anti debugging

ANTI|DEBUGGING By Adwiteeya Agrawal

Post on 21-Oct-2014




3 download


null Delhi Chapter - August 2013 Meet


Page 1: Anti Debugging



Adwiteeya Agrawal

Page 2: Anti Debugging


• Definition

“Software reverse engineering is about opening up a

program’s “box,” and looking inside. “

Page 3: Anti Debugging







Page 4: Anti Debugging

Example : Code Written

Ideally , the else block should never be executed since the value of var1 is not changed.

Page 5: Anti Debugging

After Disassembling

We can easily modify the binary to execute the else loop.

Page 6: Anti Debugging

Problem ?

• A Google search for “Crack Torrent” returns 200 million results and “Software Crack” around 45M.

• Reversing is extensively used to develop cracks for proprietary software.

Page 7: Anti Debugging

Possible Solutions

• Anti-Debugging (Detecting how a process is different from when it is being debbugged and when its run.)

• Code Obfuscation(Encryption, pseudo execution flow, logic)

• However : The end result after exploring the various options available is that we cannot totally prevent software reverse engineering however we can slow down the process for a dedicated reverse engineer.

Page 8: Anti Debugging

Anti - Debugging

• Anti Debugging is done acknowledging the fact that when a process is being debugged it is going to have a set of properties that would be different from when it is not debugged.

• Anti-debugging requires a thorough understanding of the environment in which the program would be run.

Page 9: Anti Debugging

Does Anti - Debugging help ?

Example : CCleaner

Software Vendors

Software Crackers

Malware Analysts

Page 10: Anti Debugging


API Based Detection


Direct structure access

Exception Handling

Based Detection

Page 11: Anti Debugging

API Based Anti|Debugging

(11 Techniques)

Page 12: Anti Debugging

1.FindWindow API

• Scans memory for a process with the particular class name.

{ hnd = FindWindow("OLLYDBG", 0); }

• “OLLYDBG” is the class name for all windows that would be created and

have the same callback function.

• “0” scans irrespective of WindowName.

• Returns a handle if successful

• Spy++ utility can be used to enumerate the ClassName.

• DEMO - spy++

Page 13: Anti Debugging

Spy++ on OllyDbg

Page 14: Anti Debugging

2. Registry Value

• RegOpenKeyEx and RegQueryValueEx open a registry key and retrieve its value respectively

KEY Function

HKEY_CLASSES_ROOT\exefile\shell\Open with OllyDbg

Specifies the menu for

opening an exe file with

OllyDbg with a right click

HKEY_CLASSES_ROOT\exefile\shell\Open with


Path to OllyDbg

HKEY_CLASSES_ROOT\dllfile\shell\Open with OllyDbg

Specifies the menu for

opening a dll file with OllyDbg

with a right click

HKEY_CLASSES_ROOT\dllfile\shell\Open with


Path to OllyDbg


ws NT\CurrentVersion\AeDebug\Debugger

Path to default Debugger

Page 15: Anti Debugging

3. IsDebuggerPresent API

• Looks for the BeingDebugged flag inside the PEB. • Extremely simple to use and thwart.

• { IsDebuggerPresent() } returns true if the process is being

debugged false otherwise.

• Can be done manually

• Assembly dump :

Page 16: Anti Debugging

4. CheckRemoteDebuggerPresent API

• Function : Detects if a Debug Port has been set. • Can be used for a “remote” process but is used locally mostly. • Locally :


• Remotely for a PID 2800 { hndle=OpenProcess(PROCESS_ALL_ACCESS, FALSE, 2800);

CheckRemoteDebuggerPresent(hndle,&pblsPresent); }

Page 17: Anti Debugging

5.OutputDebugString API

Set Random Value for ERROR

Call OutputDebugString with any string

Check Value Of ERROR

If(No Change) : Debugger Present

Else : No Debugger

Works in XP.

