UGDebug Beta 2
----------------

table of contents
I.   Introduction
II.  Hotkeys and commands
III. SDK
IV.  License
V.   Feedback
VI.  Known Problems/Limitations


I. Introduction
---------------

UGDebug is mostly a fun project. bleh :)




II. Hotkeys and commands:
-------------------------

    Hotkey:                 Functionality:
    -------                 --------------

    ------------- debugging --------------------------------------------
    F2                              - break / reenable debugger
    F5                              - go / run target
    F7                              - pass exception to debugee (DON'T PRESS THIS BUTTON UNLESS YOU KNOW WHAT YOU ARE DOING!)
    F8                              - trace into
    F10                             - step over
    F12                             - pret                         (press ESC while PRET is active to stop)
    ESC                             - terminate debugger

    MOUSE BUTTON 1 OVER DISASSEMBLY - set/clear breakpoint on execution
    BPX [offset|reg[(+,-,*,/)x]]    - set breakpoint on execution
    BPM [offset|reg[...] [r|w|x]    - set breakpoint on read/write/execution
    BC index|*                      - remove breakpoint on execution
    BD index|*                      - disable breakpoint on execution
    BE index|*                      - enable breakpoint on execution
    BL                              - list active breakpoints

    I3HERE [on|off]                 - enable/disable break on int3

    TAB                             - autocomplete command/symbol

    ------------- navigation -------------------------------------------
    MOUSE WHEEL UP/DOWN             - scroll disassembly/data/log  (moving the cursor over any window)

    MOUSE BUTTON 1 OVER DATA        - enable memory editor (enter to exit it)
    CTRL+UP                         - scroll disassembly view up
    CTRL+DOWN                       - scroll disassembly view down

    CTRL+PAGE UP                    - scroll disassembly view up   (fast)
    CTRL+PAGE DOWN                  - scroll disassembly view down (fast)

    ALT+UP                          - scroll data view up
    ALT+DOWN                        - scroll data view down

    ALT+PAGE UP                     - scroll data view up          (fast)
    ALT+PAGE DOWN                   - scroll data view down        (fast)

    ALT+LEFT                        - scroll data view left
    ALT+RIGHT                       - scroll data view right

    SHIFT+UP                        - scroll log view up
    SHIFT+DOWN                      - scroll log view down

    SHIFT+PAGE UP                   - scroll log view up           (fast)
    SHIFT+PAGE DOWN                 - scroll log view down         (fast)

    CTRL+ALT+LEFT                   - move debugger window left
    CTRL+ALT+RIGHT                  - move debugger window right
    CTRL+ALT+UP                     - move debugger window up
    CTRL+ALT+DOWN                   - move debugger window down
    UP                              - repeat last recognized command
    DOWN                            - delete commandline

    ------------- commands ---------------------------------------------
    .                               - disassemble current EIP
    ? [value|reg[[(+,-,*,/)x]]      - display value in HEX/DEZ
    CLS                             - clears the logwindow
    D [offset|reg[(+,-,*,/)x]]      - display memory in data window
    DUMP [offset] [size] [filename] - dump memory to disk
    DUMPPE [filename]               - dump pefile (image_size) to disk
    H                               - show help page
    R [reg]=[offset|reg[(+,-,*,/)x]]- modify/set register
    R fl [flag]                     - modify/set eflags
    RP                              - refresh plugins (reload)
    STEALTH                         - hides the debugger
    SET [variable] [on|off]         - set internal variables on/off
    TRACEX <loweip> <higheip>       - trace till a given eip range is being reached
    U [offset|reg[(+,-,*,/)x]]      - display disassembly of offset
    WHAT [value|reg]                - tries to identify known values
    ZAP                             - zap out int1/3



III. SDK
--------
The SDK sample is included in the PLUGINS directory, please feel free to explore the supplied sample to see how it works. The CommandName is being
stripped from the name of the function u give it...


NOTE: The plugins have a higher priority than the internal commands so if you for example give your function the name UGDbg_Stealth your function will
      be called instead of mine...



