Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 11-30-2013, 17:03
ragdog ragdog is offline
Friend
 
Join Date: Feb 2011
Posts: 56
Rept. Given: 2
Rept. Rcvd 25 Times in 7 Posts
Thanks Given: 9
Thanks Rcvd at 8 Times in 5 Posts
ragdog Reputation: 25
Obfuscate code

Hello

I have a KeygenMe with a big obfuscate code
Gives any good tools to deobfuscate this code?

What is your experience with Ida plugin "Codedoctor"?
Or use you other plugins or tools?

Regards,
Reply With Quote
  #2  
Old 11-30-2013, 17:19
sendersu sendersu is offline
VIP
 
Join Date: Oct 2010
Posts: 1,067
Rept. Given: 332
Rept. Rcvd 223 Times in 115 Posts
Thanks Given: 235
Thanks Rcvd at 512 Times in 288 Posts
sendersu Reputation: 200-299 sendersu Reputation: 200-299 sendersu Reputation: 200-299
Quote:
Originally Posted by ragdog View Post
Hello

I have a KeygenMe with a big obfuscate code
Gives any good tools to deobfuscate this code?

What is your experience with Ida plugin "Codedoctor"?
Or use you other plugins or tools?

Regards,
Whats your target language?
native Intel x32/x64
java
.net
etc?
Reply With Quote
  #3  
Old 11-30-2013, 17:58
ragdog ragdog is offline
Friend
 
Join Date: Feb 2011
Posts: 56
Rept. Given: 2
Rept. Rcvd 25 Times in 7 Posts
Thanks Given: 9
Thanks Rcvd at 8 Times in 5 Posts
ragdog Reputation: 25
Microsoft Visual C++ x32
Reply With Quote
  #4  
Old 11-30-2013, 21:18
sendersu sendersu is offline
VIP
 
Join Date: Oct 2010
Posts: 1,067
Rept. Given: 332
Rept. Rcvd 223 Times in 115 Posts
Thanks Given: 235
Thanks Rcvd at 512 Times in 288 Posts
sendersu Reputation: 200-299 sendersu Reputation: 200-299 sendersu Reputation: 200-299
The subject is not wellcovered by tools, so you could even write yourself one

some materials...
https://www.hex-rays.com/products/ida/support/ppt/caro_obfuscation.ppt
http://recon.cx/2008/a/eric_d_lapse/Deobfuscator_RECON2008.ppt

optimice Deobfuscation plugin for IDA
http://code.google.com/p/optimice/

Simple Deobfuscation of Code Transformation
http://hooked-on-mnemonics.blogspot.com/2012/10/simple-deobfuscation-of-code.html

IDA Plugin deofuscator plugin
http://www.openrce.org/forums/posts/1915

Ariadne Deobfuscation Technology (IDA/Olly plugins)
http://ariadne.group-ib.ru/en/about
or here http://www.woodmann.com/collaborative/tools/index.php/Ariadne

Attacking Obfuscated code with Ida Pro
http://www.blackhat.com/presentations/bh-usa-04/bh-us-04-eagle.pdf

Code doctor plugin has some deobfuscating features
http://www.woodmann.com/collaborative/tools/index.php/CodeDoctor


lots of cool IDA plugins coudl be found in contests by years
https://www.hex-rays.com/contests/index.shtml

......
Reply With Quote
  #5  
Old 12-01-2013, 04:05
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
Quote:
Originally Posted by ragdog View Post
Hello

I have a KeygenMe with a big obfuscate code
Gives any good tools to deobfuscate this code?

What is your experience with Ida plugin "Codedoctor"?
Or use you other plugins or tools?

Regards,
Obfuscated or encrypted or VM?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
x86 Code Virtualizer (Code Obfuscator) Gladiyator Source Code 1 09-04-2020 16:51
VB6 N-CODE - Stop any servive and Start any APP-Release and Source Code wilson bibe General Discussion 5 04-10-2013 00:23
Code to efficiently break on entering code section??? yaa General Discussion 4 05-08-2005 05:29


All times are GMT +8. The time now is 16:22.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )