Skip to main content

Posts

Hacking - Best OF Reverse Engineering - Part20

Glimpse of Static Malware Analysis The internet has become an essential part of our day-to-day life. We are using it to communicate, exchange information, perform bank transactions, etc. Researchers are working around the clock to expand this service and optimize it. Hackers, on the other hand, are leveraging this crucial service to perform cybercrime activities, such as stealing credit cards. Over the past few years, talented and geek computer users were exploiting and identifying applications and operating systems’ vulnerabilities for fun. However, the game has changed and shifted from a fun activity towards a profit-oriented business. Some research [3] indicates that the average global economy loss due to cybercrime and espionage is $500 billion annually. Hackers use malicious software (malware), e.g., virus, worm, or rootkit, to perform their activities. Therefore, understanding and analyzing the malware is very important to protect the end users. Moreover, it will help t...

Hacking - Best OF Reverse Engineering - Part19

Setting Up Your Own Malware Analysis Lab With new malware attacks making news everyday and compromising company’s network and critical infrastructures around the world, malware analysis is critical for anyone who responds to such incidents. In this article you will learn to setup a safe environment to analyze malicious software and understand its behaviour. Malware is a piece of software which causes harm to a computer system without the owner’s consent. Viruses, Trojans, worms, backdoors, rootkits, scareware and spyware can all be considered as malwares. Malware Analysis Malware analysis is the process of understanding the behaviour and characteristics of malware, how to detect and eliminate it. Why Malware Analysis? There are many reasons why we would want to analyze a malware, below to name just a few: • Determine the nature and purpose of the malware i.e whether the malware is an information stealing   malware, http bot, spam bot, rootkit, keylogger, RAT etc....

Hacking - Best OF Reverse Engineering - Part18

Reverse Engineering – Debugging Fundamentals The debugger concept and purpose is to test and troubleshoot another written program. Whether the debugger is a simple script, tool or a more complex computer program the idea is to utilize it in order see and verify the functionality of the “target” program / application in such a form that one can see and understand via the debugger what is happening while the “target” program / application runs and especially when it stops. The “target” program’s / application’s code that is examined (by the debugger) might alternatively be running on an Instruction Set Simulator (ISS). The ISS is a certain form of technique that gives the ability to halt when specific conditions are encountered but which will typically be somewhat slower than executing the code directly on the appropriate (or the same) processor. When the “target” program / application reaches a running condition or when the program cannot normally continue due to a programmin...

Hacking - Best OF Reverse Engineering - Part17

How to Reverse Engineer? In this article, we are going to talk about RCE, also known as reverse code engineering. Reverse code engineering is the process where the code and function of a program is modified, or may you prefer: reengineered without the original source code. For example, if a software programmer has created a program with a bug, does not release a fix, then an experienced end user can reverse engineer the application and fix the bug for everyone using the program. Sounds helpful doesn’t it? That’s because we only touched the tip of the iceberg; the road of reverse engineering is a long one and the end leads to somewhere dark and illegal. Why you wonder? Because, by that logic, computer users can modify the code of any program, alter licensing features of a commercial product and remove critical features to their own liking. For example, a software such as Photoshop that requires you to buy a serial key to register and use it, can be reverse engineered to either ext...

Hacking - Best OF Reverse Engineering - Part16

Reversing with Stack-Overflow and Exploitation The theater of the information security professional has changed drastically in the world of computing or digital world. So we are going to find the root. The keynote to secure the business is a complete analysis of internal business. The prevalence of security holes in program and protocols, the increasing size and complexity of the internet, and the sensitivity of the information stored throughout have created a target-rich environment for our next generation advisory. The criminal element is applying advanced techniques to evade the software/ tool security. So the Knowledge of Analysis is necessary. And that pin point is called “The Art Of Reverse Engineering” What is Reverse Engineering? Reverse engineering is the process of taking a compiled binary and attempting to recreate (or simply understand) the original way the program works. A programmer initially writes a program, usually in a high-level language such as C++ or V...