View Full Version : Blogs Forum
- Recon2008
- Testing debuggers
- Kernel debugging with IDA
- From simple to complex
- Bridge them all
- # IDA-Pro 5.4: old bugs on the new streets (was: to download or to not download)
- # RE course in Tel-Aviv
- Playstation3 / PS3 - Harddisk encryption
- S7 airlines is under attack!
- # simple OllyScript for upx
- # Baghdad - dead alive breakpoints
- # PatchDiff => Hex-Rays => WinDiff: how to analyze patches faster
- Class Informer IDA plug-in
- Windows 7 syscall list
- IDA v5.4 release is not that far away
- Windows 7 kernel structures
- # shell-codes analysis: where is EP?
- x64 SEH & Explorer Suite Update
- # FreeLibrary bug becomes a PE packers bug
- San-Francisco - the place to meet
- # MS VC - challenge for PE packers
- Unpinning Imported .dll's
- # 3 lines C-prog hurts MS VC
- # chilly suspicions of new win32 bug
- Malware: Unpacking Waledac
- # dynamic TLS callbacks instead of SEH
- # IDA-Pro and simple (E)SP hack
- # GetProcessDEPPolicy for XP/XP SP2
- NtSetDebugFilterState as Anti-Dbg Trick
- # TLS callbacks w/o USER32 (part III)
- # TLS callbacks w/o USER32 (part II)
- # another EnableTracing() bug
- how powerful IDA Script might be
- # IDA-Pro EnableTracing() - how not to do
- IDA and TLS callbacks
- # DS/FS is under hardware breakpoints
- # XP/S2K3 fails to process TLS w/o USER32
- blog was moved
- Guidelines to MFC reversing
- IOCTL-Proxy
- Dynamic C++ Proposal
- Command line version of OSR's DeviceTree
- Backdoor.Win32.UltimateDefender Reverse Engineering
- Switch as Binary Search, Part 1
- Switch as Binary Search, Part 0
- Qt Internals & Reversing
- CVE-2006-5758: better late than ever
- Malware and initial stack pointer value
- Shared object injection on linux/unix
- Bagle.W IDB
- Trojan.Zhelatin.pk
- Hotpatching MS08-067
- Analyzing local privilege escalations in win32k
- Exploiting Tomorrow's Internet Today: Penetration testing with IPv6
- Can you find me now? Unlocking the Verizon Wireless xv6800 (HTC Titan) GPS
- VbPython 1.2a
- examples of the syllabuses
- Using dual-mappings to evade automated unpackers
- Interesting Kernel32 Constant
- On Analysis of Client-Server Software Applications
- Analyzing Malicious PDF's
- The Wild World of VoIP
- RE-courses/conferences schedule
- custom gpa spy
- Debugger Detection Via NtSystemDebugControl
- POP SS and Debuggers
- Fighting Oreans' VM (code virtualizer flavour)
- PEiD imports parsing DoS
- Nucleus Framework
- SoftICE and KDExtensions
- IDA2PAT Reloaded
- Black Hat 2008 Wrap-up
- Part 2: Introduction to Optimization
- Part 3: Optimizing and Compiling
- Part 1: Bytecode and IR
- VMProtect, Part 0: Basics
- Inside DeleteFiber() as Anti Debug Trick
- Something different part 3, or not quite different
- Why hooking system services is more difficult (and dangerous) than it looks
- Inside SetUnhandledExceptionFilter
- Small Devices & RCE
- IDA on iPhone
- SymbolFinder
- Sun VirtualBox Disassembler Explantation
- CartellaUnicaTasse.exe Italian Malware RCE Analysis
- Why is secure development so important?
- pde/pte softice plugin
- Funny coded malware
- antisptd
- IceProbe - SoftIce Command Tracer
- build rule for x64 asm
- nonintrusive tracer on x64
- My "Unofficial" ReCon Video
- Strong-Name Signing, AdmiralDebilitate v0.1
- IDA Pro Development Environment
- Control Flow Deobfuscation Part 3
- Vmware snapshot and SSDT
- Phoenix Protector 1.3.0.1
- .NET Internals and Native Compiling
- Fujitsu 3D Shock Sensor Application Reversing
- An Introduction To .NET Reversing
- IDA and vmread/vmwrite x64
- Intel VT and cpuid break
- Downloader.Win32.Small or Win32/PolyCrypt Reversing
- #773: bug in IDA-Pro [fails to debug zero-based PE]
- "Function String Associate" IDA Plug-in
- # old CD 03 bug in windows
- # thinking in IDA Pro - how to obtain a copy
- # bug in Process Explorer (a gift for malware)
- # other solutions: how to load two or more files into the same IDA-Pro database
- # how to load two or more files into single IDA Pro database
- # Syser causes BSOD
- # eternal life, ammo, scores in games
- # free IDA-Pro training
- # turbo-import [stealth anti-api-monitors style]
- # bug in Olly, Windows behavior and Peter Ferrie
- .NET Internals and Code Injection
- D3DLookingGlass v0.1
- DisasMSIL and CFF Explorer
- Retsaot is Toaster, Reversed: Quick 'n Dirty Firmware Reversing
- My next 2 articles
- A brief discussion of Windows Vista’s IE Protected Mode (and user/process level secur
- Rebel.NET
- Integer overflow
- Control Flow Deobfuscation Part 2
- Programming against the x64 exception handling support, part 1: Definitions for x64 v
- Frame pointer omission (FPO) optimization and consequences when debugging, part 2
- Frame pointer omission (FPO) optimization and consequences when debugging, part 1
- The kernel object namespace and Win32, part 3
- The kernel object namespace and Win32, part 2
- Debugger tricks: API call logging, the quick’n'dirty way (part 3)
- The kernel object namespace and Win32, part 1
- Programming against the x64 exception handling support, part 2: A description of the
- Programming against the x64 exception handling support, part 3: Unwind internals (Rtl
- Programming against the x64 exception handling support, part 4: Unwind internals (Rtl
- Programming against the x64 exception handling support, part 5: Collided unwinds
- Programming against the x64 exception handling support, part 6: Frame consolidation u
- Programming against the x64 exception handling support, part 7: Putting it all togeth
- Debugger tricks: API call logging, the quick’n'dirty way (part 1)
- Debugger tricks: API call logging, the quick’n'dirty way (part 2)
- Few words about Kraken
- Introduction to x64 debugging, part 1
- Introduction to x64 debugging, part 2
- Introduction to x64 debugging, part 3
- Introduction to x64 debugging, part 4
- Introduction to x64 debugging, part 5
- x64 Debugging Review
- Using SDbgExt to aid your debugging and reverse engineering efforts (part 1).
