Comments (6)
I believe the feature you are looking for is part of the "Process Properties"
plugin.
Choose the "Plugins" menu and then select "Process Properties" and then the sub
menu item "Process Properties".
Finally on the "Memory" Tab, there is a "Strings" button. From there you can
select a memory region to list strings found.
As a shortcut, you can use either "Ctrl+P" to bring up the Process Properties
plugin. Or you can use "Ctrl+S" to bring up the "Strings" dialog directly (this
being the most convenient option).
Please feel free to re-open the bug if I misunderstood what you were asking for.
Original comment by evan.teran
on 1 Jun 2014 at 3:14
- Changed state: Invalid
from edb-debugger.
Yup, that's what I was looking for. However, that displays a lot fewer strings
than I can see with the strings command. Is that expected?
Original comment by [email protected]
on 1 Jun 2014 at 4:18
from edb-debugger.
A few things.
1. It does it by region, so it's possible that some of the strings are in
different loaded regions.
2. There is a lower bound of what edb considers to be strings (this is
adjustable in the Preferences dialog).
3. Finally, there may be disagreement on what edb considers to be a character
that is likely a string. If you have some examples of things not found that you
feel should be, please file a bug report for it and I'll get right on it :-).
Original comment by evan.teran
on 1 Jun 2014 at 4:20
from edb-debugger.
I feel like these strings should be found. Here's the binary I'm looking at:
http://captf.com/2013/csaw-quals/exploitation/exploit2-200/exploit2. If you run
strings, you get a couple of useful strings, including "Welcome to CSAW CTF".
These strings don't show up for me in EDB. The only think I get is a path to a
shared library and the program name. Let me know if I'm doing something wrong
or you get other output.
Original comment by [email protected]
on 1 Jun 2014 at 4:33
from edb-debugger.
Hmm, When I open that binary in edb and run strings on the primary code region
(8048000-8049000) I see strings like:
"Welcome to CSAW CTF. Exploitation will be a little harder this year. Insert
your exploit here."
at location: 0x08048cf0.
Original comment by evan.teran
on 1 Jun 2014 at 4:37
from edb-debugger.
Ah, I see. I figured it out. Thanks for the help.
Original comment by [email protected]
on 1 Jun 2014 at 5:12
from edb-debugger.
Related Issues (20)
- Cannot find file: ProcessProperties.pro. HOT 1
- Mysterious hang when starting HOT 2
- make error: unix/linux/DebuggerCore.cpp:86: error: 'PTRACE_EVENT_CLONE' was not declared in this scope HOT 10
- Cannot modify values of cpu registers in register window HOT 3
- Show XMM0-15 and YMM0-15 registers in registers window HOT 13
- Compile error on Ubuntu 12.04 HOT 3
- Stack and heap addresses' lower half is 0000 HOT 7
- "Plugin Directory" in Preferences actually expects edb-debugger main directory HOT 1
- Save Binary HOT 2
- Capstone support? HOT 5
- "Lock stack" not working HOT 1
- Please create an AppData file for edb HOT 2
- Please create an AppData file for edb HOT 2
- failed to open and attach to process please check privileges and try again
- DEFAULT_PLUGIN_PATH shouldn't be stringified by two levels of macro HOT 5
- It will be helpful to show callled program name when step into another program call by main at the top of the menu
- Searchability in plugins in general
- Running a terminal with options HOT 15
- Ambiguous Errors when installing on centos 6.6 HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from edb-debugger.