Twitter | Pretraživanje | |
Jacob Pimental
New article on using Let me know what you guys think!
Linux is one of my favorite operating systems, but you seldom see malware for it, so I was pretty interested when Linux Malware was caught…
Medium Medium @Medium
Reply Retweet Označi sa "sviđa mi se" More
MrAdminus 2. velj 2018.
Odgovor korisniku/ci @Jacob_Pimental @7ur7l3_61rl
Ok that's way over my knowledge, have no clue..
Reply Retweet Označi sa "sviđa mi se"
Jacob Pimental 2. velj 2018.
Odgovor korisniku/ci @MrAdminus @7ur7l3_61rl
What are you confused about? Maybe I can help
Reply Retweet Označi sa "sviđa mi se"
Jacob Pimental 2. velj 2018.
Awesome! Glad you liked it and that it was easy enough to understand for people new in the field!
Reply Retweet Označi sa "sviđa mi se"
Maxime Morin 2. velj 2018.
Odgovor korisniku/ci @Jacob_Pimental
I would use e scr.utf8=true also normally if you enable comments you would see the ASCII directly in the disassembly. You can also use ahi s @ the offset of the cmp. For the base 2 calculation you could use ? or rax2. And r2pipe with cmdj("aoj") for the script ;)
Reply Retweet Označi sa "sviđa mi se"
Jacob Pimental 2. velj 2018.
Odgovor korisniku/ci @Maijin212
Yeah,I had some of the comments disabled for the sake of getting the pictures for the article. I did use rax2 for a lot of things too, but didn't mention it as I went over it in other articles. Thanks for the tips though, will keep them in mind for next analysis!
Reply Retweet Označi sa "sviđa mi se"
🐲 Turtle Girl 🐉 2. velj 2018.
Odgovor korisniku/ci @Jacob_Pimental
Very cool 😎
Reply Retweet Označi sa "sviđa mi se"
Jacob Pimental 2. velj 2018.
Odgovor korisniku/ci @7ur7l3_61rl
Thank you!
Reply Retweet Označi sa "sviđa mi se"
Maxime Morin 2. velj 2018.
Odgovor korisniku/ci @Jacob_Pimental @radareorg
Use instead of to tag article ;)
Reply Retweet Označi sa "sviđa mi se"
Jacob Pimental 2. velj 2018.
Odgovor korisniku/ci @Maijin212 @radareorg
Ah, ok. Will do next time!
Reply Retweet Označi sa "sviđa mi se"
Jonathan Lassoff 3. velj 2018.
Odgovor korisniku/ci @Jacob_Pimental
This was fun to see into. I love just about everything that uses radare2. However I don't think this shows why homebrew encryption is a bad idea. If this had a more well-known block cipher with a baked-in key, it would be just as reversible.
Reply Retweet Označi sa "sviđa mi se"
Jonathan Lassoff 3. velj 2018.
Odgovor korisniku/ci @Jacob_Pimental
If anything, I would call what this is doing "obfuscation".
Reply Retweet Označi sa "sviđa mi se"