapko #4984 04:32 PM, 01 Oct 2023
    ahhh i just noticed
  • @prekvapko #4985 04:32 PM, 01 Oct 2023
    ur problem
  • @prekvapko #4986 04:32 PM, 01 Oct 2023
    yeah guess just use address
  • @prekvapko #4987 04:32 PM, 01 Oct 2023
    sometimes it does some memes
  • @6388476678 #4988 04:33 PM, 01 Oct 2023
    dang it
  • @6388476678 #4989 04:33 PM, 01 Oct 2023
    i actually wanted to hook GetProcAddress
  • @6388476678 ↶ Reply to #4801 #4990 04:56 PM, 01 Oct 2023
    I could only find:
    C:\Program Files (x86)\Windows Kits\10\Debuggers\ddk\samples\kdnet

    Can you share the path?
  • @HughEverett ↶ Reply to #4989 #4991 06:51 PM, 01 Oct 2023
    The problem with kernel32 is solved? 🤨
    I don't know why, sometimes I have the same problem with Kernel32 and KernelBase but sometime it's working. šŸ¤”
  • @HughEverett ↶ Reply to #4990 #4992 06:52 PM, 01 Oct 2023
    Yep, I meant this project.
  • 02 October 2023 (1 messages)
  • @6388476678 ↶ Reply to #4801 #4993 03:04 AM, 02 Oct 2023
    This might be useful:
    https://github.com/maharmstone/quibble/blob/master/src/debug.cpp
    quibble/src/debug.cpp at master Ā· maharmstone/quibble

    Quibble - the custom Windows bootloader. Contribute to maharmstone/quibble development by creating an account on GitHub.

  • 04 October 2023 (2 messages)
  • @Non32u #4994 08:31 AM, 04 Oct 2023
    Joined.
  • @1781413603 #4995 11:09 AM, 04 Oct 2023
    Joined.
  • 05 October 2023 (3 messages)
  • @1670864595 #4996 07:38 AM, 05 Oct 2023
    Joined.
  • @xmaple555 ↶ Reply to #4989 #4997 07:13 PM, 05 Oct 2023
    https://github.com/HyperDbg/HyperDbg/pull/276
    Update SymConvertNameToAddress by xmaple555 Ā· Pull Request #276 Ā· HyperDbg/HyperDbg

    Description

  • @6388476678 #4998 07:14 PM, 05 Oct 2023
    noice
  • 08 October 2023 (3 messages)
  • @xmaple555 #5000 08:45 AM, 08 Oct 2023
    hi, dose anyone try to use copilot to develop windows kernel driver ?
  • @xmaple555 #5001 08:45 AM, 08 Oct 2023
    I wonder if it is useful
  • @6388476678 #5002 02:18 PM, 08 Oct 2023
    i've never tried but it might be useful to synthesize manuals/papers
  • 09 October 2023 (1 messages)
  • @barbone010 #5003 10:03 PM, 09 Oct 2023
    Joined.
  • 13 October 2023 (1 messages)
  • @vietdox #5004 07:23 AM, 13 Oct 2023
    Joined.
  • 22 October 2023 (1 messages)
  • @honorary_bot #5005 10:59 PM, 22 Oct 2023
    Joined.
  • 23 October 2023 (5 messages)
  • @HughEverett ↶ Reply to #5005 #5006 07:55 AM, 23 Oct 2023
    Hey!
    @honorary_bot, are you the same person who created PulseDbg?
  • @honorary_bot #5007 07:55 AM, 23 Oct 2023
    Wassup, yep ;)
  • @HughEverett ↶ Reply to #5007 #5008 07:56 AM, 23 Oct 2023
    Wow, welcome!
  • @HughEverett #5009 07:56 AM, 23 Oct 2023
    vmiss33 - 1711065099207639527.gif.mp4
  • @honorary_bot #5010 07:56 AM, 23 Oct 2023
    Thanks! I’m curious too see how your project evolves as well
  • 24 October 2023 (1 messages)
  • @Shithemotherteam #5011 12:17 PM, 24 Oct 2023
    Joined.
  • 25 October 2023 (9 messages)
  • @1670864595 #5012 12:16 AM, 25 Oct 2023
    Joined.
  • @1670864595 #5013 12:18 AM, 25 Oct 2023
    @HughEverett, @mrexodia, did you saw that?

