<?xml version="1.0"?><?xml-stylesheet type="text/xsl" href="/rss.xsl"?><rss version="2.0"><channel><title>msecdbg Releases Rss Feed</title><link>http://msecdbg.codeplex.com/Release/ProjectReleases.aspx</link><description>msecdbg Releases Rss Description</description><item><title>Updated Release: !exploitable 1.6 (May 01, 2013)</title><link>https://msecdbg.codeplex.com/releases/view/106021</link><description>&lt;div class="wikidoc"&gt;1.6.0 Updates:&lt;br /&gt;&lt;br /&gt;ARM Dump Support Added&lt;br /&gt;Changed default hashing algorithm to SHA256&lt;br /&gt;Added Support to chose the hashing algorithm used (for backwards compatibility) &lt;br /&gt;Added support for custom exclude hash list&lt;br /&gt;Updated -v output to show which frames are used to determine the major and minor hash&lt;br /&gt;Added version number logging&lt;br /&gt;Added line number and source file reporting&lt;br /&gt;Added checking for exception handler chain corruption as an Exploitable case&lt;br /&gt;Added Stack Exhaustion as a Probably Not Exploitable case&lt;br /&gt;Added more AppVerifier symbols to the excluded symbols list&lt;br /&gt;Added checking for kernel mode code running in user land as an Exploitable case&lt;br /&gt;Moved &amp;quot;Read AV Near Null&amp;quot; to terminal rule status&lt;br /&gt;Added &amp;quot;App Verifier Stop Detected&amp;quot;&lt;br /&gt;Moved &amp;quot;Read AV Near Null&amp;quot; to Probably Not Exploitable&lt;br /&gt;Moved &amp;quot;Write AV Near Null&amp;quot; to Unknown&lt;br /&gt;Added the XLAT command for x86 and x64  &lt;br /&gt;Correctly pull the TEB32 for WOW process on 64 bit Windows&lt;br /&gt;Translate stack exhaustion cases that manifest as Write AVs into stack exhaustion&lt;br /&gt;Changed the naming of Stack Overflow to Stack Exhaustion&lt;br /&gt;Fixed a bug in the logic determining if code is in user or kernel space&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>AndyRenk</author><pubDate>Thu, 02 May 2013 00:17:27 GMT</pubDate><guid isPermaLink="false">Updated Release: !exploitable 1.6 (May 01, 2013) 20130502121727A</guid></item><item><title>Released: !exploitable 1.6 (May 01, 2013)</title><link>http://msecdbg.codeplex.com/releases/view/106021</link><description>
&lt;div class="wikidoc"&gt;1.6.0 Updates:&lt;br&gt;
&lt;br&gt;
ARM Dump Support Added&lt;br&gt;
Changed default hashing algorithm to SHA256&lt;br&gt;
Added Support to chose the hashing algorithm used (for backwards compatibility) &lt;br&gt;
Added support for custom exclude hash list&lt;br&gt;
Updated -v output to show which frames are used to determine the major and minor hash&lt;br&gt;
Added version number logging&lt;br&gt;
Added line number and source file reporting&lt;br&gt;
Added checking for exception handler chain corruption as an Exploitable case&lt;br&gt;
Added Stack Exhaustion as a Probably Not Exploitable case&lt;br&gt;
Added more AppVerifier symbols to the excluded symbols list&lt;br&gt;
Added checking for kernel mode code running in user land as an Exploitable case&lt;br&gt;
Moved &amp;quot;Read AV Near Null&amp;quot; to terminal rule status&lt;br&gt;
Added &amp;quot;App Verifier Stop Detected&amp;quot;&lt;br&gt;
Moved &amp;quot;Read AV Near Null&amp;quot; to Probably Not Exploitable&lt;br&gt;
Moved &amp;quot;Write AV Near Null&amp;quot; to Unknown&lt;br&gt;
Added the XLAT command for x86 and x64 &lt;br&gt;
Correctly pull the TEB32 for WOW process on 64 bit Windows&lt;br&gt;
