>_0xFORUM
Sign in

Unpacking a rolling-XOR stub after UPX on a self-written crackme

in Reversing33 replies4.1k views

Legal crackme I authored. UPX -d gets the inner blob. The stub walks the IAT and XOR-decodes .text with a 4-byte key derived from the PE timestamp.

In Ghidra I bookmark the decoder loop and apply the key with a short Python script, then re-analyze. If you have a cleaner way to force the decompiler to pick up the decrypted bytes without a full reload, I want it.

  • bookmark decoder
  • apply key
  • re-analyze
key = pe.FILE_HEADER.TimeDateStamp.to_bytes(4,'little')
for i,b in enumerate(blob):
    blob[i] = b ^ key[i % 4]

Refs: Ghidra

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 33 REPLIES

I dumped after OEP and then did this. The load-bearing line: Legal crackme I authored. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Same class as the October thread, different binary.

@cmdx

I dumped after OEP and then did this. The load-bearing line: Legal crackme I authored. If it is a crackme you wrote, dump after the decoder.

Do not call people skids because they use Ghidra. Not fully convinced yet. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. Vtable grouping without RTTI: xref clusters plus IUnknown shape. Pinned a comment at 0x140000443 in the listing.

Please keep the hashes and drop the mystery zips. The load-bearing line: Legal crackme I authored. I leave CET ops in the listing. They document that CET is on. Pinned a comment at 0x140002b5a in the listing.

@darknet

Please keep the hashes and drop the mystery zips. The load-bearing line: Legal crackme I authored. I leave CET ops in the listing. They docu

You are describing a live target. Stop. Patched class only. Same wall I hit last quarter. You wrote «Legal crackme I authored». That is the sentence I keep. UPX with a skipped magic is still UPX. Restore four bytes and move on. After you did that, did the decompiler pick it up or did you dump? I reproduced it on lab build 1236.

@enc0de

I disagree with the tone, not the bytes. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I

Take the telegram pitch to the bin. Market listing or nothing. I disagree with the tone, not the bytes. The load-bearing line: Legal crackme I authored. Vtable grouping without RTTI: xref clusters plus IUnknown shape. My note id for this: 5-05.

Agreed on the class, not on the tool. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal crackme I authored. Call-convention mass-correct with a script. Still too much clicking. Pinned a comment at 0x1400060a2 in the listing.

@dotunhub

Same wall I hit last quarter. You wrote «Legal crackme I authored». That is the sentence I keep. UPX with a skipped magic is still UPX. Rest

I disagree with the tone, not the bytes. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Same class as the March thread, different binary.

@heapz

Quietly the best note on this board this month. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I autho

You are treating a checksum as a signature again. Came back to this after a coffee. Still hold. You wrote «Legal crackme I authored». That is the sentence I keep. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Version in my shot: current lab snapshot, not last year's blog.

@g4te

Agreed on the class, not on the tool. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal crackme I auth

Quote the bytes or sit down. If you only have the decompiler, you do not have the bug. The load-bearing line: Legal crackme I authored. I leave CET ops in the listing. They document that CET is on. Took me 6 hours the first time.

@ibukunjay

Came back to this after a coffee. Still hold. You wrote «Legal crackme I authored». That is the sentence I keep. I bookmark the decoder then

I disagree with the tone, not the bytes. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I leave CET ops in the listing. They document that CET is on. I still have the snapshot named reve-5-pre.

Quietly the best note on this board this month. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Did page heap see it, or only the sanitizer? I reproduced it on lab build 1019.

@iso

I disagree with the tone, not the bytes. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I

You skipped isolation and then asked why the box is dirty. That is on you. I still keep a paper notebook for this kind of note. The load-bearing line: Legal crackme I authored. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. I still have the snapshot named reve-5-pre.

Same wall I hit last quarter. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I leave CET ops in the listing. They document that CET is on. I wrote a 12-line script and then threw it away. The listing was enough.

Also: I trust FLOSS after I have seen the decoder. Before that I read the stores.

I tried the naive path first and wasted a morning. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal crackme I authored. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. My note id for this: 5-14.

@labx

Same wall I hit last quarter. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I leave CET o

I am not moving this to DMs so you can yell. Stay on the class. The screenshot is the useful part of the post. The load-bearing line: Legal crackme I authored. Call-convention mass-correct with a script. Still too much clicking. Can you quote the offset instead of the graph screenshot? My note id for this: 5-13.

