Malware Development: System Calls

  Рет қаралды 48,192

crow

crow

Күн бұрын

Пікірлер: 134
@crr0ww
@crr0ww 10 ай бұрын
📌 Use code "CROW10" for 10% off your order when you checkout at Maldev Academy or use this link: maldevacademy.com/?ref=crow Font: Terminess Nerd Font Mono Colourscheme: Zero (Dark Theme) I sincerely hope you enjoyed watching this installment of our ongoing malware development series. I know the kernel debugging portion was a bit rushed, and for that, I apologize. I had an entire segment dedicated to kernel debugging, the intricacies of MSRs as well as the incredible CPUID instruction, and all of that planned out for this video but as you could imagine, had I included that, the video would be a month-long. So instead, I'm working on a blog post that will take you into harrowing depths of that entire process, so make sure you look out for it here: www.crow.rip/ ERRATA: - I just realized after rewatching this that I was doing "CONST LPCSTR" when that's not necessary at all since LPCSTR is literally: "typedef const char* LPCSTR;" HAHAHAH LOSING MY MIND tysm for watching, nerds. luv u all terribly
@C5pider
@C5pider 10 ай бұрын
Oh mom look i made it into a crow video.
@mohammadalihanfi8237
@mohammadalihanfi8237 10 ай бұрын
Yeah as expected 😅
@crr0ww
@crr0ww 10 ай бұрын
:blushing_emoji:
@b3twiise853
@b3twiise853 10 ай бұрын
Ohh look it is spider
@Dnsx_plus
@Dnsx_plus 10 ай бұрын
Aren’t you one of the contributors to Maldev Academy?
@gato4920
@gato4920 10 ай бұрын
Have not even made it this far in the series, but I had to show support. Keep it up, we appreciate you.
@crr0ww
@crr0ww 10 ай бұрын
i really appreciate that! thank you so much
@gamerkarir306
@gamerkarir306 10 ай бұрын
omg you gave me a hart attack with the fear and hunger sound 1:25
@crr0ww
@crr0ww 10 ай бұрын
XDD
@bamboooz3201
@bamboooz3201 10 ай бұрын
I am a web developer, i don't understand anything, but i love these videos, keep it up!
@crr0ww
@crr0ww 10 ай бұрын
aw thank you
@jaitjacob
@jaitjacob 10 ай бұрын
babe wake up crow just uploaded a new malware video
@crr0ww
@crr0ww 10 ай бұрын
WAKE BABE UP, WE HAVE MALWARE TO MAKE
@user-ik4px2cu1l
@user-ik4px2cu1l 10 ай бұрын
I literally just finished watching your Native API video and now you upload this, - literally GOD.
@sxmourai6897
@sxmourai6897 10 ай бұрын
I'm currently making an os and it's great to see the point of view of the userland people on the other side =) + I've learned some stuff, it's grealty explained, continue like that !
@crr0ww
@crr0ww 10 ай бұрын
thank you so much! :)
@Babachick3n
@Babachick3n 3 ай бұрын
Literally the Dale Philip of the hacking world
@Raxis
@Raxis 10 ай бұрын
Hell yes another crow video! Still need to go back and catch up on the previous vid but it's great seeing more stuff from you!
@UnhandledErrorWasTaken
@UnhandledErrorWasTaken 10 ай бұрын
Man!!! Finally a new video :D Didn't still watched it entirely but it's obviously gonna be fantastic. Ik doing this videos takes time and commitment but please do them more often ahah!
@crr0ww
@crr0ww 10 ай бұрын
thank you so much!! yeah it's a ton of work but your response(s) make all of the grey hairs super worth it :)
@t32prod.98
@t32prod.98 10 ай бұрын
just came across your page by pure chance and watched your processes, handles, and threads video. headed over to your website and your statement in the faq section was very wholesome and encouraging. thank you for documenting your journey and having a positive outlook for newcomers :) deff earned my sub and a bookmark to your blog.
