View Full Version : Blogs Forum
- FIY: Printable “Windows Kernel Address Protection” paper out
- connect two virtual machines on one physical host and use wdeb386 to debug win98 app
- Magus Ex Machina – a product of a 48h codejam
- Refreshed Windows System Call Table (NT/2000/XP/2003/Vista/2008/7/8) released
- ApiMapSet Hooking
- ApiMapSet Explained
- Code viewer, forms & timers
- Hack in the Box Magazine #7 on the wild, at last.
- New features in Hex-Rays Decompiler 1.6
- PiXiEServ out for public
- New Security Assertions in “Windows 8
- Windows 8 Syscall Interface and Export Table diffing fun
- Simple Dll Compiled From Commandline Unlike what google returns vc++ proj
- IDA Pro 6.2 beta
- Filters & Shortcuts
- How To Add TypeInfo So That Dt Commands Work Properly In Windbg
- New feature in IDA 6.2: The proximity browser
- 0-day Windows XP SP3 Denial of Service (CSRSS Crash #1)
- Book review: IDA Pro Book, 2nd Edition
- Recon 2011: Practical C++ Decompilation
- IDA Pro 6.2 with database snapshots support
- CVE-2011-1282: User-Mode NULL Pointer Dereference & co.
- PE Import Table and custom DLL paths
- CVE-2011-1281: A story of a Windows CSRSS Privilege Escalation vulnerability
- Control Flow Deobfuscation via Abstract Interpretation
- Unpacking mpress’ed PE+ DLLs with the Bochs plugin
- Basic blocks and instructions statistics.
- Some notes on how to find out hidden callbacks
- Protected Mode Segmentation as a powerful anti-debugging measure
- The HITB Magazine #6 now available!
- How to crash EXPLORER.EXE on all Windows versions
- SMEP: What is it, and how to beat it on Windows
- Compling PinTools with Microsoft Visual Studio (MSVC9)
- nt!NtMapUserPhysicalPages and Kernel Stack-Spraying Techniques
- Subtle information disclosure in WIN32K.SYS syscall return values
- Precompiled PySide binaries for IDA Pro
- Control Flow Integrity: Some interesting papers
- Pimp My CrackMe contest results
- PAPER: Securing The Kernel via Static Binary Rewriting and Program Shepherding
- VirusTotal plugin for IDA Pro
- Challenging job for software developers
- Reading Virtual Memory
- Updated plug-ins, blogging moved to..
- Dynamic Binary Instrumentation as base for security product (full system protection)?
- BINARY REWRITING WITHOUT RELOCATION INFORMATION
- DelMod2
- The dream is 'really higher up'... :P
- When choosers invade forms
- HITB E-Zine Issue 005 finally made public
- tracer or Writing tracer without using Windows Debug API
- Using nt!_MiSystemVaType to navigate dynamic kernel address space in Windows7
- My Search for knowledge and my explorations There and back and most often in a circle
- DbgView patch
- Windows Kernel-mode GS Cookies and 1 bit of entropy
- IDA & Qt: Under the hood
- Rebootless Windows Updates (Ksplice for Windows) and AutoDiff
- IDA Pro 6 licenses
- (Yet another) Memory dumper
- Reality Cracking CNN's Bias
- IDA Pro, Python and Qt
- HITB eZine Issue 004 is public!
- Calculating API hashes with IDA Pro
- Windows kernel2user transitions one more time
- The Old New Thing: Why you shouldn't allocate usermode memory from PsSetLoadImageNot
- PAPER: JIT spraying and mitigations
- Kernel exploitation – r0 to r3 transitions via KeUserModeCallback
- Recon 2010: Intro to Embedded Reverse Engineering for PC reversers
- PAPER: Security Mitigations for Return-Oriented Programming Attacks
- Dataflow-0.2.0 released. New: in memory fuzzing means
- RELEASE: SMB2 REMOTE EXPLOIT (VISTA SP1/SP2) + HACKTRO
- IDAQ: The result of 7 months at Hex-Rays
- Dynamic Binary Code and Data Flow Analysis Instrumentation.