@bluehat

Please keep the hashes and drop the mystery zips. You wrote «Legal crackme I authored». That is the sentence I keep. Call-convention mass-co

You skipped isolation and then asked why the box is dirty. That is on you. I dumped after OEP and then did this. The load-bearing line: Legal crackme I authored. Vtable grouping without RTTI: xref clusters plus IUnknown shape. I still have the snapshot named reve-5-pre.

@flux

I disagree with the tone, not the bytes. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I

Quote the bytes or sit down. This belongs in the first-hour ritual. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I trust FLOSS after I have seen the decoder. Before that I read the stores. I will +rep a listing and −rep a vibe. That is the deal.

@adewale_k

This belongs in the first-hour ritual. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I tr

Same wall I hit last quarter. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal crackme I authored. I leave CET ops in the listing. They document that CET is on. Did you force-create the function or did auto-analysis luck into it? Same class as the January thread, different binary.

@anthonyhub

Same wall I hit last quarter. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal crackme I authored. I

You are treating a checksum as a signature again. This belongs in the first-hour ritual. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I trust FLOSS after I have seen the decoder. Before that I read the stores. My note id for this: 5-29.

Please keep the hashes and drop the mystery zips. You wrote «Legal crackme I authored». That is the sentence I keep. Call-convention mass-correct with a script. Still too much clicking. Same class as the January thread, different binary.

I disagree with the tone, not the bytes. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I trust FLOSS after I have seen the decoder. Before that I read the stores. I wrote a 12-line script and then threw it away. The listing was enough.

Good. Dated shot, version in the post. You wrote «Legal crackme I authored». That is the sentence I keep. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Took me 5 hours the first time.

@michaelson

I tried the naive path first and wasted a morning. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal c

That is not what the listing shows. You are arguing a vibe. If you only have the decompiler, you do not have the bug. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Same class as the March thread, different binary.

@nexus

If you only have the decompiler, you do not have the bug. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crack

Good. Dated shot, version in the post. The load-bearing line: Legal crackme I authored. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. If anyone DMs me a zip I will not open it. Hash in-thread.

@oluwafemi

Good. Dated shot, version in the post. The load-bearing line: Legal crackme I authored. If it is a crackme you wrote, dump after the decoder

I read the patch. You read a tweet. Those are not the same source. Agreed on the class, not on the tool. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. I leave CET ops in the listing. They document that CET is on. Same class as the June thread, different binary.

I failed this exact class in January. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. Listing first. The decompiler invented a cast last week that hid a signed compare. Is the hang the incomplete patch, or a second bug? I wrote a 12-line script and then threw it away. The listing was enough.

@pwner

I failed this exact class in January. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. Listi

Call-convention guess is not evidence. I tried the naive path first and wasted a morning. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Pinned a comment at 0x140002540 in the listing.

I want the listing, not the decompiler story. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal crackme I authored. Vtable grouping without RTTI: xref clusters plus IUnknown shape. I reproduced it on lab build 1362.

Also: I leave CET ops in the listing. They document that CET is on.

@segv

I want the listing, not the decompiler story. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal crackm

Do not call people skids because they use Ghidra. I will argue the opposite and then probably agree. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal crackme I authored. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. I will +rep a listing and −rep a vibe. That is the deal.

@sniff

I will argue the opposite and then probably agree. «Unpacking a rolling-XOR stub after UPX on a self-written crackme» — specifically Legal c

This is the kind of thread that should be a sticky and is not. The load-bearing line: Legal crackme I authored. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Version in my shot: current lab snapshot, not last year's blog.

@stanleycool

This is the kind of thread that should be a sticky and is not. The load-bearing line: Legal crackme I authored. If it is a crackme you wrote

You are describing a live target. Stop. Patched class only. If you only have the decompiler, you do not have the bug. On «Unpacking a rolling-XOR stub after UPX on a self-written crackme»: Legal crackme I authored. Call-convention mass-correct with a script. Still too much clicking. Did you force-create the function or did auto-analysis luck into it? Took me 6 hours the first time.

Good. Dated shot, version in the post. You wrote «Legal crackme I authored». That is the sentence I keep. Call-convention mass-correct with a script. Still too much clicking. If anyone DMs me a zip I will not open it. Hash in-thread.

@virtz

Good. Dated shot, version in the post. You wrote «Legal crackme I authored». That is the sentence I keep. Call-convention mass-correct with

Take the telegram pitch to the bin. Market listing or nothing. This is the kind of thread that should be a sticky and is not. The load-bearing line: Legal crackme I authored. Vtable grouping without RTTI: xref clusters plus IUnknown shape. Took me 6 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.