@deleted_account-u3w
@deleted_account-u3w 10 ай бұрын
Your videos are so good, my tiny brain can finally understand all this stuff. Keep it up!
@4sakenGol3m
@4sakenGol3m 7 ай бұрын
Your LOCO❤😂 4:16 Love the content; keep up the incredible work!
@phantompuma228
@phantompuma228 10 ай бұрын
NEW CROW VID?? LETS GOOO
@crr0ww
@crr0ww 10 ай бұрын
@christian_leone
@christian_leone 10 ай бұрын
Nice vid as always crow, thanks
@crr0ww
@crr0ww 10 ай бұрын
thank you so much! i'm really happy you liked it :)
@tablettablete186
@tablettablete186 10 ай бұрын
This is why we need syscall kernel interception like we do in Linux with SECCOMP. Great video by the way!
@jonas-ke4qz
@jonas-ke4qz 4 ай бұрын
This editing is awesome
@muha0644
@muha0644 10 ай бұрын
Man you gotta make more videos, you're the new liveoverflow but more funny and less serious.
@crr0ww
@crr0ww 10 ай бұрын
thank you so much for your comment; I really appreciate that! liveoverflow's the GOAT tho :')
@muha0644
@muha0644 10 ай бұрын
@@crr0ww yeah, he is! But ever since he started using his face on camera his videos seem too "formal" or professional. More like John Hammond, but if he was German I guess...
@MeharKlair
@MeharKlair 10 ай бұрын
He's finally back after his hibernation
@QnF5EPuArXEX3bP
@QnF5EPuArXEX3bP 8 ай бұрын
I've just discovered your channel and OMG keep it up man, you're a GEMMMM
@Negalijus370
@Negalijus370 10 ай бұрын
Inspiring next generation of Greybeards ⚡⚡
@EnLopXf
@EnLopXf 10 ай бұрын
Yow the legend is back!!
@rosehacksyoutube
@rosehacksyoutube 10 ай бұрын
Quality! Your channel is going to blow up.
@faanross
@faanross 10 ай бұрын
He’s back!
@crr0ww
@crr0ww 10 ай бұрын
hey!! thank you so much for commenting, brother! i LOVE your videos as well, such a unique style! keep up the GREAT work, you'll get really far I can already tell
@faanross
@faanross 10 ай бұрын
@@crr0ww 🖤
@zombieboyxx
@zombieboyxx 3 ай бұрын
"If your prefrontal cortex misses a QuickTime event" 😂😂😂 you have to be the funniest cybersec youtuber
@madezra64
@madezra64 10 ай бұрын
What's the music at 11:50? Starts a little earlier then that but Shazam as failing me cause it's copyright free music :(
@VloggerMan-if9bt
@VloggerMan-if9bt Ай бұрын
seeing him go from using vscode to neovim was better than watching my child grow up
@azdirtnaper
@azdirtnaper 10 ай бұрын
I love watching these even though I don't understand any of the shit that is going on lmaooo
@11superjump
@11superjump 10 ай бұрын
this video taught me a lot, love it :)
@crr0ww
@crr0ww 10 ай бұрын
ah, great!! that means i've done my job haha thank you so much for commenting
@HTWwpzIuqaObMt
@HTWwpzIuqaObMt 10 ай бұрын
Welcome back ❤
@crr0ww
@crr0ww 10 ай бұрын
@gwnbw
@gwnbw 22 күн бұрын
27:54 lowkey flex, interesting vids!
@vizzil1675
@vizzil1675 10 ай бұрын
I just finished my os class. Really love it haha
@noorkhara1429
@noorkhara1429 10 ай бұрын
HES BACKKKKK !!!!! 🎉🎉🎉🎉
@crr0ww
@crr0ww 10 ай бұрын
@dadamnmayne
@dadamnmayne 10 ай бұрын
Thank you. Prob going to watch this at least 100 times.
