Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #3  
Old 04-22-2004, 19:29
Zigmund Zigmund is offline
Friend
 
Join Date: May 2002
Posts: 24
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 2
Thanks Rcvd at 3 Times in 3 Posts
Zigmund Reputation: 0
nice example... ;)

As you said 'IDA can correctly handle this most of the time'...
That's the main goal of obfuscation - prevent disassembling... But IDA in use of skilled reverser can give very good results in suche way (example you gave)...

Simpliest way (as for me) is to change outputed .asm listing of compilled program and parse it. Hardest and more professional methods : write you own translator and write VirtualMachine.

I'll describe JUNKs technique (one of the sipliest):

we have some asm listing:
--
$L8547:
mov eax, 1
Junk1
test eax, eax
je $L8548
Junk2
mov ecx, DWORD PTR [ebp-64]
mov dl, BYTE PTR [ecx+3]
or dl, 128
--
and Junk1(2) are macroses like:

Junk1 macro
local @@y
jmp @@y
db 0BCh
@@y:
endm

Junk2 macro
local @@1, @@2
push offset @@1
ret
db 069h
@@1:
push offset @@2
ret
db 0E8h
@@2:
endm

db 069h, E8h, BCh... etc - opcodes of long instructions

MOst of times IDA displays real JUNK in disasm

Any other methods? Or tools?!
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Tools For NET ASSEMBLY wilson bibe General Discussion 11 06-03-2013 11:39
Introduction to x64 Assembly Git x64 OS 11 01-03-2011 17:48
Assembly ... these might be useful to someone yaa General Discussion 6 04-28-2005 18:17


All times are GMT +8. The time now is 11:38.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )