View Full Version : Blogs Forum
- Hex-Rays Plugin Contest
- Win32k.SYS system call table
- KiTrap06(#UD)
- Using MATLAB and Mathcad for solving (mesh current) equations.
- Unexported SSDT functions finding method
- Elevation of Privilege DLL Patcher
- Hex-Rays is hiring
- Filter Monitor 1.0.1
- Hex-Rays Decompiler primer
- Structure Recovery as Counter-Example Guided Abstraction Refinement
- Controlling Windows process list, part 1
- Telewizor, meble, ma?y fiat
- SEH Graph
- SMB2: 351 Packets from the Trampoline released!
- 351 Packets from the Trampoline
- TraceHook v0.0.2
- Device Drivers Vulnerability Research, Avast a real case
- Finding instructions
- An attempt to reconstruct the call stack
- VMware CloudBurst - VMware Guest to Host Escape Exploit
- C++ Method Constness
- Develop your master boot record and debug it with IDA Pro and the Bochs debugger plug
- Code Release page
- Viewer for driver dispatch tables
- Binary-Auditing Solutions.
- Recent conferences’ reports
- DllMain and its uncovered possibilites
- The incoming SecDay conference
- Suspending processes in Windows, part 1
- TraceHook v0.0.1 release
- Hello world!
- Process termination issues
- Extending Total Commander with some minor functionality
- "Client" Unit Tests(some fun ones..)Indirect RtlCreateUserThread hooking..
- Several Common Ways That Viruses Spread
- VMware ring3 detection (RF handling)
- Javascript for IDA Pro
- News
- Sorry its taking so long on the next release of source..
- Casts are bad
- (In My fucked up way Of thinking...)
- # faked Adobe PDF.SWF exploit on milw0rm
- # weakness of PAGE_GUARD or new Windows bug (XP/Vista 32/64 SP1)
- placing a "hotpatch" where it doesnt belong..
- why Opcode0x90's "dll Injection shield" fails against RtlCreateUserThead
- Pwnie Awards Nominees!!!
- Bypassing Csrss's hold on Terminating Win32Threads..
- Aslan (4514N) - Binary Code Integrator - Okaeri
- PAPER: Evading network-level emulation
- Generic unpacking paper revision
- Kon-Boot for USB and some news
- Some graphs
- PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs
- Dynamic Data Flow Analysis via Virtual Code Integration (aka The SpiderPig case)
- If I had a nickel for every time I had a nickel, I'd have TWO NICKELS
- Incoming...
- Blah
- SpiderPig and The Childs.
- SpiderPig Memory Tracer
- Presenting Kon-Boot v1.0
- # IDA-Pro steals RIP ? introduction in relative addressing
- User-mode debugger with SoftICE UI
- # MS DirectShow MPEG2 (msvidctl.dll) worm was fired out!
- # IDA-Pro//BOCHSDBG plug-in bug: lack of 16bit support
- CallOutRecaptureRoutine and the changes it made
- # Xcon2009: passive non-resident root-kits
- VMprotect VM_logic (in v1.8 demo)
- # die Vista, die or why DEADDEEF is alive?
- A snippet of time.. ;) uneditted ..
- # IDA-Pro 5.5 has been updated, fixed ? Bochs plug-in unaligned PE bug
- # San-Francisco - A Dream Came True
- Native Blocks Pre-Alpha
- Server Handle Table Funtions.
- Ideas and concepts: behind the Sin32 Subsystem
- Bare Bone Client
- Ruby for Pentesters - The Dark Side I: Ragweed
- Server Thread Recycling (Beginings..)
- Current QuickLPC Server Implementation
- Current QuickLPC Client
- Function call graph plugin sample
- My first blog post.(plans for my blog)
- IDA Pro 5.5 and Hex-Rays 1.1 have been released!
- psusp
- Windows 7 RC syscalls
- # a bomb from McAfee (a nasty one)
- IDA Pro 5.5 goes alpha
- VMprotect VM_logic (in v1.8 demo)
- Matasano PFI (as seen on TV!)
- Using CreatePipe to detect and thwart Emulating Sandboxes and AV emulators
- EventPair Reversing, EventPairHandle as Anti-Dbg Trick
- Decompiling floating point
- IDA v5.4 demo
- RtlQueryProcessHeapInformation as Anti-Dbg Trick
- RtlQueryProcessDebugInformation as Anti-Dbg Trick
- Found what is that "long mode segmentation"
- Updated "Class Informer" plug-in
- Debugger tricks: Find all probable CONTEXT records in a crash dump
- Anti-Emulation Tricks
- InfoSec Institute's RE Course
- Examining kernel stacks on Vista/Srv08 using kdbgctrl -td
- VC++ asm intrinsics
- Ruby for Pen-Testers: Announcing Ruby Black Bag
- Netsons killed my Website
- DirecSound Capture With Deviare
- Understanding the kernel address space on 32-bit Windows Vista
- Recovering a process from a hung debugger
- Advanced Windows Kernel Debugging with VMWare and IDA's GDB debugger
- # I’m on my way to South Africa
- # self-replicated processes
- # JL/JGE Intel CPU bug as anti-reversing trick
- # Olly Plug-ins and MS VC
- # Olly loads Olly to bypass anti-attach tricks /* Clerk? trick */
- # anti-attach: BaseThreadStartThunk => NO_ACCESS
- # zombie slam
- # Process Explorer - bloody hell of indefinite waiting bugs
- # NtRequestWaitReplyPort abuses IDA-Pro
- # PRNG based on REP STOS
- # attach to me? if you can (part II)
- # self-overwritten REP STOS/MOVS, IDA-Pro 5.4 and Ko
- # try to attach to me? if you can!
