Log in

View Full Version : Blogs Forum


Pages : 1 2 [3] 4

  1. Beware of stack usage with the new network stack in Windows Vista (0 replies)
  2. Activating process servers and connecting to them (0 replies)
  3. Remote debugging with process servers (dbgsrv) (0 replies)
  4. Reverse debugging -server and -remote (0 replies)
  5. Win32 calling conventions: __thiscall in assembler (0 replies)
  6. Overview of WinDbg remote debugging (0 replies)
  7. Win32 calling conventions: __stdcall in assembler (0 replies)
  8. Win32 calling conventions: Concepts (0 replies)
  9. Remote debugging with kdsrv.exe (0 replies)
  10. Remote debugging review (0 replies)
  11. Win32 calling conventions: __fastcall in assembler (2 replies)
  12. Ollydbg v1.10 and 6E/6F/A6 opcodes, a little oversight (1 replies)
  13. Securing -server and -remote remote debugging sessions (0 replies)
  14. Remote debugging with -server and -remote (0 replies)
  15. Remote debugging with KD and NTSD (0 replies)
  16. Remote debugging with remote.exe (0 replies)
  17. Win32 calling conventions: Usage cases (0 replies)
  18. Win32 calling conventions: __cdecl in assembler (0 replies)
  19. Tracing Over System Calls In OllyDbg (16 replies)
  20. DynLogger (13 replies)
  21. Some functions are neater than the decompiler thinks (0 replies)
  22. Self-modifying TLS callbacks (4 replies)
  23. Symbian debugger (0 replies)
  24. Trojan-PSW.Win32.OnLineGames.eos Reversing (0 replies)
  25. Compiler 1, X86 Virtualizer 0 (2 replies)
  26. IDA disasms reserved opcodes, is it a bug? (3 replies)
  27. Weird export forwarding thanks to Vista x64 SP1 (3 replies)
  28. Symbian AppTRK (0 replies)
  29. Inside Session 0 Isolation and the UI Detection Service - Part 2 (0 replies)
  30. Process Memory Dumper for Credentials Disclosure Vulns (2 replies)
  31. Cross Your T's and Dot Your Filenames (0 replies)
  32. Hello Symbian! (0 replies)
  33. (Part 2 of .NET native exe insights)Serial fishing and patching .NET exes with Ollydb (9 replies)
  34. Rebuilding native .NET exes into managed .NET exes by Exploiting lefotver IL... (6 replies)
  35. Some Quick Insights Into Native .NET exe's (part 1 of?) (7 replies)
  36. Reverse Engineering Position- TS/SCI Required (12 replies)
  37. Symbol Type Viewer 32Bit/64Bit v1.0.0.3 (1 replies)
  38. Non-continuable exception trick (1 replies)
  39. Inside Session 0 Isolation and the UI Detection Service - Part 1 (0 replies)
  40. Something different part 2 (0 replies)
  41. New Hex-Rays Demo (1 replies)
  42. Different versions of Windows kernel structures (1 replies)
  43. gee mail patented algorithm (2 replies)
  44. Pythonic way (4 replies)
  45. Working? with protected processes in NT 6 (0 replies)
  46. Alignment check (0 replies)
  47. Re: RtlRemoteCall (0 replies)
  48. hm (0 replies)
  49. Running Win32 program ASAP after Nt boot (0 replies)
  50. Microsoft's Rich Signature (undocumented) (32 replies)
  51. Tricky jump tables (0 replies)
  52. Reverse Engineering the flash virtual machine (3 replies)
  53. Collaborative RCE Tool Library (CRCETL) site update (1 replies)
  54. Two Extensions added into Collaborative RCE (2 replies)
  55. Why does every heap trace in UMDH get stuck at "malloc"? (0 replies)
  56. SoftICE Installation. (23 replies)
  57. Easy structure types (0 replies)
  58. Eeye BinDiffing Trick (3 replies)
  59. Industrial-Grade Binary-Only Profiling and Coverage (1 replies)
  60. Refreshing the Taskbar Notification Area (3 replies)
  61. Idc script and stack frame variables length (0 replies)
  62. Shellcode Analysis (0 replies)
  63. SpyShredder Malware Spammed on OpenRCE (0 replies)
  64. Array Indexing Quirk (0 replies)
  65. MRXDAV.SYS and Hex-Rays Decompiler (0 replies)