- Handy debugger tricks: Setting osloader options on a per-boot basis
- Windows CSRSS Write Up: Inter-process Communication (part 2/3)
- Blog customization, old PHP advisories
- Implementing command completion for IDAPython
- Kernel debugger vs user mode exceptions
- Windows CSRSS Write Up: Inter-process Communication (part 1/3)
- Attacking the Host via Remote Kernel Debugger (Virtual Machines)
- Running scripts from the command line with idascript
- Windows CSRSS Write Up: the basics (part 1/1)
- IDA Pro 5.7 highlights
- A quick insight into the Driver Signature Enforcement
- Extending IDC and IDAPython
- [WinInternals] Reverse Engineering of kdbgctrl - How are builded Kernel Triage Dumps
- PatchDiff2 Analysis and Decompilation
- CONFidence 2010 is over
- UI and scripting improvements
- The Future of Disassembling - Cloud OS
- ARM decompiler beta is coming
- Windows CSRSS cross-version API Table
- Kernel debugging with IDA Pro / Windbg plugin and VirtualKd
- Book Review: The Art of Assembly Language, 2nd Edition
- Debugging the Debugger - Reversing kldbgdrv.sys and Potential Usages
- Windows Kernel Vulnerabilities continued – details
- CTcpFwd – cross-platform stdin/out to socket forwarding class
- Windows Kernel Vulnerabilities release (Hispasec research)
- A Filemaker Story
- Environment variable editor
- Scriptable plugins
- Using custom viewers from IDAPython
- Preview of the new cross-platform IDA Pro GUI
- Compiler Optimizations for Reverse Engineers
- Custom data types and formats
- Abusing alignment code for anti-sandboxing purposes
- Scriptable Processor modules
- My first month at Hex-Rays
- Great News!
- New IDC improvement in IDA Pro 5.6
- RCE, A New Exciting and Strange World
- Rootkit Agent.adah Anatomy and Executables Carving via Cryptoanalytical Approach
- Hex-Rays against Aurora
- Practical Appcall examples
- "Descriptor tables in kernel exploitation" - a new article
- Advanced Signature Writing via FuzzyHashing
- Introducing the Appcall feature in IDA Pro 5.6
- Debugging ARM code snippets in IDA Pro 5.6 using QEMU emulator
- PDF file loader to extract and analyse shellcode
- x86 Kernel Memory Space Visualization (KernelMAP v0.0.1)
- Code release: C-subset compiler in Objective Caml
- VinE's OCaml Programming Tricks: Explicit Continuation-Passing Style
- DNAScan Malicious Network Activity Reverse Engineering
- Hex-Rays Plugin Contest
- Win32k.SYS system call table
- KiTrap06(#UD)
- Using MATLAB and Mathcad for solving (mesh current) equations.
- Unexported SSDT functions finding method
- Elevation of Privilege DLL Patcher
- Hex-Rays is hiring
- Filter Monitor 1.0.1
- Hex-Rays Decompiler primer
- Structure Recovery as Counter-Example Guided Abstraction Refinement
- Controlling Windows process list, part 1
- Telewizor, meble, ma?y fiat
- SEH Graph
- SMB2: 351 Packets from the Trampoline released!
- 351 Packets from the Trampoline
- TraceHook v0.0.2
- Device Drivers Vulnerability Research, Avast a real case
- Finding instructions
- An attempt to reconstruct the call stack
- VMware CloudBurst - VMware Guest to Host Escape Exploit
- C++ Method Constness
- Develop your master boot record and debug it with IDA Pro and the Bochs debugger plug
- Code Release page
- Viewer for driver dispatch tables
- Binary-Auditing Solutions.
- Process termination issues
- DllMain and its uncovered possibilites
- Recent conferences’ reports
- The incoming SecDay conference
- Suspending processes in Windows, part 1
- TraceHook v0.0.1 release
- Hello world!
- Extending Total Commander with some minor functionality
- "Client" Unit Tests(some fun ones..)Indirect RtlCreateUserThread hooking..
- Several Common Ways That Viruses Spread
- VMware ring3 detection (RF handling)
- Javascript for IDA Pro
- Sorry its taking so long on the next release of source..
- Casts are bad
- (In My fucked up way Of thinking...)
- # faked Adobe PDF.SWF exploit on milw0rm
- # weakness of PAGE_GUARD or new Windows bug (XP/Vista 32/64 SP1)
- placing a "hotpatch" where it doesnt belong..
