97, 2/4 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   Prox
   12¹ø ÆÄÆ® (ºóÄ­ÀÌ ¸¹¾Æ¿ä)

http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Translate&no=83 [º¹»ç]


µý°Ç µÑ°ġ°í, ¸»ÀÌ ³Ê¹« »¡¶ó¿ä..... ¤Ð¤Ð
´Ê°Ô¿Ã¸®´Â ÁÖÁ¦¿¡ ºóÄ­µµ ¸¹Áö¸¸... ¾Æ¹«Æ° 1Â÷¹ø¿ªº» ¿Ã¸³´Ï´Ù










0:00

we just put the breakpoint in front of it, and just punching it, trust him
ÀÌ ¾Õ¿¡ ºê·¹ÀÌÅ©Æ÷ÀÎÆ®¸¦ °Ì´Ï´Ù. ***** , *****

you' setting the earlier breakpoint that you said
ÀÌÀü¿¡ ¸»Çß´ø ºê·¹ÀÌÅ©Æ÷ÀÎÆ®¸¦ ¼³Á¤Çϼ¼¿ä. (?)

and you slop her deyoda for proportion
**********


so we just opt intros on the jump
(´À³¦À¸·Î Çؼ®) ¿ì¸®´Â ¸Ç óÀ½(intro)À¸·Î °¡´Â Á¡ÇÁ¹®À» ã¾Ò¾î¿ä

and we freeze single step once, we're right inside
ÇÑ stepÀ» ÁøÇàÇϸé, ¾ÈÀ¸·Î µé¾î¿ÀÁÒ

00:40
and so pogging underaround
********

everything is a "back to near loop"
¸ðµç °ÍÀÌ back to near loop(?) ÇÕ´Ï´Ù.

so go get just a make a memory dump
ÀÌÁ¦ memory dump¸¦ ¸¸µå¼¼¿ä.

of bafter ground
*******

we're going to use a Import Reconstructor
¿ì¸®´Â "Import Reconstructor"¶ó´Â ÇÁ·Î±×·¥À» »ç¿ëÇÒ °Å¿¡¿ä

because it's a very nice tool
¾ÆÁÖ ÁÁÀº ÅøÀ̱⠶§¹®ÀÌÁÒ

1:00
process number and a (impor triple striptor)
ÇÁ·Î¼¼½º ¹øÈ£¿Í ****¸¦ ÀÔ·ÂÇϸé

so we (just a actual) process
******

(¿©±â ¿ÖÀÌ·¸°Ô ´Ü¾î°¡ ÀÌ»óÇÏÁÒ... triport, porphia ¶æÀ» ¸ð¸£°Ú¾î¿ä)
we have to write up (triport) here
******

which is a several 4 for porphia
******

press "IAT autosearch"
IAT autosearch ¹öÆ°À» ´©¸£¼¼¿ä.

so it's a, searching for IAT import table,
±×·¯¸é IAT import Å×À̺íÀ» °Ë»öÇÏ°Ô µË´Ï´Ù.

ane we've(?) get to import
******

so we have **** imported through dlls and function right here
ÀÌÁ¦ dll°ú ÇÔ¼öµéÀ» import Çß±¸¿ä.

so i'm going to make a dump, all the process,
ÇÁ·Î¼¼½º ÀüüÀÇ ´ýÇÁ¸¦ ¸¸µé°Ì´Ï´Ù.

(go right)

1:50

ends endless feesee info takler
******????

jumped up, everything is (ripple shripped into a no reges dots, stuck you care on it)
Á¡ÇÁÇØ ¿Ô±¸¿ä. ¸ðµç °ÍÀº ********


2:05

and we get the grows of deriving ******** (meeyour, my roo..)
********** (?)

thank you
°¨»çÇÕ´Ï´Ù

(i didn't you donno)

couple quick points there
¸î°¡Áö ÁöÀûÇص帮°í ½ÍÀº Á¡ÀÌ ÀÖ½À´Ï´Ù.

if you used import reconstructor before we,
¸¸¾à import reconstructor¸¦ »ç¿ëÇϼÌÀ» °æ¿ì

be aware that it doesn't always leave a perfectly working executable immediately
¿Ïº®È÷ ÀÛµ¿ÇÏ´Â ½ÇÇàÆÄÀÏÀ» ¹Ù·Î ¸¸µé¾îÁÖÁö´Â ¾Ê´Â´Ù´Â °ÍÀÔ´Ï´Ù.