  66. Shellcoding on Windows: Part II - Stack Overflow Problems (1 replies)
  67. Updated ExtraPass plug-in 2.1, and APIScan (2 replies)
  68. dr7.gd on mp systems running sice (5 replies)
  69. PE Validator Script (2 replies)
  70. Thread Optimization Checks : Code Prominence (0 replies)
  71. Run-time determination of VC++ virtual member function addresses: Take II (3 replies)
  72. Immunity Debugger v1.4 (0 replies)
  73. Debugger and process memory (0 replies)
  74. KeGetCurrentIrql can't return HIGH_LEVEL (6 replies)
  75. aMSN Input Validation Error (2 replies)
  76. Direct3D 9 Hook v1.1 (3 replies)
  77. Jump tables (0 replies)
  78. Something different (0 replies)
  79. Shellcoding on Windows: Part I (0 replies)
  80. ActiveX - Active Exploitation (0 replies)
  81. Context-keyed Payload Encoding (0 replies)
  82. Improving Software Security Analysis using Exploitation Properties (0 replies)
  83. An Objective Analysis of the Lockdown Protection System for Battle.net (0 replies)
  84. FPU Tracer v0.0.1 released (0 replies)
  85. .NET unpackme (3 replies)
  86. softice nmi hook (4 replies)
  87. ScTagQuery: Mapping Service Hosting Threads With Their Owner Service (2 replies)
  88. Virtual Machine detection method cd. (0 replies)
  89. Old new Virtual Machine detection method. (0 replies)
  90. Compiler Optimizations Regarding Structures (0 replies)
  91. HP printer and cpu at 100% (4 replies)
  92. Binary Search in Large-Scale Structure Recovery (0 replies)
  93. Again on Visual Basic (0 replies)
  94. GUID-Finder IDA Plug-in (0 replies)
  95. Explorer Suite III (CFF Explorer VII) (7 replies)
  96. Reversity Speech and Logs Available (10 replies)
  97. Control Flow Deobfuscation Part 1 (4 replies)
  98. Dvd movie and easter egg (7 replies)
  99. A catalog of NTDLL kernel mode to user mode callbacks, part 5: KiUserCallbackDispatch (0 replies)
  100. Thread Local Storage, part 2: Explicit TLS (0 replies)
  101. Thread Local Storage, part 3: Compiler and linker support for implicit TLS (0 replies)
  102. Thread Local Storage, part 4: Accessing __declspec(thread) data (0 replies)
  103. Thread Local Storage, part 5: Loader support for __declspec(thread) variables (proces (0 replies)
  104. Thread Local Storage, part 6: Design problems with the Windows Server 2003 (and earli (0 replies)
  105. Thread Local Storage, part 7: Windows Vista support for __declspec(thread) in demand (0 replies)
  106. Thread Local Storage, part 8: Wrap-up (0 replies)
  107. How does one retrieve the 32-bit context of a Wow64 program from a 64-bit process on (0 replies)
  108. Viridian guest hypercall interface published (0 replies)
  109. Why are certain DLLs required to be at the same base address system-wide? (0 replies)
  110. A catalog of NTDLL kernel mode to user mode callbacks, part 1: Overview (0 replies)
  111. A catalog of NTDLL kernel mode to user mode callbacks, part 2: KiUserExceptionDispatc (0 replies)
  112. A catalog of NTDLL kernel mode to user mode callbacks, part 3: KiUserApcDispatcher (0 replies)
  113. A catalog of NTDLL kernel mode to user mode callbacks, part 4: KiRaiseUserExceptionDi (0 replies)
  114. Thread Local Storage, part 1: Overview (0 replies)
  115. The optimizer has different traits between the x86 and x64 compilers (0 replies)
  116. Compiler tricks in x86 assembly: Ternary operator optimization (0 replies)
  117. A catalog of NTDLL kernel mode to user mode callbacks, part 6: LdrInitializeThunk (13 replies)
  118. Reversing the V740, part 4: Implementing a solution (4 replies)
  119. Common WinDbg problems and solutions (0 replies)
  120. Fast kernel debugging for VMware, part 1: Overview (0 replies)