Translate stack exhaustion cases that manifest as Write AVs into stack exhaustion&lt;br&gt;
Changed the naming of Stack Overflow to Stack Exhaustion&lt;br&gt;
Fixed a bug in the logic determining if code is in user or kernel space&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Thu, 02 May 2013 00:17:27 GMT</pubDate><guid isPermaLink="false">Released: !exploitable 1.6 (May 01, 2013) 20130502121727A</guid></item><item><title>Updated Release: !exploitable 1.6 (May 01, 2013)</title><link>https://msecdbg.codeplex.com/releases/view/106021</link><description>&lt;div class="wikidoc"&gt;1.6.0 Updates:&lt;br /&gt;&lt;br /&gt;ARM Dump Support Added&lt;br /&gt;Changed default hashing algorithm to SHA256&lt;br /&gt;Added Support to chose the hashing algorithm used (for backwards compatibility) &lt;br /&gt;Added support for custom exclude hash list&lt;br /&gt;Updated -v output to show which frames are used to determine the major and minor hash&lt;br /&gt;Added version number logging&lt;br /&gt;Added line number and source file reporting&lt;br /&gt;Added checking for exception handler chain corruption as an Exploitable case&lt;br /&gt;Added Stack Exhaustion as a Probably Not Exploitable case&lt;br /&gt;Added more AppVerifier symbols to the excluded symbols list&lt;br /&gt;Added checking for kernel mode code running in user land as an Exploitable case&lt;br /&gt;Moved &amp;quot;Read AV Near Null&amp;quot; to terminal rule status&lt;br /&gt;Added &amp;quot;App Verifier Stop Detected&amp;quot;&lt;br /&gt;Moved &amp;quot;Read AV Near Null&amp;quot; to Probably Not Exploitable&lt;br /&gt;Moved &amp;quot;Write AV Near Null&amp;quot; to Unknown&lt;br /&gt;Added the XLAT command for x86 and x64  &lt;br /&gt;Correctly pull the TEB32 for WOW process on 64 bit Windows&lt;br /&gt;Translate stack exhaustion cases that manifest as Write AVs into stack exhaustion&lt;br /&gt;Changed the naming of Stack Overflow to Stack Exhaustion&lt;br /&gt;Fixed a bug in the logic determining if code is in user or kernel space&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>AndyRenk</author><pubDate>Thu, 02 May 2013 00:11:40 GMT</pubDate><guid isPermaLink="false">Updated Release: !exploitable 1.6 (May 01, 2013) 20130502121140A</guid></item><item><title>Updated Release: Automation Scripts (May 01, 2013)</title><link>https://msecdbg.codeplex.com/releases/view/106022</link><description>&lt;div class="wikidoc"&gt;&lt;b&gt;Classify&lt;/b&gt; - A batch file used to sport crash dumps based on !exploitable output.&lt;br /&gt;&lt;b&gt;DebugWrapper&lt;/b&gt; - A batch file used to debug an application. If a crash occurs it is evaluated by !exploitable and a crash dump is saved and sorted.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>AndyRenk</author><pubDate>Thu, 02 May 2013 00:11:06 GMT</pubDate><guid isPermaLink="false">Updated Release: Automation Scripts (May 01, 2013) 20130502121106A</guid></item><item><title>Released: Automation Scripts (May 01, 2013)</title><link>http://msecdbg.codeplex.com/releases/view/106022</link><description>
&lt;div class="wikidoc"&gt;&lt;b&gt;Classify&lt;/b&gt; - A batch file used to sport crash dumps based on !exploitable output.&lt;br&gt;