Page 18: Anti Debugging

Debug String Display in OllyDbg

Page 19: Anti Debugging

Run Time Dynamic Linking

LoadLibrary Handle to dll

received GetProcAddress

Address of exported function


Example : ntdll.dll

Ex : NTSetInformationThread, NTQueryInformationProcess

Page 20: Anti Debugging

6. ZwSetInformationThread Function • Use run-time dynamic linking to get the address of


• Make the Call

• (_ZwSetInformationThread)(GetCurrentThread(),0×11,0,0);

• GetCurrentThread : Pseudo handle for the current thread

• 0x11 : ThreadHideFromDebugger , 17 in THREADINFOCLASS enum.

• 0 : Pointer of value that is to be set

• 0 : Size of the value.

• Different Approached followed.

Page 21: Anti Debugging

7. DebugActiveProcess based Self Debugging

• Theoretically a process can be debugged only by One Debugger.

• Working :

Create a child process

Child Process attempts to

debug parent

If Error : Debugger Detected

Page 22: Anti Debugging

8. OllyDbg Format String Vulnerability for Debugger Messages

• More like a vulnerability based detection

• The internal function that handles the input from OutputDebugString does so without using the correct number of format specifiers, allowing a user to supply their own format specifiers.

• OutputDebugString(TEXT("%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s"));

• Similar vulnerability based detection can be modeled around various vulnerabilities, Reference :

Page 23: Anti Debugging

9. NTQueryInformationProcess to detect ProcessDebugPort

• Run-time dynamic linking to get the pointer to NTqueryInformationProcess

• Make the call with PROCESSINFOCLASS = 0x07

• NTSTATUS WINAPI NtQueryInformationProcess( _In_ HANDLE ProcessHandle, _In_ PROCESSINFOCLASS ProcessInformationClass, _Out_ PVOID ProcessInformation, _In_ ULONG ProcessInformationLength, _Out_opt_ PULONG ReturnLength );

• The 0x07 value is the process debug port.

• Debug Port is used for communication of Debug_Event between ring 3 and the kernel

• If set the process is being debugged.

Page 24: Anti Debugging

• private enum PROCESSINFOCLASS: int { ProcessBasicInformation ProcessQuotaLimits, ProcessIoCounters ProcessVmCounters, ProcessTimes, ProcessBasePriority, ProcessRaisePriority, ProcessDebugPort, ProcessExceptionPort ProcessAccessToken, ProcessLdtInformation, ProcessLdtSize, . . . ProcessDefaultHardErrorMode, ProcessIoPortHandlers, ProcessPooledUsageAndLimits, ProcessWorkingSetWatch, ProcessDynamicFunctionTableInformation, ProcessHandleCheckingMode, ProcessKeepAliveCount, ProcessRevokeFileHandles, MaxProcessInfoClass };

Page 25: Anti Debugging

10. ProcessDebugFlags using NTQueryInformationProcess

11. ProcessDebugObject using NTQueryInformationProcess

•Run-time Dynamic Linking to get address of NTQuertInformationProcess Function. •Make the call with PROCESSINFOCLASS 0x1F. •If Set Debugger is present.

•Run-time dynamic linking to get the address •Call with PROCESSINFOCLASS 0x1E •If set debugger is present

Page 26: Anti Debugging

• private enum PROCESSINFOCLASS: int { ProcessBasicInformation ProcessQuotaLimits, ProcessIoCounters ProcessVmCounters, ProcessTimes, ProcessBasePriority, ProcessRaisePriority, . . . ProcessAffinityMask, ProcessPriorityBoost, ProcessDeviceMap, ProcessSessionInformation, ProcessForegroundInformation, ProcessWow64Information, ProcessImageFileName, ProcessLUIDDeviceMapsEnabled, ProcessBreakOnTermination, ProcessDebugObjectHandle, ProcessDebugFlags, ProcessHandleTracing, ProcessIoPriority, ProcessExecuteFlags, ProcessResourceManagement, . .