- Mr. Bachaalany joins Hex-Rays
- The IDA Pro book
- BITS used as a covert channel
- Bochs plugin goes alpha
- Bochs Emulator and IDA?
- IDA Pro has 9 debugger modules
- IDA and MIPS
- Blackhat USA 2008
- Apple's variant of ptrace()
- Recon2008
- Testing debuggers
- From simple to complex
- Kernel debugging with IDA
- Bridge them all
- # IDA-Pro 5.4: old bugs on the new streets (was: to download or to not download)
- # RE course in Tel-Aviv
- Playstation3 / PS3 - Harddisk encryption
- S7 airlines is under attack!
- # simple OllyScript for upx
- # PatchDiff => Hex-Rays => WinDiff: how to analyze patches faster
- # Baghdad - dead alive breakpoints
- Class Informer IDA plug-in
- Windows 7 syscall list
- IDA v5.4 release is not that far away
- Windows 7 kernel structures
- # shell-codes analysis: where is EP?
- x64 SEH & Explorer Suite Update
- # FreeLibrary bug becomes a PE packers bug
- San-Francisco - the place to meet
- # MS VC - challenge for PE packers
- Unpinning Imported .dll's
- # 3 lines C-prog hurts MS VC
- # chilly suspicions of new win32 bug
- Malware: Unpacking Waledac
- # dynamic TLS callbacks instead of SEH
- # IDA-Pro and simple (E)SP hack
- # GetProcessDEPPolicy for XP/XP SP2
- NtSetDebugFilterState as Anti-Dbg Trick
- # TLS callbacks w/o USER32 (part III)
- # TLS callbacks w/o USER32 (part II)
- # another EnableTracing() bug
- how powerful IDA Script might be
- # IDA-Pro EnableTracing() - how not to do
- # XP/S2K3 fails to process TLS w/o USER32
- IDA and TLS callbacks
- # DS/FS is under hardware breakpoints
- blog was moved
- Guidelines to MFC reversing
- IOCTL-Proxy
- Dynamic C++ Proposal
- Command line version of OSR's DeviceTree
- Backdoor.Win32.UltimateDefender Reverse Engineering
- Switch as Binary Search, Part 1
- Switch as Binary Search, Part 0
- Qt Internals & Reversing
- CVE-2006-5758: better late than ever
- Malware and initial stack pointer value
- Shared object injection on linux/unix
- Bagle.W IDB
- Trojan.Zhelatin.pk
- Hotpatching MS08-067
- On Analysis of Client-Server Software Applications
- Analyzing local privilege escalations in win32k
- Exploiting Tomorrow's Internet Today: Penetration testing with IPv6
- Can you find me now? Unlocking the Verizon Wireless xv6800 (HTC Titan) GPS
- VbPython 1.2a
- examples of the syllabuses
- Using dual-mappings to evade automated unpackers
- Interesting Kernel32 Constant
- Analyzing Malicious PDF's
- The Wild World of VoIP
- RE-courses/conferences schedule
- custom gpa spy
- Debugger Detection Via NtSystemDebugControl
- POP SS and Debuggers
- Fighting Oreans' VM (code virtualizer flavour)
- PEiD imports parsing DoS
- Nucleus Framework
- SoftICE and KDExtensions
- IDA2PAT Reloaded
- Black Hat 2008 Wrap-up
- VMProtect, Part 0: Basics
- Part 2: Introduction to Optimization
- Part 1: Bytecode and IR
- Part 3: Optimizing and Compiling
- Inside DeleteFiber() as Anti Debug Trick
- Something different part 3, or not quite different
- Why hooking system services is more difficult (and dangerous) than it looks
- Inside SetUnhandledExceptionFilter
- Small Devices & RCE
- IDA on iPhone
- SymbolFinder
- Sun VirtualBox Disassembler Explantation
- CartellaUnicaTasse.exe Italian Malware RCE Analysis
- Why is secure development so important?
- pde/pte softice plugin
- Funny coded malware
- antisptd
- IceProbe - SoftIce Command Tracer
- build rule for x64 asm
- nonintrusive tracer on x64
- My "Unofficial" ReCon Video
- Strong-Name Signing, AdmiralDebilitate v0.1
- IDA Pro Development Environment
- Control Flow Deobfuscation Part 3
- Vmware snapshot and SSDT
- Phoenix Protector 1.3.0.1
- .NET Internals and Native Compiling
- Fujitsu 3D Shock Sensor Application Reversing
- An Introduction To .NET Reversing
- IDA and vmread/vmwrite x64
- Intel VT and cpuid break
- Downloader.Win32.Small or Win32/PolyCrypt Reversing
- #773: bug in IDA-Pro [fails to debug zero-based PE]
- "Function String Associate" IDA Plug-in
- # bug in Process Explorer (a gift for malware)
- # thinking in IDA Pro - how to obtain a copy
- # bug in Olly, Windows behavior and Peter Ferrie
- # free IDA-Pro training
- # turbo-import [stealth anti-api-monitors style]
- # old CD 03 bug in windows
- # other solutions: how to load two or more files into the same IDA-Pro database
- # how to load two or more files into single IDA Pro database
- # Syser causes BSOD
- # eternal life, ammo, scores in games
- .NET Internals and Code Injection
- D3DLookingGlass v0.1
- DisasMSIL and CFF Explorer
- Retsaot is Toaster, Reversed: Quick 'n Dirty Firmware Reversing
- A brief discussion of Windows Vista’s IE Protected Mode (and user/process level secur
vBulletin® v3.8.2, Copyright ©2000-2009, Jelsoft Enterprises Ltd.