&lt;b&gt;DebugWrapper&lt;/b&gt; - A batch file used to debug an application. If a crash occurs it is evaluated by !exploitable and a crash dump is saved and sorted.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Thu, 02 May 2013 00:11:06 GMT</pubDate><guid isPermaLink="false">Released: Automation Scripts (May 01, 2013) 20130502121106A</guid></item><item><title>Updated Release: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009)</title><link>http://msecdbg.codeplex.com/releases/view/28935</link><description>&lt;div class="wikidoc"&gt;New MSECExtensions bits, changelog below:&lt;br /&gt;&lt;br /&gt;1.0.1 Updates:&lt;br /&gt;&lt;br /&gt;A bug that resulted in overtainting H or L registers has been fixed.&lt;br /&gt;Initial External Release: March, 2009&lt;br /&gt;&lt;br /&gt;1.0.2 Updates:&lt;br /&gt;&lt;br /&gt;When loading user mode mini-dumps, the Gather rule now correctly sets the stack context.&lt;br /&gt;&lt;br /&gt;1.0.3 Updates:&lt;br /&gt;&lt;br /&gt;New state and gather functionality and analyze rules to identify exceptions where the faulting address is on the stack.&lt;br /&gt;Hashes are fixed at 32 bit display (8 hex characters) and code locations are fixed at 64 bit display (16 hex characters).&lt;br /&gt;Added support for the REP SCAS instruction in the disassembler&lt;br /&gt;Fixed a serious bug in the wildcard match function, which would result in anything that matched up to the first wildcard matching the entire string&lt;br /&gt;Fixed a bug in which the destination pointer registers were not being set to the tainted value set for Write AVs that required taint analysis&lt;br /&gt;Fixed bugs in the distinction between source and data registers for taint tracking in some rep instructions&lt;br /&gt;&lt;br /&gt;1.0.4 Updates:&lt;br /&gt;&lt;br /&gt;Fixed a reporting and analysis bug, in which we change the faulting instruction as well as the invoking function when we skip excluded stack frames&lt;br /&gt;&lt;br /&gt;1.0.5 Updates:&lt;br /&gt;&lt;br /&gt;Updates to the excluded symbols list&lt;br /&gt;Handle POP instructions that pop to memory&lt;br /&gt;Handle PUSH instructions that push to memory&lt;br /&gt;Treat POP instructions to memory the same as MOV instructions to memory&lt;br /&gt;&lt;br /&gt;1.0.6 Updates:&lt;br /&gt;&lt;br /&gt;External Release: June, 2009&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>AndyRenk</author><pubDate>Thu, 13 Dec 2012 02:41:16 GMT</pubDate><guid isPermaLink="false">Updated Release: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009) 20121213024116A</guid></item><item><title>Released: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009)</title><link>http://msecdbg.codeplex.com/releases/view/28935</link><description>
&lt;div class="wikidoc"&gt;New MSECExtensions bits, changelog below:&lt;br&gt;
&lt;br&gt;
1.0.1 Updates:&lt;br&gt;
&lt;br&gt;
A bug that resulted in overtainting H or L registers has been fixed.&lt;br&gt;
Initial External Release: March, 2009&lt;br&gt;
&lt;br&gt;
1.0.2 Updates:&lt;br&gt;
&lt;br&gt;
When loading user mode mini-dumps, the Gather rule now correctly sets the stack context.&lt;br&gt;
&lt;br&gt;
1.0.3 Updates:&lt;br&gt;
&lt;br&gt;
New state and gather functionality and analyze rules to identify exceptions where the faulting address is on the stack.&lt;br&gt;
Hashes are fixed at 32 bit display (8 hex characters) and code locations are fixed at 64 bit display (16 hex characters).&lt;br&gt;
Added support for the REP SCAS instruction in the disassembler&lt;br&gt;
Fixed a serious bug in the wildcard match function, which would result in anything that matched up to the first wildcard matching the entire string&lt;br&gt;
