PDA

View Full Version : Blogs Forum


Pages : [1] 2 3

  1. Recon 2010: Intro to Embedded Reverse Engineering for PC reversers
  2. PAPER: Security Mitigations for Return-Oriented Programming Attacks
  3. Dataflow-0.2.0 released. New: in memory fuzzing means
  4. RELEASE: SMB2 REMOTE EXPLOIT (VISTA SP1/SP2) + HACKTRO
  5. IDAQ: The result of 7 months at Hex-Rays
  6. Dynamic Binary Code and Data Flow Analysis Instrumentation.
  7. Handy debugger tricks: Setting osloader options on a per-boot basis
  8. Windows CSRSS Write Up: Inter-process Communication (part 2/3)
  9. Blog customization, old PHP advisories
  10. Implementing command completion for IDAPython
  11. Kernel debugger vs user mode exceptions
  12. Windows CSRSS Write Up: Inter-process Communication (part 1/3)
  13. Attacking the Host via Remote Kernel Debugger (Virtual Machines)
  14. Running scripts from the command line with idascript
  15. Windows CSRSS Write Up: the basics (part 1/1)
  16. IDA Pro 5.7 highlights
  17. A quick insight into the Driver Signature Enforcement
  18. Extending IDC and IDAPython
  19. PatchDiff2 Analysis and Decompilation
  20. [WinInternals] Reverse Engineering of kdbgctrl - How are builded Kernel Triage Dumps
  21. CONFidence 2010 is over
  22. UI and scripting improvements
  23. The Future of Disassembling - Cloud OS
  24. ARM decompiler beta is coming
  25. Windows CSRSS cross-version API Table
  26. Kernel debugging with IDA Pro / Windbg plugin and VirtualKd
  27. Debugging the Debugger - Reversing kldbgdrv.sys and Potential Usages
  28. Book Review: The Art of Assembly Language, 2nd Edition
  29. Windows Kernel Vulnerabilities continued – details
  30. CTcpFwd – cross-platform stdin/out to socket forwarding class
  31. Windows Kernel Vulnerabilities release (Hispasec research)
  32. A Filemaker Story
  33. Environment variable editor
  34. Scriptable plugins
  35. Using custom viewers from IDAPython
  36. Preview of the new cross-platform IDA Pro GUI
  37. Compiler Optimizations for Reverse Engineers
  38. Custom data types and formats
  39. Abusing alignment code for anti-sandboxing purposes
  40. Scriptable Processor modules
  41. My first month at Hex-Rays
  42. Great News!
  43. New IDC improvement in IDA Pro 5.6
  44. RCE, A New Exciting and Strange World
  45. Rootkit Agent.adah Anatomy and Executables Carving via Cryptoanalytical Approach
  46. Hex-Rays against Aurora
  47. Practical Appcall examples
  48. "Descriptor tables in kernel exploitation" - a new article
  49. Advanced Signature Writing via FuzzyHashing
  50. Introducing the Appcall feature in IDA Pro 5.6
  51. Debugging ARM code snippets in IDA Pro 5.6 using QEMU emulator
  52. PDF file loader to extract and analyse shellcode
  53. x86 Kernel Memory Space Visualization (KernelMAP v0.0.1)
  54. Code release: C-subset compiler in Objective Caml
  55. VinE's OCaml Programming Tricks: Explicit Continuation-Passing Style
  56. DNAScan Malicious Network Activity Reverse Engineering
  57. Hex-Rays Plugin Contest
  58. Win32k.SYS system call table
  59. KiTrap06(#UD)
  60. Using MATLAB and Mathcad for solving (mesh current) equations.
  61. Unexported SSDT functions finding method
  62. Elevation of Privilege DLL Patcher
  63. Hex-Rays is hiring
  64. Filter Monitor 1.0.1
  65. Hex-Rays Decompiler primer
  66. Structure Recovery as Counter-Example Guided Abstraction Refinement
  67. Controlling Windows process list, part 1
  68. Telewizor, meble, ma?y fiat
  69. SEH Graph
  70. SMB2: 351 Packets from the Trampoline released!
  71. 351 Packets from the Trampoline
  72. TraceHook v0.0.2
  73. Device Drivers Vulnerability Research, Avast a real case
  74. Finding instructions
  75. An attempt to reconstruct the call stack
  76. VMware CloudBurst - VMware Guest to Host Escape Exploit
  77. C++ Method Constness
  78. Develop your master boot record and debug it with IDA Pro and the Bochs debugger plug
  79. Code Release page
  80. Viewer for driver dispatch tables
  81. Binary-Auditing Solutions.
  82. Process termination issues
  83. Recent conferences’ reports
  84. DllMain and its uncovered possibilites
  85. The incoming SecDay conference
  86. Suspending processes in Windows, part 1
  87. TraceHook v0.0.1 release
  88. Hello world!
  89. Extending Total Commander with some minor functionality
  90. "Client" Unit Tests(some fun ones..)Indirect RtlCreateUserThread hooking..