@crr0ww
@crr0ww 10 ай бұрын
i appreciate you, brother! thank you so so much
@dadamnmayne
@dadamnmayne 10 ай бұрын
@@crr0ww 19:01 that API hooking/unhooking video tho... 🙏
@korsate
@korsate 10 ай бұрын
YAYAYAYAYAYA MY GOAT UPLOADED
@MeharKlair
@MeharKlair 10 ай бұрын
CROW SIR SIR CROW YESSSSSSSSSSSSSS
@nobody-m6f
@nobody-m6f 2 ай бұрын
what is the fond and IDE that you are using?
@alec3217
@alec3217 10 ай бұрын
LESS FUCKING GOOOOOOOOO, new crow vid
@crr0ww
@crr0ww 10 ай бұрын
@alec3217
@alec3217 10 ай бұрын
@crr0ww do you have a discord server or something similar?
@gwnbw
@gwnbw 22 күн бұрын
Hows your font so smooth looking though? mine looks crispy like extra sharpened
@Beryesa.
@Beryesa. 10 ай бұрын
Operation Tux continues 😅
@lime5233
@lime5233 10 ай бұрын
FINALLY A VIDEO
@rz0007-k4c
@rz0007-k4c 10 ай бұрын
_
@crr0ww
@crr0ww 10 ай бұрын
HAHAHAHA LETS GOOOOO i wrote it down on some sticky notes so I don't forget it again :')
@rz0007-k4c
@rz0007-k4c 10 ай бұрын
@@crr0ww 😂♥
@stolfoch.
@stolfoch. 10 ай бұрын
mr crow i love you
@dompurified
@dompurified 10 ай бұрын
mom, look! cr0w uploaded!
@backinyourcommentsectionag3191
@backinyourcommentsectionag3191 10 ай бұрын
CROW WHERE HAVE YOU BEEN I MISS YOU LOVE
@honestsniping1
@honestsniping1 10 ай бұрын
Aren't all variables saved in the .TEXT section either way? Why did he manually added that code at 29:00?
@nikhilt3755
@nikhilt3755 9 ай бұрын
variables go into .data section. if we specify to allocate in .text section then contents of our variable can be executed because .text section is executable by default
@honestsniping1
@honestsniping1 9 ай бұрын
Thanks for the reply. But if I define the shellcode variable inside main(), it will be located in .TEXT and not .DATA. And after your logic, it would mean that shellcodes defined in the global section of the program (not within main) cannot be executed. I'm probably missing something here...
@ferverrel5519
@ferverrel5519 10 ай бұрын
Used your promo for the maldev academy baby!
@arnabthakuria2243
@arnabthakuria2243 10 ай бұрын
Great vid as always. What font is that ?
@nightlockhayze
@nightlockhayze 10 ай бұрын
Crow why did you just ignore us and drop this new video asdjasdhakjdadasda ily always
@czerwonejakmleko401
@czerwonejakmleko401 10 ай бұрын
does anyone know what font he uses?
@meharklair3755
@meharklair3755 10 ай бұрын
CROW CROW CROW
@meharklair3755
@meharklair3755 10 ай бұрын
i would like to inject my malware into crow :3
@crr0ww
@crr0ww 10 ай бұрын
BAHAHAHAHAHA
@HelpersSoftware
@HelpersSoftware 10 ай бұрын
Awesome ❤ Thanks!What a theme name in visual studio bro?
@vesmirnyjay
@vesmirnyjay 10 ай бұрын
touching everything
@crr0ww
@crr0ww 10 ай бұрын
😭
@mnesicles.
@mnesicles. 10 ай бұрын
Sos un capo cuervito. Excelente contenido ✨
@tracetv8115
@tracetv8115 10 ай бұрын
A video about antivirus intrusion would be nice.
@Trikstarck
@Trikstarck 10 ай бұрын
Let’s GOOOOOO 🎉🎉🎉🎉🎉🎉
@PlanetComputer
@PlanetComputer 10 ай бұрын
thanks crow
@crr0ww
@crr0ww 10 ай бұрын
it's my pleasure
@mohammedzaid6634
@mohammedzaid6634 10 ай бұрын
Hey crow whats up man ✋
@crr0ww
@crr0ww 10 ай бұрын
hey!! how are you :P
@ericytff7388
@ericytff7388 10 ай бұрын
MORE TUTORIALLS WE SHALL SEE
@dneial.