- SDbgExt extensions - part 2.
- Useful WinDbg commands: .formats
- Debugger commands review
- Useful debugger commands: .writemem and .readmem
- SDbgExt 1.09 released (support for displaying x64 EH data)
- Debugger flow control: More on breakpoints (part 2)
- Removing kernel patching on the fly with the kernel debugger
- Beware of stack usage with the new network stack in Windows Vista
- Remote debugging with process servers (dbgsrv)
- Reverse debugging -server and -remote
- Win32 calling conventions: __thiscall in assembler
- Overview of WinDbg remote debugging
- Win32 calling conventions: __stdcall in assembler
- Win32 calling conventions: Concepts
- Remote debugging with kdsrv.exe
- Remote debugging review
- Win32 calling conventions: __fastcall in assembler
- Activating process servers and connecting to them
- Ollydbg v1.10 and 6E/6F/A6 opcodes, a little oversight
- Securing -server and -remote remote debugging sessions
- Remote debugging with -server and -remote
- Remote debugging with KD and NTSD
- Remote debugging with remote.exe
- Win32 calling conventions: Usage cases
- Win32 calling conventions: __cdecl in assembler
- Tracing Over System Calls In OllyDbg
- DynLogger
- Some functions are neater than the decompiler thinks
- Self-modifying TLS callbacks
- Symbian debugger
- Trojan-PSW.Win32.OnLineGames.eos Reversing
- Compiler 1, X86 Virtualizer 0
- IDA disasms reserved opcodes, is it a bug?
- Weird export forwarding thanks to Vista x64 SP1
- Symbian AppTRK
- Inside Session 0 Isolation and the UI Detection Service - Part 2
- Process Memory Dumper for Credentials Disclosure Vulns
- Cross Your T's and Dot Your Filenames
- Hello Symbian!
- (Part 2 of .NET native exe insights)Serial fishing and patching .NET exes with Ollydb
- Rebuilding native .NET exes into managed .NET exes by Exploiting lefotver IL...
- Some Quick Insights Into Native .NET exe's (part 1 of?)
- Reverse Engineering Position- TS/SCI Required
- Symbol Type Viewer 32Bit/64Bit v1.0.0.3
- Inside Session 0 Isolation and the UI Detection Service - Part 1
- Non-continuable exception trick
- Something different part 2
- New Hex-Rays Demo
- Different versions of Windows kernel structures
- gee mail patented algorithm
- Pythonic way
- Running Win32 program ASAP after Nt boot
- hm
- Re: RtlRemoteCall
- Alignment check
- Working? with protected processes in NT 6
- Microsoft's Rich Signature (undocumented)
- Tricky jump tables
- Reverse Engineering the flash virtual machine
- Collaborative RCE Tool Library (CRCETL) site update
- Two Extensions added into Collaborative RCE
- Why does every heap trace in UMDH get stuck at "malloc"?
- SoftICE Installation.
- Easy structure types
- Eeye BinDiffing Trick
- Industrial-Grade Binary-Only Profiling and Coverage
- Refreshing the Taskbar Notification Area
- Idc script and stack frame variables length
- Shellcode Analysis
- Array Indexing Quirk
- SpyShredder Malware Spammed on OpenRCE
- MRXDAV.SYS and Hex-Rays Decompiler
- Shellcoding on Windows: Part II - Stack Overflow Problems
- Updated ExtraPass plug-in 2.1, and APIScan
- dr7.gd on mp systems running sice
- PE Validator Script
- Thread Optimization Checks : Code Prominence
- Run-time determination of VC++ virtual member function addresses: Take II
- Immunity Debugger v1.4
- Debugger and process memory
- KeGetCurrentIrql can't return HIGH_LEVEL
- aMSN Input Validation Error
- Direct3D 9 Hook v1.1
- Jump tables
- Something different
- Shellcoding on Windows: Part I
- An Objective Analysis of the Lockdown Protection System for Battle.net
- ActiveX - Active Exploitation
- Improving Software Security Analysis using Exploitation Properties
- Context-keyed Payload Encoding
- FPU Tracer v0.0.1 released
- .NET unpackme
- softice nmi hook
- ScTagQuery: Mapping Service Hosting Threads With Their Owner Service
- Virtual Machine detection method cd.
- Old new Virtual Machine detection method.
- Compiler Optimizations Regarding Structures
- HP printer and cpu at 100%
- Again on Visual Basic
- Binary Search in Large-Scale Structure Recovery
- GUID-Finder IDA Plug-in
- Explorer Suite III (CFF Explorer VII)
Powered by vBulletin® Version 4.1.9 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.