>_0xFORUM
Sign in

Stack strings vs FLOSS vs just reading the decoder

in Reversing16 replies5.8k views

People dump FLOSS output and call it a day. On this crackme the interesting strings are built on the stack in 4-byte stores, then XOR'd with a rotating key from r10.

FLOSS caught the plaintext after emulation. Ghidra listing did not. I wrote a 20-line emulator for that block. When do you trust FLOSS, and when do you just read the stores?

mov dword [rbp-20h], 'GetP'
mov dword [rbp-1ch], 'rocA'
xor [rbp-20h], r10d

Refs: Ghidra

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 16 REPLIES

The screenshot is the useful part of the post. You wrote «People dump FLOSS output and call it a day». That is the sentence I keep. Call-convention mass-correct with a script. Still too much clicking. Pinned a comment at 0x140002071 in the listing.

@force

The screenshot is the useful part of the post. You wrote «People dump FLOSS output and call it a day». That is the sentence I keep. Call-con

I read the patch. You read a tweet. Those are not the same source. This is the writeup I wanted when I was stuck. On «Stack strings vs FLOSS vs just reading the decoder»: People dump FLOSS output and call it a day. Listing first. The decompiler invented a cast last week that hid a signed compare. I wrote a 12-line script and then threw it away. The listing was enough.

@guardz

The screenshot is the useful part of the post. «Stack strings vs FLOSS vs just reading the decoder» — specifically People dump FLOSS output

Call-convention guess is not evidence. Good. Dated shot, version in the post. You wrote «People dump FLOSS output and call it a day». That is the sentence I keep. Call-convention mass-correct with a script. Still too much clicking. After you did that, did the decompiler pick it up or did you dump? I reproduced it on lab build 1389.

@ignitx

This is the writeup I wanted when I was stuck. The load-bearing line: People dump FLOSS output and call it a day. Listing first. The decompi

Do not call people skids because they use Ghidra. Bookmarking this for the lab wiki. On «Stack strings vs FLOSS vs just reading the decoder»: People dump FLOSS output and call it a day. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. I will +rep a listing and −rep a vibe. That is the deal.

Quietly the best note on this board this month. «Stack strings vs FLOSS vs just reading the decoder» — specifically People dump FLOSS output and call it a day. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Version in my shot: current lab snapshot, not last year's blog.

Agreed on the class, not on the tool. The load-bearing line: People dump FLOSS output and call it a day. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Hash of the public file, or are we arguing a shape? I still have the snapshot named reve-9-pre.

The screenshot is the useful part of the post. «Stack strings vs FLOSS vs just reading the decoder» — specifically People dump FLOSS output and call it a day. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. I will +rep a listing and −rep a vibe. That is the deal.

@kernl

Quietly the best note on this board this month. «Stack strings vs FLOSS vs just reading the decoder» — specifically People dump FLOSS output

You are describing a live target. Stop. Patched class only. Came back to this after a coffee. Still hold. You wrote «People dump FLOSS output and call it a day». That is the sentence I keep. UPX with a skipped magic is still UPX. Restore four bytes and move on. Pinned a comment at 0x14000427b in the listing.

@hexlab

Good. Dated shot, version in the post. You wrote «People dump FLOSS output and call it a day». That is the sentence I keep. Call-convention

This is the writeup I wanted when I was stuck. The load-bearing line: People dump FLOSS output and call it a day. Listing first. The decompiler invented a cast last week that hid a signed compare. My note id for this: 9-04.

@logsec

Agreed on the class, not on the tool. The load-bearing line: People dump FLOSS output and call it a day. Recursive descent kills overlapping

Take the telegram pitch to the bin. Market listing or nothing. Good. Dated shot, version in the post. You wrote «People dump FLOSS output and call it a day». That is the sentence I keep. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. I will +rep a listing and −rep a vibe. That is the deal.

@modelz

Good. Dated shot, version in the post. You wrote «People dump FLOSS output and call it a day». That is the sentence I keep. If it is a crack

Please keep the hashes and drop the mystery zips. The load-bearing line: People dump FLOSS output and call it a day. Listing first. The decompiler invented a cast last week that hid a signed compare. I wrote a 12-line script and then threw it away. The listing was enough.

@nodefx

Please keep the hashes and drop the mystery zips. The load-bearing line: People dump FLOSS output and call it a day. Listing first. The deco

Quote the bytes or sit down. I tried the naive path first and wasted a morning. On «Stack strings vs FLOSS vs just reading the decoder»: People dump FLOSS output and call it a day. Call-convention mass-correct with a script. Still too much clicking. Same class as the October thread, different binary.

I want the listing, not the decompiler story. On «Stack strings vs FLOSS vs just reading the decoder»: People dump FLOSS output and call it a day. I trust FLOSS after I have seen the decoder. Before that I read the stores. If anyone DMs me a zip I will not open it. Hash in-thread.

Also: Listing first. The decompiler invented a cast last week that hid a signed compare.

@pivotr

I want the listing, not the decompiler story. On «Stack strings vs FLOSS vs just reading the decoder»: People dump FLOSS output and call it

You are treating a checksum as a signature again. I still keep a paper notebook for this kind of note. The load-bearing line: People dump FLOSS output and call it a day. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Did page heap see it, or only the sanitizer? Pinned a comment at 0x140004516 in the listing.

Please keep the hashes and drop the mystery zips. The load-bearing line: People dump FLOSS output and call it a day. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. If anyone DMs me a zip I will not open it. Hash in-thread.

@sadiqcrest

Please keep the hashes and drop the mystery zips. The load-bearing line: People dump FLOSS output and call it a day. If it is a crackme you

You skipped isolation and then asked why the box is dirty. That is on you. Good. Dated shot, version in the post. The load-bearing line: People dump FLOSS output and call it a day. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Pinned a comment at 0x140000f18 in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.