Fixed a bug in which the destination pointer registers were not being set to the tainted value set for Write AVs that required taint analysis&lt;br&gt;
Fixed bugs in the distinction between source and data registers for taint tracking in some rep instructions&lt;br&gt;
&lt;br&gt;
1.0.4 Updates:&lt;br&gt;
&lt;br&gt;
Fixed a reporting and analysis bug, in which we change the faulting instruction as well as the invoking function when we skip excluded stack frames&lt;br&gt;
&lt;br&gt;
1.0.5 Updates:&lt;br&gt;
&lt;br&gt;
Updates to the excluded symbols list&lt;br&gt;
Handle POP instructions that pop to memory&lt;br&gt;
Handle PUSH instructions that push to memory&lt;br&gt;
Treat POP instructions to memory the same as MOV instructions to memory&lt;br&gt;
&lt;br&gt;
1.0.6 Updates:&lt;br&gt;
&lt;br&gt;
External Release: June, 2009&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Thu, 13 Dec 2012 02:41:16 GMT</pubDate><guid isPermaLink="false">Released: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009) 20121213024116A</guid></item><item><title>Updated Release: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009)</title><link>http://msecdbg.codeplex.com/releases/view/28935</link><description>&lt;div class="wikidoc"&gt;New MSECExtensions bits, changelog below:&lt;br /&gt;&lt;br /&gt;1.0.1 Updates:&lt;br /&gt;&lt;br /&gt;A bug that resulted in overtainting H or L registers has been fixed.&lt;br /&gt;Initial External Release: March, 2009&lt;br /&gt;&lt;br /&gt;1.0.2 Updates:&lt;br /&gt;&lt;br /&gt;When loading user mode mini-dumps, the Gather rule now correctly sets the stack context.&lt;br /&gt;&lt;br /&gt;1.0.3 Updates:&lt;br /&gt;&lt;br /&gt;New state and gather functionality and analyze rules to identify exceptions where the faulting address is on the stack.&lt;br /&gt;Hashes are fixed at 32 bit display (8 hex characters) and code locations are fixed at 64 bit display (16 hex characters).&lt;br /&gt;Added support for the REP SCAS instruction in the disassembler&lt;br /&gt;Fixed a serious bug in the wildcard match function, which would result in anything that matched up to the first wildcard matching the entire string&lt;br /&gt;Fixed a bug in which the destination pointer registers were not being set to the tainted value set for Write AVs that required taint analysis&lt;br /&gt;Fixed bugs in the distinction between source and data registers for taint tracking in some rep instructions&lt;br /&gt;&lt;br /&gt;1.0.4 Updates:&lt;br /&gt;&lt;br /&gt;Fixed a reporting and analysis bug, in which we change the faulting instruction as well as the invoking function when we skip excluded stack frames&lt;br /&gt;&lt;br /&gt;1.0.5 Updates:&lt;br /&gt;&lt;br /&gt;Updates to the excluded symbols list&lt;br /&gt;Handle POP instructions that pop to memory&lt;br /&gt;Handle PUSH instructions that push to memory&lt;br /&gt;Treat POP instructions to memory the same as MOV instructions to memory&lt;br /&gt;&lt;br /&gt;1.0.6 Updates:&lt;br /&gt;&lt;br /&gt;External Release: June, 2009&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>jasoshi</author><pubDate>Fri, 13 Aug 2010 00:30:11 GMT</pubDate><guid isPermaLink="false">Updated Release: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009) 20100813123011A</guid></item><item><title>Released: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009)</title><link>http://msecdbg.codeplex.com/releases/view/28935</link><description>&lt;div class=wikidoc&gt;New MSECExtensions bits, changelog below:&lt;br&gt;&lt;br&gt;1.0.1 Updates:&lt;br&gt;&lt;br&gt;A bug that resulted in overtainting H or L registers has been fixed.