. ProcessRevokeFileHandles, MaxProcessInfoClass };

Page 27: Anti Debugging

Exception Based Anti|Debugging

(9 Techniques)

Page 28: Anti Debugging

Exceptions | Windows

First Chance



Last Chance




SEH • SEH, per thread, FS:0

LC • Process Suspend


• UnhandledExceptionFilter

• System Final Handler

Page 29: Anti Debugging

Exception Handlers

typedef struct _EXCEPTION_RECORD { DWORD ExceptionCode; DWORD ExceptionFlags; struct _EXCEPTION_RECORD* ExceptionRecord; PVOID ExceptionAddress; DWORD NumberParameters; ULONG_PTR ExceptionInformation[EXCEPTION_MAXIMUM_PARAMETERS]; } EXCEPTION_RECORD, *PEXCEPTION_RECORD;


LONG CALLBACK ExceptionHandler( __in PEXCEPTION_POINTERS ExceptionInformation);

Page 30: Anti Debugging

1. INT 3 Break Point Exception.

• The INT 3 instruction generates a special one byte opcode (CC) that is intended for calling the debug exception handler.

• To set INT3 breakpoint, a debugger replaces first byte of the 80x86 command by 0xCC

• Type : EXCEPTION_BREAKPOINT to the Debugger

• When manually inlined then the process would just halt at the next instruction if run in a Debugger(thereby not triggering your catch block) or return 0x80000003 status code if run without a debugger.

Page 31: Anti Debugging

2. INT 2D Exception

• Int 2Dh is used by ntoskrnl.exe to interact with kernel debugging system but we can use it also in user-mode or from ring 3 as well since the call will eventually filter to a ring 3 debugger if no kernel debugger exists.

• When int 2Dh is called the system will skip one byte after the interrupt, leading to opcode scission.

• Behaves exactly like int 3

• Based on weather our catch block is executed or not we declare presence of a debugger.

Page 32: Anti Debugging

3. 0xF1 ICE Break Point

• This is identical to the functioning of 0xcc except the fact the this uses two bytes 0xCD 0x3C to insert the breakpoint.

4. TWO byte INT 3 breakpoint.

•One of the Intel's undocumented instruction, opcode 0xF1. •Executing this instruction will generate a SINGLE_STEP exception. •The debugger will think it is the normal exception generated by executing the instruction with the SingleStep bit set in the Flags registers.

Page 33: Anti Debugging

5. Close Handle API call

• The CloseHandle function throws an exception, if an invalid handle is provided.

• The logic behind detection with Close Handle function is the opposite to the ones used in INT3 or INT 2D exception based debugger detection.

• Exception is only thrown when in a debugger

• Usually in debugging sessions it is a common practice that the exception is passed to the application

Page 34: Anti Debugging

6. Trap Flag exception based detection

• The EFLAGS is a 32-bit register used as a collection of bits representing

Boolean values to store the results of operations and the state of the processor.

• By in-lining ASM we can modify the EFLAGS register.

• First bit of the second byte that is TF or the trap flag. If this flag is set the execution halts after executing the current instruction.

• Also called as the single step exception

Page 35: Anti Debugging

EGLAGS Register

Page 36: Anti Debugging

7. Memory breakpoint based detection

• If a memory breakpoint is set up, any access to the page in which the breakpoint exists, would result in the exception and the process would halt.

Allocate some 5mb

Fill with RET

Make it a GUARD PAGE Pointer to the PAGE

Call the Pointer

Detect Error

Page 37: Anti Debugging


VirtualAlloc(NULL, 0x500000, MEM_COMMIT, PAGE_READWRITE);

RtlFillMemory(memRegion, 0x10, 0xC3);

VirtualProtect(memRegion, 0x10, PAGE_EXECUTE_READ | PAGE_GUARD,


myproc = (FARPROC) memRegion


Detect Error


Page 38: Anti Debugging

Hack that ?

Page 39: Anti Debugging

8. Control C VEH

• If a console process is being debugged for a CTRL+C signals, the system generates a DBG_CONTROL_C exception.

• If a debugger is not present CTRL+C event would require a console control handler.

• The CCH is executed if the debugger is not present.

