corkami.blogspot.com
c..k..i: If you want to strike me down in anger
http://corkami.blogspot.com/2010/02/if-you-want-to-strike-me-down-in-anger.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). If you want to strike me down in anger. Do you understand these snippets? Setz ah setnz cl. Aad 11 xor eax, eax. Add eax,04000f3 mov fs:[eax], esp. Jmp eax ror cl, 01. Let's take a simple example:. If you want to reset ECX and artificially create unneededed computing cycles, you can use. Which just decrements ECX until it's zero. It might take several seconds (! An easy way to hide the conditional jump and...
corkami.blogspot.com
c..k..i: ...Weiß noch nicht, dass er tanzen muss
http://corkami.blogspot.com/2010/07/wei-noch-nicht-dass-er-tanzen-muss.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). Weiß noch nicht, dass er tanzen muss. Just to let you know I updated the Map. Hoping things will be a little more detailed about my various experiments. Petite mise à jour. Simplement pour vous dire que j'ai mis à jour la Carte. En espérant que les choses soient un peu plus claires concernant mes bidouillages. Subscribe to: Post Comments (Atom). There was an error in this gadget. Blackbag, Barry's weblog.
corkami.blogspot.com
c..k..i: March 2010
http://corkami.blogspot.com/2010_03_01_archive.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). If you wanna make the world a better place, take a look at . It can be useful to have a reminder of the most usual packers entry point - especially the light ones, which are likely to be hacked or used as an inner layer. Read more (inclue version française). Quand mes 'elles' se froissent et mes 'ils' se noient. Pages on anti-debuggers and PE oddities. Read more (inclue version française). Which is a criti...
corkami.blogspot.com
c..k..i: January 2010
http://corkami.blogspot.com/2010_01_01_archive.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). It's just a flesh wound. Section-less PE file (updated). You may not expect a PE to be valid without all its standard structure:. Dos Header, Nt Headers, File Header, Optional Header, Data Directories, Section Headers. TinyPE already proved that the Data directories are not compulsory, but also sections are not always required. Read more (inclue version française). A PE Headers graph. Thus, if 2 sections w...
corkami.blogspot.com
c..k..i: July 2011
http://corkami.blogspot.com/2011_07_01_archive.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). Too scared to go to prison, we're unable to make decisions. I still don't have the time to write a decent blog article, but at least, I managed to do a few things since the last post (if you don't follow me on twitter or reddit):. Trying to improve my screencasting methodology, I created a screencast tutorial. On reJava (compare with my previous one. And let me know which one is better). Too scared to go t...
corkami.blogspot.com
c..k..i: April 2010
http://corkami.blogspot.com/2010_04_01_archive.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). Wir halten zusammen, keiner kämpft allein. As I added Data Directories to the PE infographics, my 3 infographics projects are now finished:. Read more (inclue version française). Before you judge me, take a look at you. I created one last diagram, showing Packers most common algorithms. Read more (inclue version française). Si tu cherches un peu de gaîté, viens donc faire un tour à. It makes it much more r...
corkami.blogspot.com
c..k..i: April 2011
http://corkami.blogspot.com/2011_04_01_archive.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). Mireille est une star au fin fond du Tibet. Here are a few things that I released recently but didn't get a regular blog post, just a twitter entry:. V01): a usermode opcode tester, covering most opcodes, including rare, obsolete, recent, undocumented, 64 bits, exception triggers, anti-debugs. (gathering and extending the result of my previous blog entries and programs). I created a simple screencast.
corkami.blogspot.com
c..k..i: vous devez chausser du 48 ou bien mettre des scholls
http://corkami.blogspot.com/2011/09/vous-devez-chausser-du-48-ou-bien.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). Vous devez chausser du 48 ou bien mettre des scholls. As I now prefer to write and update technical documents in my wiki. And notify people via my announcement-only twitter account. Rather than write on this blog, it will be unlikely updated in the future. So, to keep yourself updated, I suggest to check @corkami. If you want to use an RSS reader, you can point it to this address. Qui fonctionne sans probl...
corkami.blogspot.com
c..k..i: September 2011
http://corkami.blogspot.com/2011_09_01_archive.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). Vous devez chausser du 48 ou bien mettre des scholls. As I now prefer to write and update technical documents in my wiki. And notify people via my announcement-only twitter account. Rather than write on this blog, it will be unlikely updated in the future. So, to keep yourself updated, I suggest to check @corkami. If you want to use an RSS reader, you can point it to this address. Subscribe to: Posts (Atom).
corkami.blogspot.com
c..k..i: February 2011
http://corkami.blogspot.com/2011_02_01_archive.html
Reverse engineering experiments and documentations. The most frequently updated page of this blog). I wear my crown of thorns, on my liar's chair. A bit of nostalgia (virii). My first contact with a computer virus was Ping-Pong. Which infected our 10 Mhz 8086. Hopefully, a magazine was giving the solution (for free! They were giving the hex sequence to search and replace! Instant detection, but once again, not exactly the most user friendly! Mais je me lâche la main, je m’éloigne de moi. With a standard ...