&lt;br&gt;Initial External Release: March, 2009&lt;br&gt;&lt;br&gt;1.0.2 Updates:&lt;br&gt;&lt;br&gt;When loading user mode mini-dumps, the Gather rule now correctly sets the stack context.&lt;br&gt;&lt;br&gt;1.0.3 Updates:&lt;br&gt;&lt;br&gt;New state and gather functionality and analyze rules to identify exceptions where the faulting address is on the stack.&lt;br&gt;Hashes are fixed at 32 bit display (8 hex characters) and code locations are fixed at 64 bit display (16 hex characters).&lt;br&gt;Added support for the REP SCAS instruction in the disassembler&lt;br&gt;Fixed a serious bug in the wildcard match function, which would result in anything that matched up to the first wildcard matching the entire string&lt;br&gt;Fixed a bug in which the destination pointer registers were not being set to the tainted value set for Write AVs that required taint analysis&lt;br&gt;Fixed bugs in the distinction between source and data registers for taint tracking in some rep instructions&lt;br&gt;&lt;br&gt;1.0.4 Updates:&lt;br&gt;&lt;br&gt;Fixed a reporting and analysis bug, in which we change the faulting instruction as well as the invoking function when we skip excluded stack frames&lt;br&gt;&lt;br&gt;1.0.5 Updates:&lt;br&gt;&lt;br&gt;Updates to the excluded symbols list&lt;br&gt;Handle POP instructions that pop to memory&lt;br&gt;Handle PUSH instructions that push to memory&lt;br&gt;Treat POP instructions to memory the same as MOV instructions to memory&lt;br&gt;&lt;br&gt;1.0.6 Updates:&lt;br&gt;&lt;br&gt;External Release: June, 2009&lt;/div&gt;&lt;div&gt;&lt;/div&gt;</description><author></author><pubDate>Fri, 13 Aug 2010 00:30:11 GMT</pubDate><guid isPermaLink="false">Released: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009) 20100813123011A</guid></item><item><title>Updated Release: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009)</title><link>http://msecdbg.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=28935</link><description>&lt;div&gt;New MSECExtensions bits, changelog below:&lt;br&gt;&lt;br&gt;1.0.1 Updates:&lt;br&gt;&lt;br&gt;A bug that resulted in overtainting H or L registers has been fixed.&lt;br&gt;Initial External Release: March, 2009&lt;br&gt;&lt;br&gt;1.0.2 Updates:&lt;br&gt;&lt;br&gt;When loading user mode mini-dumps, the Gather rule now correctly sets the stack context.&lt;br&gt;&lt;br&gt;1.0.3 Updates:&lt;br&gt;&lt;br&gt;New state and gather functionality and analyze rules to identify exceptions where the faulting address is on the stack.&lt;br&gt;Hashes are fixed at 32 bit display (8 hex characters) and code locations are fixed at 64 bit display (16 hex characters).&lt;br&gt;Added support for the REP SCAS instruction in the disassembler&lt;br&gt;Fixed a serious bug in the wildcard match function, which would result in anything that matched up to the first wildcard matching the entire string&lt;br&gt;Fixed a bug in which the destination pointer registers were not being set to the tainted value set for Write AVs that required taint analysis&lt;br&gt;Fixed bugs in the distinction between source and data registers for taint tracking in some rep instructions&lt;br&gt;&lt;br&gt;1.0.4 Updates:&lt;br&gt;&lt;br&gt;Fixed a reporting and analysis bug, in which we change the faulting instruction as well as the invoking function when we skip excluded stack frames&lt;br&gt;&lt;br&gt;1.0.5 