es
Feedback
ReverseEngineering

ReverseEngineering

Ir al canal en Telegram
1 265
Suscriptores
Sin datos24 horas
-37 días
+730 días
Archivo de publicaciones
📣 Introducing ICRev v1.0 🔻 Our new tool for tunneling via ICMP and establishing encrypted reverse-shell — built with Go and no external dependencies. Key features: ‏AES-256-CBC: All payloads are encrypted and each packet is generated with a unique IV to prevent predictable patterns. ‏HMAC-SHA256: Ensures data integrity and authenticity, prevents packet forgery and replay attacks. No external dependencies: Fully self-contained with the Go standard library, reducing footprint and increasing portability. Server and agent modes with Jitter and Heartbeat: Suitable for long-term and stealthy operations. Use ICMP: Bypass network limitations and reduce the likelihood of detection by IDS/IPS, without the need for open ports. Why ICMP? ICMP traffic is similar to regular network activity (ping), so it is more difficult to detect. Ability to transfer small data for sending commands or exfiltration without requiring specific ports. Full details on installation, server and agent implementation, and access points are available in the GitHub README. 👁‍🗨 Github 💬 Forum 📣 DarkBit

Repost from DarkBit
📣 معرفی ICRev v1.0 🔻 ابزار جدید ما برای تونلینگ از طریق ICMP و برقراری reverse‑shell رمزنگاری‌شده — ساخته‌شده با Go و بدون وابستگی خارجی. ویژگی‌های کلیدی:
‏AES-256-CBC: تمامی payloadها رمزنگاری می‌شوند و هر پکت با IV منحصربه‌فرد تولید می‌شود تا الگوهای قابل پیش‌بینی ایجاد نشود. ‏HMAC-SHA256: تضمین یکپارچگی و اصالت داده‌ها، جلوگیری از جعل بسته‌ها و حملات replay. بدون وابستگی خارجی: کاملاً self-contained با کتابخانه استاندارد Go، کاهش footprint و افزایش قابلیت حمل. حالت‌های سرور و ایجنت با Jitter و Heartbeat: برای عملیات طولانی‌مدت و مخفیانه مناسب است. استفاده از ICMP: عبور از محدودیت‌های شبکه و کاهش احتمال شناسایی توسط IDS/IPS، بدون نیاز به پورت باز. چرا ICMP؟ ترافیک ICMP مشابه فعالیت‌های شبکه‌ای معمول (ping) است، بنابراین شناسایی آن دشوارتر است. امکان انتقال داده‌های کوچک برای ارسال دستورات یا exfiltration بدون نیاز به پورت‌های خاص.
تمام جزئیات نصب، اجرای سرور و ایجنت، و نکات مربوط به دسترسی‌ها در README گیت‌هاب موجود است. 👁‍🗨 Github 💬 Forum 📣 DarkBit

جریان اصلی وقتی یک تابع صدا زده میشه:
1️⃣ call func آدرس بعد از call (return address) پوش میشه رو استک 2️⃣ داخل تابع: RBP ذخیره میشه فریم استک ساخته میشه 3️⃣ متغیرها آرگومان‌ ها استفاده میشن 4️⃣ leave → فریم قدیمی برگردونده میشه 5️⃣ ret → caller برگشت به
The basic flow when a function is called:
1️⃣ call func The address after the call (return address) is pushed onto the stack 2️⃣ Inside the function: RBP is saved A stack frame is created 3️⃣ Variables and arguments are used 4️⃣ leave → Old frame is returned 5️⃣ ret → caller returns to
@reverseengine

پلاگین GhidraGPT یک پلاگین قدرتمند برای Ghidra که مدل‌های زبانی بزرگ (LLMs) را برای ارتقا فرآیند مهندسی معکوس به کار می‌گیرد و تحلیل و بهبود کد را هوشمندانه‌تر می‌کند. ویژگی‌ها: بهبود کد: تغییر نام توابع و متغیرها با کمک AI برای افزایش خوانایی توضیح کد: ارائه تحلیل دقیق از منطق و عملکرد توابع تحلیل امنیتی: شناسایی آسیب‌پذیری‌ها و بررسی مسائل امنیتی پشتیبانی چندگانه: سازگار با بیش از ۸ ارائه‌دهنده شامل OpenAI، Anthropic، Google Gemini، Cohere، Mistral AI، DeepSeek، Grok (xAI) GhidraGPT Plugin A powerful plugin for Ghidra that leverages Large Language Models (LLMs) to enhance the reverse engineering process and make code analysis and improvement smarter. Features: Code Optimization: AI-assisted renaming of functions and variables to increase readability Code Explanation: Provides detailed analysis of function logic and performance Security Analysis: Identify vulnerabilities and investigate security issues Multiple Support: Compatible with 8+ providers including OpenAI, Anthropic, Google Gemini, Cohere, Mistral AI, DeepSeek, Grok (xAI) and 🦅 Safe Byte Channel | Safe Byte Group #Tools 🦅 کانال بایت امن | گروه بایت امن

Some Sources Related to Reverse Engineering https://github.com/alphaSeclab/awesome-reverse-engineering

🔴 معرفی پروژه ی RE-Architect این پروژه یک پلتفرم خودکار و پیشرفته برای مهندسی معکوس هستش و دارای ویژگی های مانند: - فایلهای باینری رو میتونه دیکامپایل و تحلیل کنه. - خلاصه ای از رفتار توابع رو با استفاده از مدلهای یادگیری زبان در میاره. - ساختار داده های پیچیده رو شناسایی و بازسازی میکنه. - نمایش گرافیکی قابل پیکربندی داره. - از دیکامپایلرهای IDA Pro , Ghidra و Binary Ninja پشتیبانی میکنه. - قابل ‌اجرا روی Windows، Linux، و macOS هستش. - امکان ایجاد کد Test Harness رو داره. ( قابلیتی که میتونیم یک تابع رو بدون اجرای کل برنامه، تست کنیم. معمولا در مباحث فازینگ کاربرد داره). - در پایتون توسعه داده شده. 🔴 Introducing the RE-Architect project This project is an automated and advanced reverse engineering platform and has features such as: - Can decompile and analyze binary files. - Summarizes the behavior of functions using language learning models. - Recognizes and reconstructs complex data structures. - Has a configurable graphical display. - Supports IDA Pro, Ghidra, and Binary Ninja decompilers. - Runs on Windows, Linux, and macOS. - Has the ability to create Test Harness code. (A feature that allows us to test a function without running the entire program. Usually used in fuzzing topics). - Developed in Python. #مهندسی_معکوس #ReverseEngineering #REArchitect 🆔 @onhex_ir ➡️ ALL Link

Repost from Network Security
FREE reverse engineering module now available! Learn assembly fundamentals - perfect for beginners. • Hands-on debugging with real examples • Web based: no downloads, installs, or VMs Start reversing here 👇 https://www.aceresponder.com/learn/rem-intro