  91. Several Common Ways That Viruses Spread
  92. VMware ring3 detection (RF handling)
  93. Javascript for IDA Pro
  94. Sorry its taking so long on the next release of source..
  95. Casts are bad
  96. (In My fucked up way Of thinking...)
  97. # faked Adobe PDF.SWF exploit on milw0rm
  98. # weakness of PAGE_GUARD or new Windows bug (XP/Vista 32/64 SP1)
  99. placing a "hotpatch" where it doesnt belong..
  100. why Opcode0x90's "dll Injection shield" fails against RtlCreateUserThead
  101. Pwnie Awards Nominees!!!
  102. Bypassing Csrss's hold on Terminating Win32Threads..
  103. Aslan (4514N) - Binary Code Integrator - Okaeri
  104. If I had a nickel for every time I had a nickel, I'd have TWO NICKELS
  105. Dynamic Data Flow Analysis via Virtual Code Integration (aka The SpiderPig case)
  106. PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs
  107. Kon-Boot for USB and some news
  108. Some graphs
  109. PAPER: Evading network-level emulation
  110. Generic unpacking paper revision
  111. Incoming...
  112. Blah
  113. SpiderPig and The Childs.
  114. SpiderPig Memory Tracer
  115. Presenting Kon-Boot v1.0
  116. # IDA-Pro steals RIP ? introduction in relative addressing
  117. User-mode debugger with SoftICE UI
  118. # MS DirectShow MPEG2 (msvidctl.dll) worm was fired out!
  119. # IDA-Pro//BOCHSDBG plug-in bug: lack of 16bit support
  120. CallOutRecaptureRoutine and the changes it made
  121. # Xcon2009: passive non-resident root-kits
  122. VMprotect VM_logic (in v1.8 demo)
  123. # die Vista, die or why DEADDEEF is alive?
  124. A snippet of time.. ;) uneditted ..
  125. # IDA-Pro 5.5 has been updated, fixed ? Bochs plug-in unaligned PE bug
  126. # San-Francisco - A Dream Came True
  127. Native Blocks Pre-Alpha
  128. Server Handle Table Funtions.
  129. Ideas and concepts: behind the Sin32 Subsystem
  130. Bare Bone Client
  131. Ruby for Pentesters - The Dark Side I: Ragweed
  132. Server Thread Recycling (Beginings..)
  133. Current QuickLPC Client
  134. Current QuickLPC Server Implementation
  135. Function call graph plugin sample
  136. My first blog post.(plans for my blog)
  137. IDA Pro 5.5 and Hex-Rays 1.1 have been released!
  138. psusp
  139. Windows 7 RC syscalls
  140. # a bomb from McAfee (a nasty one)