Updates:&lt;br&gt;&lt;br&gt;Updates to the excluded symbols list&lt;br&gt;Handle POP instructions that pop to memory&lt;br&gt;Handle PUSH instructions that push to memory&lt;br&gt;Treat POP instructions to memory the same as MOV instructions to memory&lt;br&gt;&lt;br&gt;1.0.6 Updates:&lt;br&gt;&lt;br&gt;External Release: June, 2009&lt;/div&gt;</description><author>jasoshi</author><pubDate>Wed, 17 Jun 2009 19:11:35 GMT</pubDate><guid isPermaLink="false">Updated Release: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009) 20090617071135P</guid></item><item><title>Released: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009)</title><link>http://msecdbg.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=28935</link><description>&lt;div&gt;New MSECExtensions bits, changelog below:&lt;br&gt;&lt;br&gt;1.0.1 Updates:&lt;br&gt;&lt;br&gt;A bug that resulted in overtainting H or L registers has been fixed.&lt;br&gt;Initial External Release: March, 2009&lt;br&gt;&lt;br&gt;1.0.2 Updates:&lt;br&gt;&lt;br&gt;When loading user mode mini-dumps, the Gather rule now correctly sets the stack context.&lt;br&gt;&lt;br&gt;1.0.3 Updates:&lt;br&gt;&lt;br&gt;New state and gather functionality and analyze rules to identify exceptions where the faulting address is on the stack.&lt;br&gt;Hashes are fixed at 32 bit display (8 hex characters) and code locations are fixed at 64 bit display (16 hex characters).&lt;br&gt;Added support for the REP SCAS instruction in the disassembler&lt;br&gt;Fixed a serious bug in the wildcard match function, which would result in anything that matched up to the first wildcard matching the entire string&lt;br&gt;Fixed a bug in which the destination pointer registers were not being set to the tainted value set for Write AVs that required taint analysis&lt;br&gt;Fixed bugs in the distinction between source and data registers for taint tracking in some rep instructions&lt;br&gt;&lt;br&gt;1.0.4 Updates:&lt;br&gt;&lt;br&gt;Fixed a reporting and analysis bug, in which we change the faulting instruction as well as the invoking function when we skip excluded stack frames&lt;br&gt;&lt;br&gt;1.0.5 Updates:&lt;br&gt;&lt;br&gt;Updates to the excluded symbols list&lt;br&gt;Handle POP instructions that pop to memory&lt;br&gt;Handle PUSH instructions that push to memory&lt;br&gt;Treat POP instructions to memory the same as MOV instructions to memory&lt;br&gt;&lt;br&gt;1.0.6 Updates:&lt;br&gt;&lt;br&gt;External Release: June, 2009&lt;/div&gt;</description><author></author><pubDate>Wed, 17 Jun 2009 19:11:35 GMT</pubDate><guid isPermaLink="false">Released: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009) 20090617071135P</guid></item><item><title>Created Release: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009)</title><link>http://msecdbg.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=28935</link><description>&lt;div&gt;New MSECExtensions bits, changelog below:&lt;br&gt;&lt;br&gt;1.0.1 Updates:&lt;br&gt;&lt;br&gt;A bug that resulted in overtainting H or L registers has been fixed.&lt;br&gt;Initial External Release: March, 2009&lt;br&gt;&lt;br&gt;1.0.2 Updates:&lt;br&gt;&lt;br&gt;When loading user mode mini-dumps, the Gather rule now correctly sets the stack context.&lt;br&gt;&lt;br&gt;1.0.3 Updates:&lt;br&gt;&lt;br&gt;New state and gather functionality and analyze rules to identify exceptions where the faulting address is on the stack.