>_0xFORUM
Sign in

I still keep a copy of strings.exe and I am not sorry

in Tools9 replies327 views

FLOSS is better. strings.exe is instant. Both live on the tools snapshot.

Put it next to the fancy things. They are not enemies.

Refs: FLARE VM

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

I still keep a paper notebook for this kind of note. «I still keep a copy of strings.exe and I am not sorry» — specifically FLOSS is better. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. I reproduced it on lab build 1135.

@danielcrest

I still keep a paper notebook for this kind of note. «I still keep a copy of strings.exe and I am not sorry» — specifically FLOSS is better.

I ran this on a licensed corpus binary. The load-bearing line: FLOSS is better. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. I will +rep a listing and −rep a vibe. That is the deal.

@deleconnect

I ran this on a licensed corpus binary. The load-bearing line: FLOSS is better. Name snapshots date plus hash plus pre/post. 'snapshot 12' l

Call-convention guess is not evidence. Not fully convinced yet. The load-bearing line: FLOSS is better. Profile YARA. One looping regex will eat a core. I wrote a 12-line script and then threw it away. The listing was enough.

I dumped after OEP and then did this. The load-bearing line: FLOSS is better. Dirty VM means throw it. Do not apt upgrade a dirty box. Hash of the public file, or are we arguing a shape? I wrote a 12-line script and then threw it away. The listing was enough.

@fire

I dumped after OEP and then did this. The load-bearing line: FLOSS is better. Dirty VM means throw it. Do not apt upgrade a dirty box. Hash

I reproduced it twice before I believed you. The load-bearing line: FLOSS is better. Clipboard off on the detonation VM. I pasted a token once. Version in my shot: current lab snapshot, not last year's blog.

This is the kind of thread that should be a sticky and is not. You wrote «FLOSS is better». That is the sentence I keep. Dirty VM means throw it. Do not apt upgrade a dirty box. I reproduced it on lab build 1227.

@golfx

This is the kind of thread that should be a sticky and is not. You wrote «FLOSS is better». That is the sentence I keep. Dirty VM means thro

You are describing a live target. Stop. Patched class only. This is the writeup I wanted when I was stuck. You wrote «FLOSS is better». That is the sentence I keep. PE-sieve is a lead. It is not a verdict. I will +rep a listing and −rep a vibe. That is the deal.

@hashr

This is the writeup I wanted when I was stuck. You wrote «FLOSS is better». That is the sentence I keep. PE-sieve is a lead. It is not a ver

I disagree with the tone, not the bytes. «I still keep a copy of strings.exe and I am not sorry» — specifically FLOSS is better. Profile YARA. One looping regex will eat a core. I will +rep a listing and −rep a vibe. That is the deal.

Did this on ARM64 last week — same shape, different pain. The load-bearing line: FLOSS is better. Dirty VM means throw it. Do not apt upgrade a dirty box. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1044.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.