Lost your password?

Blogs about: Reverse Code Engineering

Featured Blog

Swimming into Trojan and Rootkit GameThief.Win32.Magania Hostile Code

evilcodecave wrote 1 month ago: Redirection: http://evilcodecave.blogspot.com/2009/10/swimming-into-trojan-and-rootkit.html Regards, … more →

Tags: hostile code, malware analysis, Malware Reverse Engineering, megania, Reverse Engineering, Rootkit, trojan, Trojan-GameThief.Win32.Magania

P-Code Opcodes List

antelox wrote 1 month ago: I have backuped a Database of P-Code Opcodes so it can help you and me to reverse a VB program makes … more →

Device Drivers Vulnerability Research, Avast a real case10 comments

evilcodecave wrote 2 months ago: In the past days I worked intensively on Antivirus’s Device Drivers bugs, at the actual state … more →

Tags: Insecurity, C / C++ (Visual Studio Based) Coding, Debugging & Disassembling, Driver Coding, Bug, Device Drivers Vulnerability Research, kernel mode, real case

Vista IRP Struct with offset references for consult

evilcodecave wrote 2 months ago: Redirection: http://evilcodecave.blogspot.com/2009/09/vista-irp-struct-with-offset-references.html … more →

Tags: Driver Coding, Device Drivers, IRP Struct, Reverse Engineering, Reversing, vista kernel

Vista Tp* Thread Pool Functions

evilcodecave wrote 2 months ago: Redirection: http://evilcodecave.blogspot.com/2009/09/vista-tp-functions.html … more →

Tags: Debugging & Disassembling, thread pool, threadpool, TP

Vista's TEB Struct with offset for handy consult

evilcodecave wrote 2 months ago: Redirection: http://evilcodecave.blogspot.com/2009/09/vistas-teb-struct-with-offset-for-handy.html R … more →

Tags: TEB struct, vista kernel, _TEB

Pills of Reversing - new PEB/_TEB members who uses it ?

evilcodecave wrote 2 months ago: Redirection: http://evilcodecave.blogspot.com/2009/09/pills-of-reversing-new-pebteb-members.html … more →

Tags: DbgUiRemoteBreakin, RtlInitializeExceptionChain, RtlIsCurrentThreadAttachExempt, vista kernel, win7 kernel

How fastly bypass Hostile Code for Trojan-GameThief.Win32.Magania

evilcodecave wrote 2 months ago: http://evilcodecave.blogspot.com/2009/08/how-fastly-bypass-hostile-code-for.html Regards, Giuseppe … more →

Tags: Insecurity, DALXBHDFGERTONGOJK_POP, nmdfgds0.dll, olhrwef.exe, PolyEnE 0.01+ by Lennart Hedlund, RavMon.exe, Trojan-GameThief.Win32.Magania, Unpacking

How to debug a process created by another one

evilcodecave wrote 3 months ago: Redirection: http://evilcodecave.blogspot.com/2009/08/how-to-debug-process-created-by-another.html R … more →

Malware - 26xpl SSH Propagating Exploit Pack

evilcodecave wrote 3 months ago: Redirection to my second blog: http://evilcodecave.blogspot.com/2009/08/malware-26xpl-ssh-propagatin … more →

Tags: Debugging & Disassembling, Insecurity, malware analysis, ssh, 2.6.13, 2.6.17.4 + 2.6.9-22.ELsmp systems, 26, A. Sh., backdoor shogai

Linux Process Memory Dumper in Python

evilcodecave wrote 3 months ago: Redirection: http://evilcodecave.blogspot.com/2009/08/linux-process-memory-dumper-in-python.html Reg … more →

Tags: C / C++ (Visual Studio Based) Coding, Linux Process Memory Dumper, Python

How to solve GetFileVersionInfo Crashes a Qt Implementation

evilcodecave wrote 3 months ago: Redirection: http://evilcodecave.blogspot.com/2009/08/getfileversioninfo-crashes-qt.html Regards, Gi … more →

Tags: C / C++ (Visual Studio Based) Coding, crash, Qt, GetFileVersionInfo, qfsfileengine_win.cpp, VS_FIXEDFILEINFO

W32/Skintrim Reverse Engieering - Functional Analysis1 comment

evilcodecave wrote 3 months ago: Redirection: http://evilcodecave.blogspot.com/2009/08/w32skintrim-reverse-engieering.html Regards … more →

TheGreenBow VPN Client tgbvpn.sys DoS and Potential Local Privilege Escalation Vulnerability.

evilcodecave wrote 3 months ago: Hi, Redirection: http://evilcodecave.blogspot.com/2009/08/thegreenbow-vpn-client-tgbvpnsys-dos.html … more →

Tags: Driver Coding, Insecurity, Vulnerability, Bug, DOS, Potential Local Privilege Escalation, tgbvpn.sys, TheGreenBow, VPN Client

W32/Skintrim Reverse Engieering of a Badly Coded Malware #4

evilcodecave wrote 3 months ago: Redirection: http://evilcodecave.blogspot.com/2009/08/w32skintrim-reverse-engieering-of-badly.html R … more →

Tags: malware, Reverse Engineering, Skintrim

SSH Malware Analysis - udp.pl, Juno and Stealth ELFs Reversing

evilcodecave wrote 3 months ago: Redirection: SSH Malware Analysis – udp.pl, Juno and Stealth ELFs Reversing Regards, Giuseppe … more →

Tags: Insecurity, malware analysis, bot, botnet, Bruteforce Attack, dDos attacks, flood.tgz, juno, spamming

RFI Malware Analysis - Ascrimez Hacking Kit - Notifier

evilcodecave wrote 3 months ago: Redirection http://evilcodecave.blogspot.com/2009/08/rfi-malware-analysis-ascrimez-kit.html Regards, … more →

Tags: Insecurity, rbn, Russian Bank Network, Reverse Engineering, malware analysis, rfi malware, r57 shell, hacking kit, ascrimez

Malware - How Works Trojan.PHPInfo

evilcodecave wrote 3 months ago: Hi, Redirection to my blogspot http://evilcodecave.blogspot.com/2009/08/malware-how-works-trojanphpi … more →

Tags: Reverse Engieering, Trojan.PHPInfo, Web Malware, Malicious php script, rfi malware

Malware Trojan-Spy.Win32.Zbot low detection rate - Fast Analysis

evilcodecave wrote 3 months ago: The usual redirection to my second blog.. http://evilcodecave.blogspot.com/2009/08/malware-zbot-low- … more →

Tags: Reverse Engineering, malware analysis, Trojan-Spy.Win32.Zbot, ZBot


Have your say. Start a blog.

See our free features →

Related Tags
All →

Follow this tag via RSS