{"id":733,"date":"2014-02-27T00:27:04","date_gmt":"2014-02-27T00:27:04","guid":{"rendered":"http:\/\/www.gironsec.com\/blog\/?p=733"},"modified":"2014-03-18T00:11:12","modified_gmt":"2014-03-18T00:11:12","slug":"mcafee-bup-file-decrypt-er-update","status":"publish","type":"post","link":"https:\/\/www.gironsec.com\/blog\/2014\/02\/mcafee-bup-file-decrypt-er-update\/","title":{"rendered":"McAfee BUP File decrypt-er update"},"content":{"rendered":"<p>Howdy all!<\/p>\n<p>Time for an update. Today I went through and re-did my McAfee BUP file decrypt-er thingy. I got rid of the guy with sunglasses, modified the decryption sequence to cut off the first 2048 junk bytes, added drag-n-drop capabilities, and added a hex view.<\/p>\n<p>Old:<br \/>\n<a href=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2014\/02\/oldeee.png\"><img decoding=\"async\" loading=\"lazy\" src=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2014\/02\/oldeee.png\" alt=\"oldeee\" width=\"307\" height=\"426\" class=\"alignnone size-full wp-image-734\" srcset=\"https:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2014\/02\/oldeee.png 307w, https:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2014\/02\/oldeee-216x300.png 216w\" sizes=\"(max-width: 307px) 100vw, 307px\" \/><\/a><\/p>\n<p>New:<br \/>\n<a href=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2014\/02\/neweeeee.png\"><img decoding=\"async\" loading=\"lazy\" src=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2014\/02\/neweeeee.png\" alt=\"neweeeee\" width=\"613\" height=\"545\" class=\"alignnone size-full wp-image-735\" srcset=\"https:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2014\/02\/neweeeee.png 613w, https:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2014\/02\/neweeeee-300x266.png 300w\" sizes=\"(max-width: 613px) 100vw, 613px\" \/><\/a><\/p>\n<p>I guess this looks more professional. You can download it <a href=\"http:\/\/gironsec.com\/code\/Joes_BUP_File_Viewer.7z\" title=\"here\" target=\"_blank\">here<\/a>.<\/p>\n<p>As for other projects, I am continuing my memory analysis work with python, am going to be giving a malware analysis workshop at <a href=\"http:\/\/www.cactuscon.com\/\" title=\"CactusCon\" target=\"_blank\"><\/a>, and I&#8217;m thinking of developing something new. Something lucrative. <\/p>\n<p>Anywho, happy hacking!<br \/>\nEdited to to censorship<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Howdy all! Time for an update. Today I went through and re-did my McAfee BUP file decrypt-er thingy. I got rid of the guy with sunglasses, modified the decryption sequence to cut off the first 2048 junk bytes, added drag-n-drop capabilities, and added a hex view. Old: New: I guess this looks more professional. You [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[4],"tags":[89],"_links":{"self":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/733"}],"collection":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/comments?post=733"}],"version-history":[{"count":3,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/733\/revisions"}],"predecessor-version":[{"id":760,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/733\/revisions\/760"}],"wp:attachment":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/media?parent=733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/categories?post=733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/tags?post=733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}