• However if the debugger is present and it passes the exception to the application we can still detect it by adding a vectored exception handler. ;)

Page 40: Anti Debugging

9. INVALID OPCODE exception based debugging

• Invalid OPCODE can be formed by manually editing bytes.

• F0 0F C7 C8 popularly known as the "Pentium F00F bug.“

• This evaluates to LOCK CMPXCHNG8B EAX

• OPCODE since a LOCK on CMPXCHNG8B cannot be applied with the destination operand as a register

• Now, before this OPCODE is executed an exception is created ILLEGAL_INSTRUCTION (C000001D)

• we define an UnhandledExceptionFilter ,only executed when the program

is not being debugged. So even if the debugger passes the exception to the application there isnt any handler. ;)

Page 41: Anti Debugging

Direct Structure Access Based Anti|Debugging

(4 Techniques)

Page 42: Anti Debugging

Direct isDebuggerPressent via PEB

• In this method we manually do what the isdebuggerpresent function call does.

• Run-Time Dynamic Linking to call NTQueryInformationProcess with PROCESSINFOCLASS set to ProcessBasicInformation = 0.

• typedef struct _PROCESS_BASIC_INFORMATION { PVOID Reserved1; PPEB PebBaseAddress; PVOID Reserved2[2]; ULONG_PTR UniqueProcessId; PVOID Reserved3; } PROCESS_BASIC_INFORMATION;

• Access ProcessExecutionBlock via PPEB (pointer) to check BeingDebbugedFlag.

Page 43: Anti Debugging

PEB |Structure

typedef struct _PEB { BYTE Reserved1[2]; BYTE BeingDebugged; BYTE Reserved2[1]; PVOID Reserved3[2]; PPEB_LDR_DATA Ldr; PRTL_USER_PROCESS_PARAMETERS ProcessParameters; BYTE Reserved4[104]; PVOID Reserved5[52]; PVOID Reserved8[312]; BYTE Reserved6[128]; PVOID Reserved7[1]; ULONG SessionId; } PEB, *PPEB; pPIB.PebBaseAddress->BeingDebugged

Page 44: Anti Debugging

ProcessHeapFlag Debugger Detection

Heap Header User Allocation

Heap Header User Allocation Tail Checking Pattern Heap Extra

Multiple of 16 bytes 16 bytes

16 bytes Multiple of 16 bytes 16 bytes 16–31 bytes



{ HEAP }

{ /HEAP }

•In order to tell this to the OS before creating the HEAP two flags are set. “Flags” and “ForceFlags” •Present at the offset 0x14 and 0x18 for windows XP. •PEBbase address + Offset to HEAPbaseAddress + Flag offset.

Page 45: Anti Debugging

typedef struct _HEAP { HEAP_ENTRY Entry; ULONG SegmentSignature; ULONG SegmentFlags; LIST_ENTRY SegmentListEntry; PHEAP Heap; . . . ULONG NumberOfUnCommittedPages; ULONG NumberOfUnCommittedRanges; WORD SegmentAllocatorBackTraceIndex; WORD Reserved; LIST_ENTRY UCRSegmentList; ULONG Flags; ULONG ForceFlags; ULONG CompatibilityFlags; ULONG EncodeFlagMask; HEAP_ENTRY Encoding; . . HEAP_COUNTERS Counters; HEAP_TUNING_PARAMETERS TuningParameters; } HEAP, *PHEAP;

Page 46: Anti Debugging

NTGlobalFlag Debugger Detection

• NTGlobalFlag is a DWORD value present at the offset 0x68 from the PEB base address.

• When inside a debugger the following flags are set by the operating system : FLG_HEAP_ENABLE_TAIL_CHECK (0x10) FLG_HEAP_ENABLE_FREE_CHECK(0x20) FLG_HEAP_VALIDATE_PARAMETERS(0x40)

• This equals to 0x70. We detect the value by the similar method and judge if a debugger is present or not.

Page 47: Anti Debugging

and many more…

• Quick Discussion on minor.

• And MOST importantly if I have reached this slide :D