1 265
Suscriptores
Sin datos24 horas
-37 días
+730 días
Archivo de publicaciones
1 265
Locals متغیرهای محلی
هر متغیر محلی داخل استک فریم قرار میگیره
مثلا در C:
void f() { int a; int b; int c[10]; }کامپایلر ممکنه این فریم رو بسازه: |--------------------------| | return address | | previous RBP | |--------------------------| | a (4 bytes) | | b (4 bytes) | | padding (align) | | c[10] (40 bytes) | |--------------------------| Saved Registers رجیسترهایی که باید ذخیره بشن طبق ABI سه نوع register داریم: نوعنیاز به ذخیره توسط callee مثال caller-savedنهRAX, RCX, RDX callee-savedبلهRBX, RBP, R12-R15 specialبسته به شرایطRSP پس اگر تابعی مثل این باشه:
void foo() { int a; int b; // uses RBX }کامپایلر باید RBX رو هم داخل فریم ذخیره کنه چون callee-saved هست Spill slots وقتی رجیستر کم میاد اگر تعداد متغیرها زیاد بشه رجیستر کم میاد و کامپایلر مجبور میشه بعضی مقدار ها رو داخل استک بریزه مثلا:
void f(int a, int b, int c, int d, int e, int f) { .... }برای اینا رجیستر کم میاد میرن spill slot روی استک Temporary space فضاهای موقت کامپایلر برای کارهایی مثل call هایی که پارامتر زیاد دارن حافظه موقت روی استک میسازه مثال:
printf("%d %d %d %d", a, b, c, d);ممکنه کامپایلر موقت همه رو داخل استک بچینه Locals Every local variable is placed in a stack frame For example, in C:
void f() { int a; int b; int c[10]; }The compiler may create this frame: |--------------------------| | return address | | previous RBP | |---------------------| | a (4 bytes) | | b (4 bytes) | | padding (align) | | c[10] (40 bytes) | |---------------------| Saved Registers Registers that need to be saved According to the ABI, we have three types of registers: Types that need to be saved by the callee Example caller-saved No RAX, RCX, RDX callee-saved Yes RBX, RBP, R12-R15 special Depending on the RSP conditions So if a function is like this:
void foo() { int a; int b; // uses RBX }The compiler must also store RBX in the frame because it is callee-saved Spill slots when the register runs out If the number of variables increases, the register runs out and the compiler is forced to push some values onto the stack For example:
void f(int a, int b, int c, int d, int e, int f) { .... }For this, the register runs out They go to the spill slot on the stack Temporary space Temporary spaces The compiler creates temporary memory on the stack for tasks such as calls that have many parameters For example:
printf("%d %d %d %d", a, b, c, d);The compiler may temporarily push everything onto the stack @reverseengine
1 265
FlexibleFreet: macOS Malware Deploys in Fake Job Scams
https://www.jamf.com/blog/flexibleferret-malware-continues-to-adapt/
@reverseengine
1 265
File Tunnel
https://github.com/fiddyschmitt/File-Tunnel
Bypassing a firewall:
# Host A
ft.exe -L 5000:127.0.0.1:3389 --write "\\server\share\1.dat" --read "\\server\share\2.dat"
# Host B
ft.exe --read "\\server\share\1.dat" --write "\\server\share\2.dat"
Tunnel TCP through RDP:
# Host A
ft.exe -L 5000:192.168.1.50:8888 --write "C:\Temp\1.dat" --read "C:\Temp\2.dat"
# Host B
ft.exe --read "\\tsclient\c\Temp\1.dat" --write "\\tsclient\c\Temp\2.dat"
@reverseengine1 265
Repost from Fuzzing ZONE
Analysis of Encryption Structure of Yurei Ransomware Go-based Builder
https://asec.ahnlab.com/en/90975/
@FUZZ0x
1 265
HashDB is a free community-sourced library of hashing algorithms used in malware, with an IDA plugin!
API
https://hashdb.openanalysis.net/
IDA Plugin
https://github.com/OALabs/hashdb-ida
Add Custom Algorithms
https://github.com/OALabs/hashdb
@reverseengine
1 265
Binary Ninja 3.0 The Next Chapter (Pseudo C decompile!)
https://binary.ninja/2022/01/27/3.0-the-next-chapter.html
@reverseengine
1 265
Repost from Source Byte
Morphisec Thwarts Russian-Linked StealC V2 Campaign Targeting Blender Users via Malicious .blend Files
https://www.morphisec.com/blog/morphisec-thwarts-russian-linked-stealc-v2-campaign-targeting-blender-users-via-malicious-blend-files/
1 265
A Linux eBPF rootkit with a backdoor C2 library injection execution hijacking persistence and stealth capabilities
https://github.com/h3xduck/TripleCross
@reverseengine
1 265
Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)
https://github.com/memN0ps/bootkit-rs
@reverseengine
1 265
LayeredSyscall – Abusing VEH to Bypass EDRs
https://whiteknightlabs.com/2024/07/31/layeredsyscall-abusing-veh-to-bypass-edrs
@reverseengine
1 265
DJI - The ART of obfuscation
https://blog.quarkslab.com/dji-the-art-of-obfuscation.html
@reverseengine
1 265
Debugging and Reversing ALPC
https://csandker.io/2022/05/29/Debugging-And-Reversing-ALPC.html
@reverseengine
1 265
FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares
https://github.com/FirmWire/FirmWire
@reverseengine
1 265
From Windows drivers to a almost fully working EDR
https://blog.whiteflag.io/blog/from-windows-drivers-to-a-almost-fully-working-edr/
@reverseengine