they have to do  *****(¿¡Ãë)******** sinces faces of washes code
~~~~~~ ¸¦ ÇØ¾ß ÇÕ´Ï´Ù.

help you creating (ferfrep) that may not actually run
½ÇÁ¦·Î ½ÇÇàµÇÁö´Â ¾Ê´Â ½ÇÇàÆÄÀÏÀ» ¸¸µé¾îÁشٴ °ÍÀÌÁÒ. (?)

instead, ah, what i'm gonna ****(introduce?) is, it is now easily analyzed in ida-pro,
´ë½Å, **** ÀÌÁ¦´Â, Áö±ÝÀº ida-pro·Î ½ÇÇàÆÄÀÏÀ» ½±°Ô ºÐ¼® ÇÒ ¼ö ÀÖ½À´Ï´Ù.

so as you seen before, when i try to load it up, i wouldn't get the very good.. ******** (->don't efeckers is looking into quickter's code)
ÀÌÀü¿¡ º¸¾Ò´Ù½ÃÇÇ, ÀÌ°ÍÀ» ºÒ·¯¿À°íÀÚ ÇÒ ¶§, ¾ÆÁÖ ÁÁÀº ********** ¸¦ ¾òÁö´Â ¸øÇÕ´Ï´Ù.

but nichole find out was that, this was looks like it was first tab
±×·¯³ª nicholeÀÌ ¾Ë¾Æ³½ ¹Ù·Î´Â, ÀÌ°Ç first tabó·³ º¸ÀÌÁö¸¸

ifewer px and aelviyoda quicter run on a so lu's actually two
????????????????????????, ÀÌ°ÍÀº ½ÇÁ¦·Î µÎ°³¶õ °ÍÀÌÁÒ. (?)

3:00

may have **** noticed two different places for of you separate points and cocked(talked) out
*******

ahm, it's quite good, the main reason why **** (ka kei) to do this that
±×Á¡Àº ÁÁ¾Æ¿ä. *********

you just did that in, a know what 10 minutes,
´ç½ÅÀÌ ±×°É ÇÏ´Â µ¥ 10ºÐ¹Û¿¡ ¾È°É·È°í

everyone took him few minutes longer than that
´Ù¸¥ ºÐµéµµ 10ºÐº¸´Ù Á¶±Ý ´õ °É¸° Á¤µµÁö¿ä.

and you get that for real for the first time (that's for days) so..
***********

very lucky to have him to demonstrate to you via **** of these
À̺Ð(Nichole?)ÀÌ ****À» ÅëÇØ ¿©·¯ºÐ²² ºÐ¼®À» ½Ã¿¬ÇÏ°Ô µÇ¾î¼­ ¾ÆÁÖ Çà¿îÀ̶ó »ý°¢ÇÕ´Ï´Ù.

if you noticed **** slides, there's preety lame,
*** ½½¶óÀ̵带 º¸½Ã¸é ¾Ë°ÚÁö¸¸, ****

discussion on how i used to do a bad thing,
Á¦°¡ ¾î¶»°Ô ³ª»Û Áþµé(?)À» Çß´ÂÁö discussionÇÑ °Ô ÀÖ¾î¿ä.

yeah, and a good place ****, with this actually we getting slides to the conference garge you can download
*******

3:40

i'll come little over talk *** trying go through quickly see you guys ** launch here

unloading FV , now nofect, executable,

and a *** hotload 201 here

yeah i'm go right from my don before


didn't complain about the imports table (at top), that's a good sign
¸Ç À§¿¡ ÀÖ´Â import table¿¡ ´ëÇØ ºÒÆòÇÏÁö ¸¶¼¼¿ä. ±×°Ç ÁÁÀº ¶æÀÌ¿¡¿ä

yeah, you see we actually have "local ****(saico) real WinMain"
