View Full Version : Blogs Forum
- Reversity Speech and Logs Available
- Control Flow Deobfuscation Part 1
- Dvd movie and easter egg
- Thread Local Storage, part 7: Windows Vista support for __declspec(thread) in demand
- Thread Local Storage, part 6: Design problems with the Windows Server 2003 (and earli
- Thread Local Storage, part 5: Loader support for __declspec(thread) variables (proces
- Thread Local Storage, part 4: Accessing __declspec(thread) data
- Thread Local Storage, part 3: Compiler and linker support for implicit TLS
- Thread Local Storage, part 2: Explicit TLS
- Thread Local Storage, part 8: Wrap-up
- How does one retrieve the 32-bit context of a Wow64 program from a 64-bit process on
- Viridian guest hypercall interface published
- Why are certain DLLs required to be at the same base address system-wide?
- A catalog of NTDLL kernel mode to user mode callbacks, part 1: Overview
- A catalog of NTDLL kernel mode to user mode callbacks, part 2: KiUserExceptionDispatc
- A catalog of NTDLL kernel mode to user mode callbacks, part 3: KiUserApcDispatcher
- A catalog of NTDLL kernel mode to user mode callbacks, part 4: KiRaiseUserExceptionDi
- A catalog of NTDLL kernel mode to user mode callbacks, part 5: KiUserCallbackDispatch
- Thread Local Storage, part 1: Overview
- The optimizer has different traits between the x86 and x64 compilers
- Compiler tricks in x86 assembly: Ternary operator optimization
- Reversing the V740, part 4: Implementing a solution
- A catalog of NTDLL kernel mode to user mode callbacks, part 6: LdrInitializeThunk
- Common WinDbg problems and solutions
- Fast kernel debugging for VMware, part 1: Overview
- Fast kernel debugging for VMware, part 2: KD Transport Module Interface
- Fast kernel debugging for VMware, part 3: Guest to Host Communication Overview
- Fast kernel debugging for VMware, part 5: Bridging the Gap to DbgEng.dll
- Fast kernel debugging for VMware, part 6: Roadmap to Future Improvements
- VMKD 1.1.1.7 released
- Fast kernel debugging for VMware, part 4: Communicating with the VMware VMM
- Reversing the V740, part 3: The V740 abstraction layer module
- Reversing the V740, part 2: Digging deeper: The connection manager software
- Reversing the V740, part 1: Rationale
- Why doesn't the publicly available kernrate work on Windows x64? (and how to fix it
- The default invalid parameter behavior for the VC8 CRT doesnâ??t break into the debug
- I tend to prefer debugging with release builds instead of debug builds.
- More packer analysis
- Packer analysis
- Debugging a custom unhandled exception filter
- Collaborative RCE Tool Library contents so far
- ImageRemCert - Removes certificate from PE image.
- CommWarrior.B Thorough IDB (ARM/C++)
- MemInfo: Peer Inside Memory Manager Behavior on Windows Vista and Server 2008
- dr7.gd - dr6 saving
- Better user interface for decompiler
- The Windows Vista Issue
- Weird Code: CCs On The Stack
- Windbg “dt” output converter
- MmGetSystemRoutineAddress : forwards on vista
- Traversing Offset Semantics : Walking Along the Curb
- The Collaborative RCE Tool Library
- syscall fuzzer
- The secret project finally revealed...
- Site Relaunch
- A framework to take the tedium out of code-injection in C++
- Beware of int 2c instruction
- IDC scripting a Win32.Virut variant - Part 2
- IDC scripting a Win32.Virut variant - Part 1
- Nanomites by Deroko
- Hang problem due to Hooking Curb in Codes.
- Vaughn Of The Dead Pt III: Some small-fry
- Armadillo, Nanomites and vectored exception-handling
- Why Protected Processes Are A Bad Idea
- Behind Windows x64's 44-bit Virtual Memory Addressing Limit
- Purple Pill: What Happened
- Secrets of the Application Compatilibity Database (SDB) - Part 4
- New Object Manager Filtering APIs
- Vista DRM Issue Aftermath
- Rebooting from Kernel Mode
- Recent Events
- Update on Driver Signing Bypass
- Windows Vista 64-bit Driver Signing/PatchGuard Workaround
- How I cracked the iTunes 7 DRM, Pt V
- How I cracked the iTunes 7 DRM, Pt III
- Case study: Fraps
- RCE essentials: PEiD
- Run-time determination of VC++ 2005 virtual member function addresses
- DLL injection via CreateRemoteThread
- How I cracked the iTunes 7 DRM, Pt II
- How I cracked the iTunes 7 DRM, Pt I
- Drawing on another Direct3D program's viewport
- How I cracked the iTunes 7 DRM, Pt IV
- Bypassing IsDebuggerPresent
- RDP Botnets : Malware Google Dorking - Not an Easy Task
- Exploring Protocols 2: Writing some tools
- Exploring Protocols - Part 1
- Reversing a ZLib-Obfuscated? Network Protocol
- MITMing an SSLized Java App
- Analyzing Mac OS X Applications 101: CrashReporter and Malloc
- Refreshing Change Of Pace: Actual Technical Discussions at Nate's Blog
- BinNavi Traces IOS and ScreenOS. It's On, Yo.
- Mystery Vulnerability Theater 3000: Part I
- ridiculous_fish Open-Sources HexFiend!
- Is Win32 A Debugging API? If Not, How Close Is It?
- Experimenting with IDA 5.2's scriptable debugger
- Auditing Oracle with Cesar Cerrudo
- Undocumented Windows 2000 Secrets - free pdf edition
- PaiMei / PIDA Fun
- Breaking in DAV RPC INTERFACE : Peripherals
- Decompiler output ctree
- Intrinsic "_ReturnAddress()" C/C++ WTF!
- New face and new concept for the Reverse Code Engineering Video Portal
- Immunity Debugger Plugin Awards
- Immunity Debugger v1.1 Release
- For those who miss it: Immunity Debugger v1.2 Release
- Vista Heap, Controlling the Determinism.
- Python + Microsoft Minidumps
- Small PyDBG Enhancements Incoming
- Packet Sniffing With ImmunityDebugger
- Grey Box Web Application Testing With Immunity Debugger
- Visual Patterns for File Format Fuzzing
- Reliability of Pseudo Registers in Bug Tracking
- Dissecting Windows XP Svchost Internals : Traversing Core Parameters
- Stack Unwinding : Reliability Panorama
- Hardware Breakpoints : Stature
- Immunity Debugger is now released!
- Null pointer dereference in win32k
- An "extra pass" for IDA Pro
- Dancing with exceptions
- Updated APIScan
- Real Time Tracing
- My first entry
- Embedded Portable Executable File
- Comming soon! Uber process hooking/detour system!
- Assembly Custom GetProcAddress
- IDA's .IDS Files Part I
- Mysteries of win32k & GDI - Win32Thread
- Syscall lister
- Another IDA script: Dump section
- T2 2006 VM Analysis
- My Training Class
- ProcDump Thorough IDB
- IDA's .IDS Files Part II
- Future occupation: Archeological reverser?
- Automating analysis with PyDbg
- Interesting primer on Virtualization from VMware
- Mass deface with RFI scanners
- Why VMware is bad for shareware?
- ExeCryptor's code morphing "technology"
- Semi-automatic import recovery
- HELLO!
- Komodo Edit 4.2 released
- Visual Basic DllFunctionCall
- A new player in the virtualization arena for Mac
- VMWare Fusion?
- EXPLICATOR?
- Scripting fun
- Adding IDC commands to the out-of-the-box set
- OUTLAW ROOTKITS?
- LINUX AT LAST!
- Radio?
- Negated structure offsets
- IDA and Microcontrollers
- Hex-Rays SDK is ready!
- Coordinate system for Hex-Rays
- Trunk, Branches, and Leaves
- OpenRCE?
- Never say never
- Decompilation gets real
- Finally, good STL replacement?
- Hex-Rays beta testing is open!
- Very simple custom viewer
- Dynamic coloring
- Adding cross references
- On batch analysis
- Does 'return' come back?
- Video #5 is up.
- Editable Listview control
- IDA plugin: Extract (UnRot13) and analyze
- The Point-R technique
- Doing it without Weird Hacks (tm) is even easier
- imports are easy to fix
- New Video Tutorials website
- Exploiting the Otherwise Non-Exploitable on Windows
- Improving Automated Analysis of Windows x64 Binaries
- Fingerprinting 802.11 Implementations via Statistical Analysis of the Duration Field
- Wars Within
- Effective Bug Discovery
- Preventing the Exploitation of SEH Overwrites
- Exploiting 802.11 Wireless Driver Vulnerabilities on Windows
- Locreate: An Anagram for Relocate
- Subverting PatchGuard Version 2
- Mnemonic Password Formulas
- Memalyze: Dynamic Analysis of Memory Access Behavior in Software
- Reducing the Effective Entropy of GS Cookies
- Generalizing Data Flow Information
- A Catalog of Local Windows Kernel-mode Backdoor Techniques
- OS X Kernel-mode Exploitation in a Weekend
- PatchGuard Reloaded: A Brief Analysis of PatchGuard Version 3
- Real-time Steganography with RTP
- Abusing Mach on Mac OS X
- GREPEXEC: Grepping Executive Objects from Pool Memory
- Anti-Virus Software Gone Wrong
- 802.11 VLANs and Association Redirection
- Introduction to Reverse Engineering Win32 Applications
- Smart Parking Meters
- Loop Detection
- Social Zombies: Aspects of Trojan Networks
- Mac OS X PPC Shellcode Tricks
- Annoyances Caused by Unsafe Assumptions
- Implementing a Customer X86 Encoder
- Bypassing Windows Hardware-enforced DEP
- Temporal Return Addresses
- Inside Blizzard: Battle.net
- Bypassing PatchGuard on Windows x64
- Analyzing Common Binary Parser Mistakes
- Attacking NTLM with Precomputed Hashtables
- Linux Improvised Userland Schedular Virus
- FUTo
- Post-Exploitation on Windows using ActiveX Controls
- Thick Clients Gone Wrong
- Windows Kernel-mode Payload Fundamentals
- Funny API function inside ntdll.dll
- Upack
- Code injection
- How to get the Virtual Address of a PE section with IDA
- Finessing Import REConstructor
- REcon 2005
- Getting around anti-debugger code
- Forcing IDA's "Create function..." on functions containing invalid code
- When the Red Pill is Hard to Swallow
- Using Structure Offsets as Symbolic Constants in IDA
- Unpacking DLLs and Drivers with OllyDbg
- Terms of the Trade
- Circumventing custom SEH
- Advanced Malware Deobfuscation training course at Black Hat
- Function Analysis
- Counting Lines of Source Code
- Loading Drivers in OllyDbg
- Career Shift
- Stateless Bi-Directional Proxy
- Investigating Outlook's Single-Instance Restriction (PART 1)
- Investigating Outlook's Single-Instance Restriction (PART 2)
- Virus Bulletin 2006
- Using assembly buffers in C++ without using hex-strings
- stuffz
- Блогујем ја, блогујеш ти....
- ВМВаре видимо се : vmware detection
- Свету се немодзе угодити
- Виртуелно, виртуелно и машински
- Making an advanced api redirection more advanced?
- Some words on how to decrypt trojan Ascesso
- Something About Firewall Hooking and Packet Filtering #1
- Hello World
- A Framework for Hash Algorithms Analysis
- Something About Firewall Hooking and Packer Filtering #2
- hm
- First blog entry ever on Woodmann.com!
- A Guide to Decompiler Design - Part 0
Powered by vBulletin® Version 4.1.9 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.