&lt;br&gt;Hashes are fixed at 32 bit display (8 hex characters) and code locations are fixed at 64 bit display (16 hex characters).&lt;br&gt;Added support for the REP SCAS instruction in the disassembler&lt;br&gt;Fixed a serious bug in the wildcard match function, which would result in anything that matched up to the first wildcard matching the entire string&lt;br&gt;Fixed a bug in which the destination pointer registers were not being set to the tainted value set for Write AVs that required taint analysis&lt;br&gt;Fixed bugs in the distinction between source and data registers for taint tracking in some rep instructions&lt;br&gt;&lt;br&gt;1.0.4 Updates:&lt;br&gt;&lt;br&gt;Fixed a reporting and analysis bug, in which we change the faulting instruction as well as the invoking function when we skip excluded stack frames&lt;br&gt;&lt;br&gt;1.0.5 Updates:&lt;br&gt;&lt;br&gt;Updates to the excluded symbols list&lt;br&gt;Handle POP instructions that pop to memory&lt;br&gt;Handle PUSH instructions that push to memory&lt;br&gt;Treat POP instructions to memory the same as MOV instructions to memory&lt;br&gt;&lt;br&gt;1.0.6 Updates:&lt;br&gt;&lt;br&gt;External Release: June, 2009&lt;/div&gt;</description><author>jasoshi</author><pubDate>Wed, 17 Jun 2009 19:11:14 GMT</pubDate><guid isPermaLink="false">Created Release: MSEC Debugger Extensions v1.0.6 (Jun 17, 2009) 20090617071114P</guid></item><item><title>Updated Release: MSEC.dll BETA v1.0.1.0 Source and Bins x86 x64 (Mar 20, 2009)</title><link>http://msecdbg.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=24667</link><description>&lt;div&gt;
&lt;h1&gt;
Requirements:
&lt;/h1&gt;	Windows Debugger (windbg.exe)&lt;br&gt; &lt;br&gt;&lt;h1&gt;
Installation Instructions :
&lt;/h1&gt;	Copy the correct version (x86 or x64) to your Windows Debugger winext sub-directory&lt;br&gt; &lt;br&gt;&lt;h1&gt;
Usage Instructions:
&lt;/h1&gt; &lt;br&gt;	You may need to explicitly load the MSEC DLL. If you installed it to the winext sub-directory, you can load&lt;br&gt;	it with &lt;i&gt;!load winext\msec.dll&lt;/i&gt;&lt;br&gt; &lt;br&gt;{preserving formatting&lt;br&gt; &lt;br&gt;	!exploitable&lt;br&gt;	Gives an analysis, including a proposed bug title&lt;br&gt; &lt;br&gt;	!exploitable -v&lt;br&gt;	Gives a verbose analysis&lt;br&gt; &lt;br&gt;	!exploitable -m&lt;br&gt;	Gives the same output as -v, but formatted for easy machine parsing	&lt;br&gt;	&lt;br&gt;	!exploitable -jit:address&lt;br&gt;	Use the JIT Exception Record to determine the exception&lt;br&gt;	&lt;br&gt;	!ror [-n &amp;lt;Rotation Count&amp;gt; [-c] &amp;lt;Value&amp;gt;&lt;br&gt;	Get the API name for hash value &amp;lt;Value&amp;gt; using rotation count &amp;lt;Rotation Count&amp;gt;. Use -c to do a reverse lookup from an API name to a hash value. Run !ror without options for examples.&lt;br&gt; &lt;br&gt; &lt;br&gt;	!xoru &lt;a href="http://msecdbg.codeplex.com/Wiki/View.aspx?title=-b"&gt;-b&lt;/a&gt; &amp;lt;addr&amp;gt; &lt;a href="http://msecdbg.codeplex.com/Wiki/View.aspx?title=&amp;lt;length&amp;gt;"&gt;&amp;lt;length&amp;gt;&lt;/a&gt; &amp;lt;key&amp;gt;&lt;br&gt;	Do the Xor transformation on the buffer from address &amp;lt;addr&amp;gt; to address &amp;lt;addr&amp;gt; + &amp;lt;length&amp;gt; using the key &amp;lt;key&amp;gt; and disassemble the buffer. Use -b to leave the transformed buffer in memory. Run !xoru without options for examples. You can do other types of transformation using xora, xorui, xorua, suba, subu, adda, addu, rola, or rolu.}&lt;br&gt; &lt;br&gt;End of format preservation}&lt;br&gt; &lt;br&gt;&lt;h1&gt;