ÀÌ°÷¿¡¼­ ÁøÂ¥ WinMainÇÔ¼ö¸¦ º¼ ¼ö ÀÖÁÒ.

and I prose(?) finding lots and lots of executable code
ÀÌÁ¦ ***** ¾ÆÁÖ ¸¹Àº ½ÇÇàÄڵ带 ã¾Ò¾î¿ä.

so, again (polly take it over, ok)
(Æú¸®¾¾, ¹ÞÀ¸¼¼¿ä, ¿ÀÄÉÀÌ.)

so, its, i'm gonna see if i can see the structure (»ß³î¸®¾Æ)

this is still quite busy but it's far far better ******* in terms of
¾ÆÁ÷ ÇؾßÇÒ °Ô ¸¹Áö¸¸, ÀÌ·¸°Ô ÇÏ´Â °Ç ******º¸´Ù ÈξÀ ÁÁ¾Æ¿ä.

  Hit : 2016     Date : 2011/08/03 06:20



    
  12¹ø ÆÄÆ® (ºóÄ­ÀÌ ¸¹¾Æ¿ä)     Prox
08/03 2015
71   ¹ø¿ª part 7 status     babyalpha
08/21 2001
70   ±ÞÇÑ´ë·Î 6¹øÆÄÆ®[1]     bluemario
05/11 1915
69   ÆÄÆ®1 ºÐ·®ÀÔ´Ï´Ù.     ¸Û¸Û
08/02 1895
68   [Á¦ 2ȸ] ¹ø¿ª ÆÄÆ®°¡ Á¤ÇØÁ³½À´Ï´Ù[12]     ¸Û¸Û
07/18 1892
67   µÎ ¹ø° ¹ø¿ª ´ë»ó °ü·Ã..[5]     ¸Û¸Û
06/16 1887
66   3¹ø° ÆÄÆ® ¾Èµé¸®´Â ºÎºÐ »©°í ´ÙÇß½À´Ï´Ù[9]     ahotsuna
05/04 1886
65   [1ȸ] recon - auditing source code ºÐÇÒ ÆÄÀÏÀÔ´Ï´Ù (ÃÑ 9°³)[8]     ¸Û¸Û
05/04 1877
64   À¯Æ©ºê µ¿¿µ»ó ¾÷·Îµå[3]     d4rkang3l
05/16 1856
63   Á¦ 1ȸ ¹ø¿ª ÀÚ¸· ´Þ¾ÆÁÖ½Ç ºÐ ã½À´Ï´Ù~[3]     ¸Û¸Û
05/25 1844
62   ¾ÕÀ¸·Î ¸®½º´×&¹ø¿ªÇϸé ÁÁ°Ú´Ù°í »ý°¢µÇ´Â µ¿¿µ»óµéÀÔ´Ï´Ù.     ¸Û¸Û
05/15 1828
61   ÀÚ¸· - darkangel´Ô °Í°ú lycan´Ô °Í ÅëÇÕ     ¸Û¸Û
06/22 1825
60   À§Å° ÆäÀÌÁö º¯°æ ¹× ¸ðµÎ ¸¸µé¾î ³õ°Ú½À´Ï´Ù. + ¸Û¸Û´Ô Çѹø ºÁÁÖ¼¼¿ä[1]     W.H.
05/13 1796
59   ¸¶Áö¸· ÆÄÆ® ÀÔ´Ï´Ù. ´Ê¾î¼­ Á˼ÛÇÕ´Ï´Ù. ¤¾[1]     k1rha
05/12 1787
58   6¹ø ÆÄÆ® ¾Èµé¸®´Â °Íµé ¸¹ÀÌ ¸øÇ߳׿䠠   ahotsuna
08/02 1785
57   µ¿¿µ»ó ÆÄÀÏÀÔ´Ï´Ù. <- ÀÌ µ¿¿µ»óÀº Á¤ÇØÁø µ¿¿µ»óÀÌ ¾Æ´Ï¿¡¿ä~~[8]     W.H.
05/27 1775
56   [°øÁö] Á¦ 1ȸ ¹ø¿ª ½ºÄÉÁìÀÔ´Ï´Ù. (ÁøÇà»óȲÀ» °¢ÀÚ ´ñ±Û·Î update)[10]     ¸Û¸Û
05/03 1772
55   [Á¦ 2ȸ] À¯Åõºê ¸µÅ©[1]     lycan
07/16 1767
54   ºÐÇÒµÈ µ¿¿µ»óÀ» À¯Åõºê¿¡ ¿Ã·ÁÁÖ½Ç ºÐ ã½À´Ï´Ù.[2]     ¸Û¸Û
05/15 1749
53   À§¿¡ ¸Û¸Û´ÔÀÌ ¿Ã¸®½Å µ¿¿µ»óÀ¸·Î ÀÛ¾÷ÇØÁÖ¼¼¿ä~ (ÀÌ °Ô½Ã¹°X)[21]     W.H.
05/03 1749
52   [1ȸ] ¿ªÇÒ ºÐ´ãÇÕ´Ï´Ù.[1]     ¸Û¸Û
05/03 1749
51   4¹ø ÆÄÆ® ¸®½º´×&¹ø¿ª ³»¿ëÀÔ´Ï´Ù.[1]     ¸Û¸Û
05/09 1748
50   1¹ø ÆÄÆ® ÀÏ´Ü Áö±Ý±îÁö ÇÑ°Å ¿Ã¸³´Ï´Ù.[2]     W.H.
05/10 1744
49   ÀÛ¾÷ÇÏ´Ù ¸·È÷½Å ºÐ, ±×¸®°í ÀÛ¾÷ ÇÒ´ç ¸ø¹ÞÀ¸½Å ºÐ ºÁÁÖ¼¼¿ä     ¸Û¸Û
05/06 1743
48   Á¦ 2ȸ ¹ø¿ª ÁøÇà»óȲ ´ñ±Û ¹Ù¶ø´Ï´Ù.[9]     ¸Û¸Û
08/02 1736
[1] 2 [3][4]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org