- why Opcode0x90's "dll Injection shield" fails against RtlCreateUserThead
- Pwnie Awards Nominees!!!
- Bypassing Csrss's hold on Terminating Win32Threads..
- Aslan (4514N) - Binary Code Integrator - Okaeri
- Incoming...
- If I had a nickel for every time I had a nickel, I'd have TWO NICKELS
- Dynamic Data Flow Analysis via Virtual Code Integration (aka The SpiderPig case)
- Kon-Boot for USB and some news
- Generic unpacking paper revision
- PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs
- PAPER: Evading network-level emulation
- Blah
- SpiderPig and The Childs.
- SpiderPig Memory Tracer
- Presenting Kon-Boot v1.0
- Some graphs
- # IDA-Pro steals RIP ? introduction in relative addressing
- User-mode debugger with SoftICE UI
- # MS DirectShow MPEG2 (msvidctl.dll) worm was fired out!
- # IDA-Pro//BOCHSDBG plug-in bug: lack of 16bit support
- CallOutRecaptureRoutine and the changes it made
- # Xcon2009: passive non-resident root-kits
- VMprotect VM_logic (in v1.8 demo)
- # die Vista, die or why DEADDEEF is alive?
- A snippet of time.. ;) uneditted ..
- # IDA-Pro 5.5 has been updated, fixed ? Bochs plug-in unaligned PE bug
- # San-Francisco - A Dream Came True
- Native Blocks Pre-Alpha
- Server Handle Table Funtions.
- Ideas and concepts: behind the Sin32 Subsystem
- Bare Bone Client
- Ruby for Pentesters - The Dark Side I: Ragweed
- Server Thread Recycling (Beginings..)
- Current QuickLPC Server Implementation
- Current QuickLPC Client
- Function call graph plugin sample
- My first blog post.(plans for my blog)
- IDA Pro 5.5 and Hex-Rays 1.1 have been released!
- psusp
- Windows 7 RC syscalls
- # a bomb from McAfee (a nasty one)
- IDA Pro 5.5 goes alpha
- VMprotect VM_logic (in v1.8 demo)
- Matasano PFI (as seen on TV!)
- Using CreatePipe to detect and thwart Emulating Sandboxes and AV emulators
- EventPair Reversing, EventPairHandle as Anti-Dbg Trick
- Decompiling floating point
- IDA v5.4 demo
- RtlQueryProcessHeapInformation as Anti-Dbg Trick
- RtlQueryProcessDebugInformation as Anti-Dbg Trick
- Found what is that "long mode segmentation"
- Updated "Class Informer" plug-in
- Debugger tricks: Find all probable CONTEXT records in a crash dump
- Anti-Emulation Tricks
- InfoSec Institute's RE Course
- Examining kernel stacks on Vista/Srv08 using kdbgctrl -td
- VC++ asm intrinsics
- Ruby for Pen-Testers: Announcing Ruby Black Bag
- Netsons killed my Website
- DirecSound Capture With Deviare
- Understanding the kernel address space on 32-bit Windows Vista
- Recovering a process from a hung debugger
- Advanced Windows Kernel Debugging with VMWare and IDA's GDB debugger
- # I’m on my way to South Africa
- # self-replicated processes
- # JL/JGE Intel CPU bug as anti-reversing trick
- # Olly Plug-ins and MS VC
- # Olly loads Olly to bypass anti-attach tricks /* Clerk? trick */
- # anti-attach: BaseThreadStartThunk => NO_ACCESS
- # zombie slam
- # Process Explorer - bloody hell of indefinite waiting bugs
- # NtRequestWaitReplyPort abuses IDA-Pro
- # PRNG based on REP STOS
- # attach to me? if you can (part II)
- # self-overwritten REP STOS/MOVS, IDA-Pro 5.4 and Ko
- # try to attach to me? if you can!
- The IDA Pro book
- Mr. Bachaalany joins Hex-Rays
- Bochs Emulator and IDA?
- IDA Pro has 9 debugger modules
- IDA and MIPS
- BITS used as a covert channel
- Bochs plugin goes alpha
- Blackhat USA 2008
- Apple's variant of ptrace()
Powered by vBulletin® Version 4.1.9 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.