    
IV. License
------------
UGDebug is licensed under teh super-UG-license!!


V. Feedback
------------

UGDebug is being developed by ^DAEMON^

In order to improve UGDebug, feedback and ideas are more than
welcome - please drop me a few lines: cdaemon@gmx.net


VI. Known Problems/Limitations
-----------------------------
- The graphical output is done via allegro, which is a quite nice and good but also slow directx wrapper
  (u should run it on a fairly new machine to get a decent speed)
- If you don't have the dbg window active OR you execute the program (f5) it won't accept keystrokes
- I noticed some funny behaviour of the debug registers when SICE is running in the background might be
  only related to v4.3 // nothing i could do about it :) don'T run sice in background! ;D
- Debugging a program which has it's own directx surface might lead to unknown problems (crashes ?!)
- Allegro gives me really one of a headache, for some very odd reason the exit routines seem to be hanging from
  time to time, well there's not anything i could do about that :|



Changelog:
BETA 2:      - added quit dialog
             - fixed int3 parsing
             - tracex added (loop analyzer / rdtsc / different anti-anti-debugging added)
             - int1 allow/disallow added (internal int1 handling)
             - displaymsg has now formatted output
             - set added (atm only BreakOnEHandler)
             - pusher (thx man) was kind enough to translate the sdk sample to delphi
             - some small bug fixes
             - cursor home/end added (thx pusher for pointing that out)
             - key_down delete cmdline
             - plugin refresh added (thx to pusher)
             - more symbol lookup for cmdline (bpx Loa* can be autocompleted) (and again pusher ;)
             - sdk: displaymsg -> upgraded

BETA 1:      - plugin support added

PUB Alpha 13:- exchanged the font
             - improved backwards disassembling
             - some ui code changes // speedhacks
             - wont eat up all the cpu power anymore when debugger is idle
             - multithread handling -> finally! ;>>>>
             - added more symbol code -> bpx/u/d/bpm loadlibrary[[+,-...]X]
             - some fixes
             - cursor handling
             - memory editor

PUB Alpha 12:- added zap command
             - better sice rgb colors
             - adjusted the layout a bit more
             - proper dr7 settings for L0|R(W)0 in SetHwBreakpoint 
             - ESC while PRET to stop it
             - bg highlight for logwindow added
             - fixed HEX/DEC readin from input for bc/bd/be
             - initial bpm support
             - fixed weird "be" bug, for some odd reason the source 
               file must have been reverted to some very old revision
             - fixed some other bpm stuff (disable/enable)
             - fixed R eip when singlestepping over a breakpoint
             - r fl X added
             - read/write for bpm completed
             - reenabling of breakpoints "improved" (f5)
             - added stealth command
             - added f7 -> pass-on exception
             - added f2 -> reenable debugger
             - register change highlight
             - (initial not completed yet) offset (symbol)/ module display 
               in UI for disassembly and data
               
PUB Alpha 11:- source optimizations
             - added a real blinking cursor
             - noticed some little issues regarding the parser - to be fixed ;D
             - fixed some input/output stuff (keyboard copy buffer not empty ?!)
             - added r command
             - added ? command
             - added what command
             - added clear command (clears the logwindow)
             - logwindow stuff improved (fuzzy code)

PUB Alpha 10:- added arrows
             - added PRET via f12
             - fixed double bpx setting via "bpx" cmdline
             - fixed currentdir for loadfile

PUB Alpha 9: - added mouse support
             - fixed "bc" cmd
             - bpx/bc via mouse possible
             - scroll up/down -> disassembly/data/log window

PUB Alpha 8: - "Token analysing" added

PUB Alpha 7: - index list of bp's
             - added bc index|*
             - added bd index|*
             - added be index|*
             - improved symbol lookup (0xe8)
             - changed some keys
             - added fast view for disassembly
             - added autocomplete via tab
             - added display of possible cmds in statusbar
             - added logview handler (very basic atm) fast/slow mode

PUB Alpha 6: - fixed symbol lookup (caused me a fuckin headache)

PUB Alpha 5: - improved backwards disassembly
             - improved command parsing
             - added dump / dumppe

PUB Alpha 4: - fixed random initialized memory
             - fixed debugger logic
             - adjusted all other shits