Skip to content

VMProtect detection when using gdb attach #3

@Silur

Description

@Silur

Works great on the same executable when using the ollydbg plugin but when I inject from the CLI and run gdb-server 0.0.0.0:4444 --attach <injected pid> and attach a remote dbg instance, the debugger get's detected and I'm looking at the heavily obfuscated endless loops and self-referrent jumps as without using scylla.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions