fa
Feedback
ReverseEngineering

ReverseEngineering

رفتن به کانال در Telegram
1 265
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-37 روز
+730 روز
آرشیو پست ها
Locals متغیرهای محلی هر متغیر محلی داخل استک فریم قرار میگیره مثلا در C:
void f() {     int a;     int b;     int c[10]; }
کامپایلر ممکنه این فریم رو بسازه: |--------------------------| |  return address          | |  previous RBP            | |--------------------------| |  a (4 bytes)             | |  b (4 bytes)             | |  padding (align)         | |  c[10] (40 bytes)        | |--------------------------| Saved Registers  رجیسترهایی که باید ذخیره بشن طبق ABI سه نوع register داریم: نوعنیاز به ذخیره توسط callee مثال caller-savedنهRAX, RCX, RDX callee-savedبلهRBX, RBP, R12-R15 specialبسته به شرایطRSP پس اگر تابعی مثل این باشه:
void foo() {     int a;     int b;     // uses RBX }
کامپایلر باید RBX رو هم داخل فریم ذخیره کنه چون callee-saved هست Spill slots  وقتی رجیستر کم میاد اگر تعداد متغیرها زیاد بشه رجیستر کم میاد و کامپایلر مجبور میشه بعضی مقدار ها رو داخل استک بریزه مثلا:
void f(int a, int b, int c, int d, int e, int f) {       ....   }
برای اینا رجیستر کم میاد میرن spill slot روی استک Temporary space فضاهای موقت کامپایلر برای کارهایی مثل call هایی که پارامتر زیاد دارن حافظه موقت روی استک میسازه مثال:
printf("%d %d %d %d", a, b, c, d);
ممکنه کامپایلر موقت همه رو داخل استک بچینه Locals Every local variable is placed in a stack frame For example, in C:
void f() { int a; int b; int c[10]; }
The compiler may create this frame: |--------------------------| | return address | | previous RBP | |---------------------| | a (4 bytes) | | b (4 bytes) | | padding (align) | | c[10] (40 bytes) | |---------------------| Saved Registers Registers that need to be saved According to the ABI, we have three types of registers: Types that need to be saved by the callee Example caller-saved No RAX, RCX, RDX callee-saved Yes RBX, RBP, R12-R15 special Depending on the RSP conditions So if a function is like this:
void foo() { int a; int b; // uses RBX }
The compiler must also store RBX in the frame because it is callee-saved Spill slots when the register runs out If the number of variables increases, the register runs out and the compiler is forced to push some values ​​onto the stack For example:
void f(int a, int b, int c, int d, int e, int f) { .... }
For this, the register runs out They go to the spill slot on the stack Temporary space Temporary spaces The compiler creates temporary memory on the stack for tasks such as calls that have many parameters For example:
printf("%d %d %d %d", a, b, c, d);
The compiler may temporarily push everything onto the stack @reverseengine

FlexibleFreet: macOS Malware Deploys in Fake Job Scams https://www.jamf.com/blog/flexibleferret-malware-continues-to-adapt/ @reverseengine

File Tunnel https://github.com/fiddyschmitt/File-Tunnel Bypassing a firewall: # Host A ft.exe -L 5000:127.0.0.1:3389 --write "\\server\share\1.dat" --read "\\server\share\2.dat" # Host B ft.exe --read "\\server\share\1.dat" --write "\\server\share\2.dat" Tunnel TCP through RDP: # Host A ft.exe -L 5000:192.168.1.50:8888 --write "C:\Temp\1.dat" --read "C:\Temp\2.dat" # Host B ft.exe --read "\\tsclient\c\Temp\1.dat" --write "\\tsclient\c\Temp\2.dat" @reverseengine

Repost from Fuzzing ZONE
Analysis of Encryption Structure of Yurei Ransomware Go-based Builder https://asec.ahnlab.com/en/90975/ @FUZZ0x

MaldevAcademyLdr.2 RunPE implementation with multiple evasive techniques @reverseengine

HashDB is a free community-sourced library of hashing algorithms used in malware, with an IDA plugin! API https://hashdb.openanalysis.net/ IDA Plugin https://github.com/OALabs/hashdb-ida Add Custom Algorithms https://github.com/OALabs/hashdb @reverseengine

A graphical tool to visualize binary data https://github.com/sharkdp/binocle @reverseengine

Binary Ninja 3.0 The Next Chapter (Pseudo C decompile!) https://binary.ninja/2022/01/27/3.0-the-next-chapter.html @reverseengine

Repost from Source Byte
Morphisec Thwarts Russian-Linked StealC V2 Campaign Targeting Blender Users via Malicious .blend Files https://www.morphisec.com/blog/morphisec-thwarts-russian-linked-stealc-v2-campaign-targeting-blender-users-via-malicious-blend-files/

Repost from N/a
Part 0ne Part TW0 #shellcode #PIC

A Linux eBPF rootkit with a backdoor C2 library injection execution hijacking persistence and stealth capabilities https://github.com/h3xduck/TripleCross @reverseengine

Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus) https://github.com/memN0ps/bootkit-rs @reverseengine

Titan is a VMProtect devirtualizer https://github.com/archercreat/titan @reverseengine

FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares https://github.com/FirmWire/FirmWire @reverseengine