  121. Fast kernel debugging for VMware, part 2: KD Transport Module Interface (0 replies)
  122. Fast kernel debugging for VMware, part 3: Guest to Host Communication Overview (0 replies)
  123. Fast kernel debugging for VMware, part 5: Bridging the Gap to DbgEng.dll (0 replies)
  124. Fast kernel debugging for VMware, part 6: Roadmap to Future Improvements (0 replies)
  125. VMKD 1.1.1.7 released (0 replies)
  126. I tend to prefer debugging with release builds instead of debug builds. (0 replies)
  127. The default invalid parameter behavior for the VC8 CRT doesnâ??t break into the debug (0 replies)
  128. Why doesn't the publicly available kernrate work on Windows x64? (and how to fix it (0 replies)
  129. Reversing the V740, part 1: Rationale (0 replies)
  130. Reversing the V740, part 2: Digging deeper: The connection manager software (0 replies)
  131. Reversing the V740, part 3: The V740 abstraction layer module (0 replies)
  132. Fast kernel debugging for VMware, part 4: Communicating with the VMware VMM (0 replies)
  133. More packer analysis (0 replies)
  134. Packer analysis (1 replies)
  135. Debugging a custom unhandled exception filter (0 replies)
  136. Collaborative RCE Tool Library contents so far (7 replies)
  137. ImageRemCert - Removes certificate from PE image. (4 replies)
  138. CommWarrior.B Thorough IDB (ARM/C++) (1 replies)
  139. MemInfo: Peer Inside Memory Manager Behavior on Windows Vista and Server 2008 (12 replies)
  140. dr7.gd - dr6 saving (4 replies)
  141. Better user interface for decompiler (3 replies)
  142. The Windows Vista Issue (23 replies)
  143. Weird Code: CCs On The Stack (0 replies)
  144. Windbg “dt” output converter (5 replies)
  145. MmGetSystemRoutineAddress : forwards on vista (11 replies)
  146. Traversing Offset Semantics : Walking Along the Curb (2 replies)
  147. The Collaborative RCE Tool Library (1 replies)
  148. syscall fuzzer (0 replies)
  149. The secret project finally revealed... (1 replies)
  150. Site Relaunch (3 replies)
  151. A framework to take the tedium out of code-injection in C++ (3 replies)
  152. Beware of int 2c instruction (3 replies)
  153. IDC scripting a Win32.Virut variant - Part 1 (4 replies)
  154. IDC scripting a Win32.Virut variant - Part 2 (11 replies)
  155. Nanomites by Deroko (0 replies)
  156. Hang problem due to Hooking Curb in Codes. (0 replies)
  157. Vaughn Of The Dead Pt III: Some small-fry (0 replies)
  158. Armadillo, Nanomites and vectored exception-handling (8 replies)
  159. Recent Events (0 replies)
  160. Update on Driver Signing Bypass (0 replies)
  161. Windows Vista 64-bit Driver Signing/PatchGuard Workaround (0 replies)
  162. Behind Windows x64's 44-bit Virtual Memory Addressing Limit (0 replies)
  163. Purple Pill: What Happened (0 replies)
  164. Secrets of the Application Compatilibity Database (SDB) - Part 4 (0 replies)
  165. Why Protected Processes Are A Bad Idea (3 replies)
  166. New Object Manager Filtering APIs (0 replies)
  167. Vista DRM Issue Aftermath (0 replies)
  168. Rebooting from Kernel Mode (0 replies)
  169. How I cracked the iTunes 7 DRM, Pt V (7 replies)
  170. Run-time determination of VC++ 2005 virtual member function addresses (0 replies)
  171. RCE essentials: PEiD (0 replies)
  172. Case study: Fraps (0 replies)
  173. How I cracked the iTunes 7 DRM, Pt III (0 replies)
  174. DLL injection via CreateRemoteThread (0 replies)
  175. Drawing on another Direct3D program's viewport (1 replies)
  176. Bypassing IsDebuggerPresent (3 replies)
  177. How I cracked the iTunes 7 DRM, Pt I (0 replies)
  178. How I cracked the iTunes 7 DRM, Pt II (0 replies)
  179. How I cracked the iTunes 7 DRM, Pt IV (3 replies)
  180. RDP Botnets : Malware Google Dorking - Not an Easy Task (0 replies)
