Obsidium 1.5.x.x (Unpacking)
A quick unpacking tutorial covering Obsidium 1.5.x.x builds. Example unpackme file of Obsidium 1.5.2 Build 11 included.
View ArticlePECOFF Revision 11.0
This specification describes the structure of executable (image) files and object files under the Windows family of operating systems. These files are referred to as Portable Executable (PE) and Common...
View ArticleCrackmes.de (2011 - 2015)
Crackmes.de, a site for testing reversing skills. Crackmes range from "Very Easy" to "Very Hard" for many operating systems.Archive contains a 2011 release from Malware Ninja... Well after the...
View ArticleFravias First Period: Reverse Engineering ("Reality Cracking") (1995 - 1999)
My reader, this labyrinth of pages (you'll never be able to count them all :-) contains many teachings, and will help you gain knowledge that you will not find elsewhere. Please wander slowly inside:...
View ArticleFravias Second Period: Web Searching ("Search Lores") (2000 - 2009)
I have opened my www.searchlores.org, in Oz, in February 2000. Searchlores seems fairly popular: I receive on my main site alone an average of (around) a million hits per month, without counting the...
View ArticleThe Immortal Descendants (1997 - 2001)
The Immortal Descendants started out as members of an IRC group on irc.prodigy.net called "Deadmen.Society" way back in 1995. As we gained skills, we realized that there were better, and more...
View ArticleRCE Messageboard's Regroupment (2008 - 2016)
RCE Messageboard's Regroupment, "serious reversing, cracking and programming discussions."Discussion board content archived between 2008 and 2016. Previously hosted at: http://www.woodmann.com/
View ArticleA Practical Cryptanalysis of the Telegram Messaging Protocol
The number one rule for cryptography is never create your own crypto. Instant messaging application Telegram has disregarded this rule and decided to create an original message encryption protocol. In...
View ArticleA Proposal For a Stateless Laptop
Modern Intel x86-based endpoint systems, such as laptops, are plagued by a number of security-related problems. Additionally, with the recent introduction of Intel Management Engine (ME)...
View ArticleCharacterizing Loops in Android Applications
When performing program analysis, loops are one of the most important aspects that needs to be taken into account. In the past, many approaches have been proposed to analyze loops to perform different...
View ArticleContext-Sensitive Analysis of Obfuscated x86 Executables
A method for context-sensitive analysis of binaries that may have obfuscated procedure call and return operations is presented. Such binaries may use operators to directly manipulate stack instead of...
View ArticleControl Flow Graph Based Multiclass Malware Detection Using Bi-normal Separation
Control flow graphs (CFG) and OpCodes extracted from disassembled executable files are widely used for malware detection. Most of the research in static analysis is focused on binary class malware...
View ArticleDe-anonymizing Programmers via Code Stylometry
Source code authorship attribution is a significant privacy threat to anonymous code contributors. However, it may also enable attribution of successful attacks from code left behind on an infected...
View ArticleFactoring RSA Keys With TLS Perfect Forward Secrecy
This report describes the successful factorization of RSA moduli, by connecting to faulty TLS servers which enable forward secrecy and which use an insufficiently hardened RSA-CRT implementation. The...
View ArticleGPU-Disasm - A GPU-based x86 Disassembler
Static binary code analysis and reverse engineering are crucial operations for malware analysis, binary-level software protections, debugging, and patching, among many other tasks. Faster binary code...
View ArticleLooking Inside the (Drop) Box
Dropbox is a cloud based file storage service used by more than 100 million users. In spite of its widespread popularity, we believe that Dropbox as a platform hasn’t been analyzed extensively enough...
View ArticleObfuscation Code Localization Based on CFG Generation of Malware
This paper presents a tool BE-PUM (Binary Emulator for PUshdown Model generation), which generates a precise control flow graph (CFG), under presence of typical obfuscation techniques of malware, e.g.,...
View ArticleOffensive Techniques in Binary Analysis
Finding and exploiting vulnerabilities in binary code is a challenging task. The lack of high-level, semantically rich information about data structures and control constructs makes the analysis of...
View ArticlePreventing Reverse Engineering of Native and Managed Programs
One of the important aspects of protecting software from attack, theft of algorithms, or illegal software use is eliminating the possibility of performing reverse engineering. One common method used to...
View ArticleReversing An Obfuscated Java Malware
Some time in the recent past, I stumbled upon a news on The Intercept, about a malware being used against some Argentine prosecutor, who was found dead under uncanny circumstances (Fig. 1 & 2)....
View Article