  141. IDA Pro 5.5 goes alpha
  142. VMprotect VM_logic (in v1.8 demo)
  143. Matasano PFI (as seen on TV!)
  144. Using CreatePipe to detect and thwart Emulating Sandboxes and AV emulators
  145. EventPair Reversing, EventPairHandle as Anti-Dbg Trick
  146. Decompiling floating point
  147. IDA v5.4 demo
  148. RtlQueryProcessHeapInformation as Anti-Dbg Trick
  149. RtlQueryProcessDebugInformation as Anti-Dbg Trick
  150. Found what is that "long mode segmentation"
  151. Updated "Class Informer" plug-in
  152. Debugger tricks: Find all probable CONTEXT records in a crash dump
  153. Anti-Emulation Tricks
  154. InfoSec Institute's RE Course
  155. Examining kernel stacks on Vista/Srv08 using kdbgctrl -td
  156. VC++ asm intrinsics
  157. Ruby for Pen-Testers: Announcing Ruby Black Bag
  158. Netsons killed my Website
  159. DirecSound Capture With Deviare
  160. Understanding the kernel address space on 32-bit Windows Vista
  161. Recovering a process from a hung debugger
  162. Advanced Windows Kernel Debugging with VMWare and IDA's GDB debugger
  163. # I’m on my way to South Africa
  164. # self-replicated processes
  165. # JL/JGE Intel CPU bug as anti-reversing trick
  166. # Olly Plug-ins and MS VC
  167. # Olly loads Olly to bypass anti-attach tricks /* Clerk? trick */
  168. # anti-attach: BaseThreadStartThunk => NO_ACCESS
  169. # zombie slam
  170. # Process Explorer - bloody hell of indefinite waiting bugs
  171. # NtRequestWaitReplyPort abuses IDA-Pro
  172. # PRNG based on REP STOS
  173. # attach to me? if you can (part II)
  174. # self-overwritten REP STOS/MOVS, IDA-Pro 5.4 and Ko
  175. # try to attach to me? if you can!
  176. Mr. Bachaalany joins Hex-Rays
  177. The IDA Pro book
  178. BITS used as a covert channel
  179. Bochs Emulator and IDA?
  180. IDA Pro has 9 debugger modules
  181. IDA and MIPS
  182. Bochs plugin goes alpha
  183. Blackhat USA 2008
  184. Apple's variant of ptrace()
  185. Recon2008
  186. Testing debuggers
  187. From simple to complex
  188. Kernel debugging with IDA
  189. Bridge them all
  190. # IDA-Pro 5.4: old bugs on the new streets (was: to download or to not download)
  191. # RE course in Tel-Aviv
  192. Playstation3 / PS3 - Harddisk encryption
  193. # simple OllyScript for upx
  194. S7 airlines is under attack!
  195. # PatchDiff => Hex-Rays => WinDiff: how to analyze patches faster
  196. # Baghdad - dead alive breakpoints
  197. Class Informer IDA plug-in
  198. Windows 7 syscall list
  199. IDA v5.4 release is not that far away
  200. Windows 7 kernel structures
  201. # shell-codes analysis: where is EP?
  202. x64 SEH & Explorer Suite Update
  203. # FreeLibrary bug becomes a PE packers bug
  204. San-Francisco - the place to meet
  205. # MS VC - challenge for PE packers
  206. Unpinning Imported .dll's
  207. # chilly suspicions of new win32 bug
  208. # 3 lines C-prog hurts MS VC
  209. Malware: Unpacking Waledac
  210. # dynamic TLS callbacks instead of SEH
  211. # IDA-Pro and simple (E)SP hack
  212. # GetProcessDEPPolicy for XP/XP SP2
  213. NtSetDebugFilterState as Anti-Dbg Trick
  214. # TLS callbacks w/o USER32 (part III)
  215. # TLS callbacks w/o USER32 (part II)
  216. # another EnableTracing() bug
  217. how powerful IDA Script might be
  218. # IDA-Pro EnableTracing() - how not to do
  219. IDA and TLS callbacks
  220. # XP/S2K3 fails to process TLS w/o USER32
  221. # DS/FS is under hardware breakpoints
  222. blog was moved
  223. Guidelines to MFC reversing
  224. IOCTL-Proxy
  225. Dynamic C++ Proposal
  226. Command line version of OSR's DeviceTree
  227. Backdoor.Win32.UltimateDefender Reverse Engineering
  228. Switch as Binary Search, Part 1
  229. Switch as Binary Search, Part 0
  230. Qt Internals & Reversing
  231. CVE-2006-5758: better late than ever
  232. Malware and initial stack pointer value
  233. Shared object injection on linux/unix
  234. Bagle.W IDB
  235. Trojan.Zhelatin.pk
  236. Hotpatching MS08-067
  237. On Analysis of Client-Server Software Applications
  238. Analyzing local privilege escalations in win32k
  239. Exploiting Tomorrow's Internet Today: Penetration testing with IPv6
  240. Can you find me now? Unlocking the Verizon Wireless xv6800 (HTC Titan) GPS
  241. VbPython 1.2a
  242. examples of the syllabuses
  243. Using dual-mappings to evade automated unpackers
  244. Interesting Kernel32 Constant
  245. Analyzing Malicious PDF's
  246. The Wild World of VoIP
  247. RE-courses/conferences schedule
  248. custom gpa spy
  249. Debugger Detection Via NtSystemDebugControl
  250. POP SS and Debuggers