  181. Is Win32 A Debugging API? If Not, How Close Is It? (11 replies)
  182. Reversing a ZLib-Obfuscated? Network Protocol (0 replies)
  183. Exploring Protocols 2: Writing some tools (0 replies)
  184. Exploring Protocols - Part 1 (0 replies)
  185. MITMing an SSLized Java App (0 replies)
  186. Analyzing Mac OS X Applications 101: CrashReporter and Malloc (0 replies)
  187. Refreshing Change Of Pace: Actual Technical Discussions at Nate's Blog (0 replies)
  188. Mystery Vulnerability Theater 3000: Part I (0 replies)
  189. ridiculous_fish Open-Sources HexFiend! (0 replies)
  190. BinNavi Traces IOS and ScreenOS. It's On, Yo. (0 replies)
  191. Experimenting with IDA 5.2's scriptable debugger (2 replies)
  192. Undocumented Windows 2000 Secrets - free pdf edition (0 replies)
  193. Auditing Oracle with Cesar Cerrudo (0 replies)
  194. PaiMei / PIDA Fun (0 replies)
  195. Breaking in DAV RPC INTERFACE : Peripherals (0 replies)
  196. Decompiler output ctree (0 replies)
  197. Intrinsic "_ReturnAddress()" C/C++ WTF! (1 replies)
  198. New face and new concept for the Reverse Code Engineering Video Portal (2 replies)
  199. Small PyDBG Enhancements Incoming (0 replies)
  200. Packet Sniffing With ImmunityDebugger (0 replies)
  201. Grey Box Web Application Testing With Immunity Debugger (0 replies)
  202. Visual Patterns for File Format Fuzzing (0 replies)
  203. Reliability of Pseudo Registers in Bug Tracking (0 replies)
  204. Python + Microsoft Minidumps (0 replies)
  205. Dissecting Windows XP Svchost Internals : Traversing Core Parameters (0 replies)
  206. Stack Unwinding : Reliability Panorama (0 replies)
  207. An "extra pass" for IDA Pro (2 replies)
  208. Hardware Breakpoints : Stature (0 replies)
  209. Comming soon! Uber process hooking/detour system! (3 replies)
  210. My Training Class (0 replies)
  211. Vista Heap, Controlling the Determinism. (0 replies)
  212. For those who miss it: Immunity Debugger v1.2 Release (0 replies)
  213. Immunity Debugger v1.1 Release (0 replies)
  214. Updated APIScan (1 replies)
  215. Embedded Portable Executable File (0 replies)
  216. Real Time Tracing (0 replies)
  217. My first entry (0 replies)
  218. Another IDA script: Dump section (0 replies)
  219. Assembly Custom GetProcAddress (0 replies)
  220. IDA's .IDS Files Part I (0 replies)
  221. IDA's .IDS Files Part II (0 replies)
  222. ProcDump Thorough IDB (0 replies)
  223. T2 2006 VM Analysis (0 replies)
  224. Syscall lister (0 replies)
  225. Mysteries of win32k & GDI - Win32Thread (0 replies)
  226. Null pointer dereference in win32k (0 replies)
  227. Immunity Debugger is now released! (0 replies)
  228. Immunity Debugger Plugin Awards (0 replies)
  229. Dancing with exceptions (4 replies)
  230. Future occupation: Archeological reverser? (0 replies)
  231. Automating analysis with PyDbg (0 replies)
  232. Interesting primer on Virtualization from VMware (0 replies)
  233. Mass deface with RFI scanners (0 replies)
  234. Semi-automatic import recovery (0 replies)
  235. ExeCryptor's code morphing "technology" (0 replies)
  236. Why VMware is bad for shareware? (3 replies)
  237. Radio? (0 replies)
  238. Komodo Edit 4.2 released (0 replies)
  239. Visual Basic DllFunctionCall (0 replies)
  240. A new player in the virtualization arena for Mac (0 replies)
  241. VMWare Fusion? (0 replies)
  242. HELLO! (0 replies)
  243. OUTLAW ROOTKITS? (0 replies)
  244. LINUX AT LAST! (0 replies)
  245. Adding IDC commands to the out-of-the-box set (0 replies)
  246. Scripting fun (0 replies)
  247. EXPLICATOR? (0 replies)
  248. On batch analysis (0 replies)
  249. Dynamic coloring (0 replies)
  250. Does 'return' come back? (0 replies)