    (Don't be confused, the paper is written in English, not Russian)
  • @HughEverett ↶ Reply to #5013 #5014 04:14 AM, 25 Oct 2023
    Thanks for sharing. I will check it.
  • @1670864595 ↶ Reply to #5013 #5015 08:05 AM, 25 Oct 2023
    R. K. Lebedev - Using x86 mode switching for program code protection [25 October 2023]
    R_K_Lebedev_Using_x86_mode_switching_for_program_code_protection.pdf
  • @invlpg ↶ Reply to #5015 #5016 08:13 AM, 25 Oct 2023
    haven't read that yet, but by looking at first glance i assume that they're somehow abusing the fs stuff to switch your execution from x64 to x86 and vice versa
    old news, no? all these techniques(heaven's/hell's gate) techniques were pretty much already discussed hundreds of thousands of times already
    not sure what could you do to achieve some code protection by switching the execution mode šŸ¤”
  • @invlpg #5017 08:15 AM, 25 Oct 2023
    i mean i totally get the point that it could confuse debuggers(windbg, for example, handles such stuff flawlessly)/disassemblers but it is pretty much expected and i wouldn't really call it some code-protection technique
  • @HughEverett ↶ Reply to #5015 #5018 01:00 PM, 25 Oct 2023
    I have a glance at it and yeah, I agree with @invlpg. There are pretty good details about WOW64 mode switches but I think the method cannot be useful to be implemented in a debugger.
  • @HughEverett #5019 01:03 PM, 25 Oct 2023
    In HyperDbg we already have a command (called !mode) that I added months ago (not yet document it and it's not yet well tested) but this '!mode' event detects user-mode to kernel-mode and kernel-mode to user-mode events and trigger a HyperDbg debugging event for each of them based on the process specified by the user. I think this could be more meaningful rather than detecting x64 to x86 (or x86 to x86). But the article itself was good (and the intention of the author was proposing an obfuscation method rather than making it useful for a debugger).
  • @HughEverett ↶ Reply to #5019 #5020 01:08 PM, 25 Oct 2023
    And there's one more thing I wanted to mention. I think I vaguely remember (not sure) reading about GDT protection bits in a recent document from Intel. They were talking about potentially removing GDT protection bits in future generations of Intel processors, and if that's the case, this method might also be up for some changes.
  • 28 October 2023 (5 messages)
  • @Cynical9 #5021 11:13 AM, 28 Oct 2023
    Hey all!

    I am trying to debug the kernel but neither of my computers have serial ports, is there an app that can create a virtual serial port that works? or what is the best thing to do?
  • @HughEverett ↶ Reply to #5021 #5022 01:48 PM, 28 Oct 2023
    Hi
    You have two options, either use HyperDbg in the VMI Mode (local debugging) or use a virtual machine (VMware) in the Debugger Mode.
  • @Ffcbht #5023 01:55 PM, 28 Oct 2023
    2021003123639035
  • @HughEverett ↶ Reply to #5023 #5024 01:56 PM, 28 Oct 2023
    ??
  • @invlpg ↶ Reply to #5023 #5025 02:00 PM, 28 Oct 2023
    wtf
  • 29 October 2023 (1 messages)
  • @nim0x2a #5026 09:26 AM, 29 Oct 2023
    Joined.
  • 30 October 2023 (7 messages)
  • @5781093824 ↶ Reply to #5023 #5027 10:32 PM, 30 Oct 2023
    ęˆ‘äøåŒę„
  • @Secret00Sec #5028 10:33 PM, 30 Oct 2023
    å•„å‡ ęŠŠēŽ©ę„
  • @5781093824 #5029 10:39 PM, 30 Oct 2023
    ę—§ēš„å®‰č£…
  • @5539033269 #5030 10:55 PM, 30 Oct 2023
    å§ę§½
  • @5539033269 #5031 10:55 PM, 30 Oct 2023
    @sina looks like u got some users from China
  • @blackjustinFR #5032 10:56 PM, 30 Oct 2023
    anyone have good skill / knowledge about hyperv here ?
  • @5539033269 #5033 10:58 PM, 30 Oct 2023
    I think recruitment is not allowed here~
  • 31 October 2023 (8 messages)
  • @xmaple555 #5034 03:36 PM, 31 Oct 2023

    photo_2023-10-31_15-36-29.jpg
  • @xmaple555 #5035 03:36 PM, 31 Oct 2023
    does anyone get the error ?
  • @xmaple555 #5036 03:36 PM, 31 Oct 2023
    the last dev
  • @xmaple555 #5037 03:46 PM, 31 Oct 2023
    the error is from https://github.com/HyperDbg/HyperDbg/commit/db4f693dcade11411d3ca2a37d86eb2366f329c3
    add support for TSC and PMC on direct termination Ā· HyperDbg/HyperDbg@db4f693

    State-of-the-art native debugging tool. Contribute to HyperDbg/HyperDbg development by creating an account on GitHub.

  • @HughEverett ↶ Reply to #5037 #5038 05:59 PM, 31 Oct 2023
    This is not the latest in the dev, can you 'git pull' it again?
  • @invlpg ↶ Reply to #5032 #5039 06:00 PM, 31 Oct 2023
    bro just stop it already 😭
  • @invlpg #5040 06:00 PM, 31 Oct 2023
    nobody would paste a hypervisor for your p2c
  • @xmaple555 ↶ Reply to #5038 #5041 11:55 PM, 31 Oct 2023
    I mean the error start from the commit https://github.com/HyperDbg/HyperDbg/commit/db4f693dcade11411d3ca2a37d86eb2366f329c3 to the last dev
    add support for TSC and PMC on direct termination Ā· HyperDbg/HyperDbg@db4f693

    State-of-the-art native debugging tool. Contribute to HyperDbg/HyperDbg development by creating an account on GitHub.

  • 01 Oct 2023 (28)
  • 02 Oct 2023 (1)
  • 04 Oct 2023 (2)
  • 05 Oct 2023 (3)
  • 08 Oct 2023 (3)
  • 09 Oct 2023 (1)
  • 13 Oct 2023 (1)
  • 22 Oct 2023 (1)
  • 23 Oct 2023 (5)
  • 24 Oct 2023 (1)
  • 25 Oct 2023 (9)
  • 28 Oct 2023 (5)
  • 29 Oct 2023 (1)
  • 30 Oct 2023 (7)
  • 31 Oct 2023 (8)