>_0xFORUM
Sign in

Base64 + rolling XOR in resources, still not a packer

in Reversing19 replies2.8k views

People call any resource blob a packer. This one is a config. Decode is 12 lines.

I wish writeups would stop saying 'packed' when they mean 'encoded config'.

blob = b64(res)
for i,b in enumerate(blob): blob[i] ^= (0xA5 + i) & 0xFF

Refs: Ghidra

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 19 REPLIES

I disagree with the tone, not the bytes. You wrote «People call any resource blob a packer». That is the sentence I keep. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. I reproduced it on lab build 1024.

@edwinjay

I disagree with the tone, not the bytes. You wrote «People call any resource blob a packer». That is the sentence I keep. I bookmark the dec

I am not moving this to DMs so you can yell. Stay on the class. I still keep a paper notebook for this kind of note. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a packer. UPX with a skipped magic is still UPX. Restore four bytes and move on. If anyone DMs me a zip I will not open it. Hash in-thread.

I dumped after OEP and then did this. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a packer. Call-convention mass-correct with a script. Still too much clicking. My note id for this: 21-02.

I dumped after OEP and then did this. You wrote «People call any resource blob a packer». That is the sentence I keep. I trust FLOSS after I have seen the decoder. Before that I read the stores. My note id for this: 21-06.

@fredricko

I dumped after OEP and then did this. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a

That is not what the listing shows. You are arguing a vibe. I would have written the opposite conclusion a year ago. On Ā«Base64 + rolling XOR in resources, still not a packerĀ»: People call any resource blob a packer. Vtable grouping without RTTI: xref clusters plus IUnknown shape. What did you key the join on — PID or process GUID? I will +rep a listing and āˆ’rep a vibe. That is the deal.

@grayhat

I would have written the opposite conclusion a year ago. On «Base64 + rolling XOR in resources, still not a packer»: People call any resourc

Not fully convinced yet. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a packer. I leave CET ops in the listing. They document that CET is on. I reproduced it on lab build 1111.

@hashx

Not fully convinced yet. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a packer. I le

I read the patch. You read a tweet. Those are not the same source. I disagree with the tone, not the bytes. You wrote «People call any resource blob a packer». That is the sentence I keep. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. I still have the snapshot named reve-33-pre.

@lima

Same wall I hit last quarter. You wrote «People call any resource blob a packer». That is the sentence I keep. I bookmark the decoder then r

I tried the naive path first and wasted a morning. You wrote «People call any resource blob a packer». That is the sentence I keep. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. I reproduced it on lab build 1320.

@koredehub

I tried the naive path first and wasted a morning. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any re

Do not call people skids because they use Ghidra. Same wall I hit last quarter. You wrote «People call any resource blob a packer». That is the sentence I keep. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. I still have the snapshot named reve-33-pre.

I tried the naive path first and wasted a morning. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a packer. UPX with a skipped magic is still UPX. Restore four bytes and move on. Did you force-create the function or did auto-analysis luck into it? If anyone DMs me a zip I will not open it. Hash in-thread.

@intelr

I dumped after OEP and then did this. You wrote «People call any resource blob a packer». That is the sentence I keep. I trust FLOSS after I

Call-convention guess is not evidence. Came back to this after a coffee. Still hold. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a packer. I trust FLOSS after I have seen the decoder. Before that I read the stores. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@mapr

I tried the naive path first and wasted a morning. You wrote «People call any resource blob a packer». That is the sentence I keep. I bookma

You are describing a live target. Stop. Patched class only. I failed this exact class in January. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a packer. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. I still have the snapshot named reve-33-pre.

This belongs in the first-hour ritual. On «Base64 + rolling XOR in resources, still not a packer»: People call any resource blob a packer. Listing first. The decompiler invented a cast last week that hid a signed compare. Same class as the March thread, different binary.

Also: I leave CET ops in the listing. They document that CET is on.

@ohmx

This belongs in the first-hour ritual. On «Base64 + rolling XOR in resources, still not a packer»: People call any resource blob a packer. L

Take the telegram pitch to the bin. Market listing or nothing. Good. Dated shot, version in the post. You wrote «People call any resource blob a packer». That is the sentence I keep. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. After you did that, did the decompiler pick it up or did you dump? I still have the snapshot named reve-33-pre.

Did this on ARM64 last week — same shape, different pain. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call any resource blob a packer. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. If anyone DMs me a zip I will not open it. Hash in-thread.

@primez

Did this on ARM64 last week — same shape, different pain. Ā«Base64 + rolling XOR in resources, still not a packerĀ» — specifically People call

Quote the bytes or sit down. Please keep the hashes and drop the mystery zips. On «Base64 + rolling XOR in resources, still not a packer»: People call any resource blob a packer. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. Took me 5 hours the first time.

@rfsec

Please keep the hashes and drop the mystery zips. On «Base64 + rolling XOR in resources, still not a packer»: People call any resource blob

I dumped after OEP and then did this. The load-bearing line: People call any resource blob a packer. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. I reproduced it on lab build 1257.

@scrpt

I dumped after OEP and then did this. The load-bearing line: People call any resource blob a packer. If it is a crackme you wrote, dump afte

You are treating a checksum as a signature again. I will argue the opposite and then probably agree. The load-bearing line: People call any resource blob a packer. I leave CET ops in the listing. They document that CET is on. Same class as the June thread, different binary.

I ran this on a licensed corpus binary. You wrote «People call any resource blob a packer». That is the sentence I keep. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Hash of the public file, or are we arguing a shape? Pinned a comment at 0x1400065f9 in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.