Known Issues:
&lt;/h1&gt; &lt;br&gt;	!exploitable&lt;br&gt;	&lt;br&gt;		The instruction set is known to be incomplete. 	&lt;br&gt;		&lt;br&gt;		KERNEL&lt;i&gt;MODE&lt;/i&gt;EXCEPTION&lt;i&gt;NOT&lt;/i&gt;HANDLED / KERNEL&lt;i&gt;MODE&lt;/i&gt;EXCEPTION&lt;i&gt;NOT&lt;/i&gt;HANDLED_M does not currently differentiate between read and write access violations.&lt;br&gt;
&lt;/div&gt;</description><author>jasoshi</author><pubDate>Fri, 20 Mar 2009 08:00:18 GMT</pubDate><guid isPermaLink="false">Updated Release: MSEC.dll BETA v1.0.1.0 Source and Bins x86 x64 (Mar 20, 2009) 20090320080018A</guid></item><item><title>Released: MSEC.dll BETA v1.0.1.0 Source and Bins x86 x64 (Mar 20, 2009)</title><link>http://msecdbg.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=24667</link><description>&lt;div&gt;
&lt;h1&gt;
Requirements:
&lt;/h1&gt;	Windows Debugger (windbg.exe)&lt;br&gt; &lt;br&gt;&lt;h1&gt;
Installation Instructions :
&lt;/h1&gt;	Copy the correct version (x86 or x64) to your Windows Debugger winext sub-directory&lt;br&gt; &lt;br&gt;&lt;h1&gt;
Usage Instructions:
&lt;/h1&gt; &lt;br&gt;	You may need to explicitly load the MSEC DLL. If you installed it to the winext sub-directory, you can load&lt;br&gt;	it with &lt;i&gt;!load winext\msec.dll&lt;/i&gt;&lt;br&gt; &lt;br&gt;{preserving formatting&lt;br&gt; &lt;br&gt;	!exploitable&lt;br&gt;	Gives an analysis, including a proposed bug title&lt;br&gt; &lt;br&gt;	!exploitable -v&lt;br&gt;	Gives a verbose analysis&lt;br&gt; &lt;br&gt;	!exploitable -m&lt;br&gt;	Gives the same output as -v, but formatted for easy machine parsing	&lt;br&gt;	&lt;br&gt;	!exploitable -jit:address&lt;br&gt;	Use the JIT Exception Record to determine the exception&lt;br&gt;	&lt;br&gt;	!ror [-n &amp;lt;Rotation Count&amp;gt; [-c] &amp;lt;Value&amp;gt;&lt;br&gt;	Get the API name for hash value &amp;lt;Value&amp;gt; using rotation count &amp;lt;Rotation Count&amp;gt;. Use -c to do a reverse lookup from an API name to a hash value. Run !ror without options for examples.&lt;br&gt; &lt;br&gt; &lt;br&gt;	!xoru &lt;a href="http://msecdbg.codeplex.com/Wiki/View.aspx?title=-b"&gt;-b&lt;/a&gt; &amp;lt;addr&amp;gt; &lt;a href="http://msecdbg.codeplex.com/Wiki/View.aspx?title=&amp;lt;length&amp;gt;"&gt;&amp;lt;length&amp;gt;&lt;/a&gt; &amp;lt;key&amp;gt;&lt;br&gt;	Do the Xor transformation on the buffer from address &amp;lt;addr&amp;gt; to address &amp;lt;addr&amp;gt; + &amp;lt;length&amp;gt; using the key &amp;lt;key&amp;gt; and disassemble the buffer. Use -b to leave the transformed buffer in memory. Run !xoru without options for examples. You can do other types of transformation using xora, xorui, xorua, suba, subu, adda, addu, rola, or rolu.}&lt;br&gt; &lt;br&gt;End of format preservation}&lt;br&gt; &lt;br&gt;&lt;h1&gt;
Known Issues:
&lt;/h1&gt; &lt;br&gt;	!exploitable&lt;br&gt;	&lt;br&gt;		The instruction set is known to be incomplete. 	&lt;br&gt;		&lt;br&gt;		KERNEL&lt;i&gt;MODE&lt;/i&gt;EXCEPTION&lt;i&gt;NOT&lt;/i&gt;HANDLED / KERNEL&lt;i&gt;MODE&lt;/i&gt;EXCEPTION&lt;i&gt;NOT&lt;/i&gt;HANDLED_M does not currently differentiate between read and write access violations.&lt;br&gt;
&lt;/div&gt;</description><author></author><pubDate>Fri, 20 Mar 2009 08:00:18 GMT</pubDate><guid isPermaLink="false">Released: MSEC.dll BETA v1.0.1.0 Source and Bins x86 x64 (Mar 20, 2009) 20090320080018A</guid></item></channel></rss>