Skip to content

Joe's Security Blog

Month: December 2013

Merry F’in Christmas to you too buddy!

So here I am at work on Christmas Eve (because I have no soul) and the malware is insulting me. See it? Fuck you too buddy! And in another one, to be an asshole, they embedded their program in another program. I was wondering why IDA was showing a stub program less than 5 kb […]

December 25, 2013 averagejoe reversingLeave a comment

Other AntiDebug tricks

I came across this one individual’s page whom is an avid reverse engineer with some great material. Check out his pdf cheat sheet on anti-debugging. There were a few in there I didn’t know about like the ‘csr’ trick which involves calling an undocumented ‘CsrGetProcessId’ function within OpenProcess. CsrGetProcessId is a native API that returns […]

December 23, 2013December 23, 2013 averagejoe code, reversingLeave a comment

0day Wednesday – Newish Malware That Came Across My Desk

Some may say this is crazy, I call it Wednesday. This came across my desk yesterday and I worked it out today. It came as the payload following a java exploit from an old 2012 CVE (SecurityManager one I think). I’m calling it 0day because there were no listing for the exe in VirusTotal / […]

December 19, 2013December 19, 2013 averagejoe cracking, reversingLeave a comment

Writing your own windows debugger in C

Hello all! I’m cracking away on various projects and trying to keep focus. As I was going through my old notes, I came across a talk I wanted to give but could not due to my car accident and the subsequent down time caused me to forget. I wanted to cover making your own debugger […]

December 9, 2013December 9, 2013 averagejoe code, reversingLeave a comment
Blogroll
  • CG – Christ Gates
  • MadMouse
  • RageStorm
Find It

Home

December 2013
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
3031  
« Nov   Jan »

Proudly powered by WordPress | Theme: Sweetheat by aThemes

Top