@dneial. 10 ай бұрын
Can anyone link the equivalent of this but on Mac plz 🤗
@gordonfreimann
@gordonfreimann 10 ай бұрын
whats your font in vs?
@mastergame1599
@mastergame1599 4 ай бұрын
+1
@hiddengo3232
@hiddengo3232 8 ай бұрын
how to modify exploit code
@illumin8-r
@illumin8-r 10 ай бұрын
all your syscalls are belong to us
@GHOST-qx6wi
@GHOST-qx6wi 10 ай бұрын
finally
@brunom12111
@brunom12111 10 ай бұрын
that's my goat right there
@DaxSudo
@DaxSudo 10 ай бұрын
All of this just serves my point. The NT Kernel f***ing sucks balls.
@hell0kitje
@hell0kitje 10 ай бұрын
MOB PSYCHO 100!
@fodk7021
@fodk7021 10 ай бұрын
What do you mean ?
@hell0kitje
@hell0kitje 10 ай бұрын
@@fodk7021 its anime.
@fodk7021
@fodk7021 10 ай бұрын
@@hell0kitje yes but where is it in the video.
@hell0kitje
@hell0kitje 10 ай бұрын
@@fodk7021 its in thumbail
@fodk7021
@fodk7021 10 ай бұрын
@@hell0kitje I thought it was midoriya from my hero academia
@DM-qm5sc
@DM-qm5sc 10 ай бұрын
Imagine calling pantaloons trousers LuL
@synrage
@synrage 10 ай бұрын
finally bro
@jacobjohnson1501
@jacobjohnson1501 10 ай бұрын
heyyo you're alive ?
@crr0ww
@crr0ww 10 ай бұрын
YESSIR!!! :)
@4sakenGol3m
@4sakenGol3m 7 ай бұрын
WTF 9:56 😂😂😂😂😂😂😂😂
@raven-vr5yz
@raven-vr5yz 10 ай бұрын
yo man nice nickname
@crr0ww
@crr0ww 10 ай бұрын
thank you RAVEN, nice nickname as well, RAVEN :>
@uh3906
@uh3906 10 ай бұрын
Lmao just thought about you yesterday
@FictionHubZA
@FictionHubZA 10 ай бұрын
Nice
@lumikarhu
@lumikarhu 10 ай бұрын
a more in-depth video on indirect syscalls would be great, im not sure everything was covered, noob here. i can only cross check with the maldevs module. PS. i came with the power of thousand suns, you should get exclusive rights for maldev sponsoring, why watch boring jurassic park man when crow videos exist? lmfao please mr. d0x do this, the world will be a better place if crow becomes THE teacher. me not knowing C and low level programming well had some difficulties understanding the material but now so much has gotten clearer it's not even funny. ILY Crow
@snapshot8886
@snapshot8886 10 ай бұрын
Bro!!!
@nordgaren2358
@nordgaren2358 10 ай бұрын
Lmao. Urien spotted.
@marcelocabral389
@marcelocabral389 5 ай бұрын
I'm not gonna lie, i didn't understand almost anything from the video, this "layer" of execution in assembly code and things written in hexadecimal gave me a headache, great video anyway!
@SpYlE-
@SpYlE- 10 ай бұрын
bro.. iam from bangldesh ..plzz make more video
@sinatra02
@sinatra02 10 ай бұрын
a group of crows are called a murder... are we, as your fan base... murderers?
@mongru
@mongru 10 ай бұрын
ah yes here i am again
@crr0ww
@crr0ww 10 ай бұрын
and i'm so happy u are
@lavender0666
@lavender0666 10 ай бұрын
hot
@Mika_565
@Mika_565 10 ай бұрын
Thats cool but how do I get free robux
@crr0ww
@crr0ww 10 ай бұрын
YOU THINK I'M AT *THAT* LEVEL, MIKA? THAT'S TOO ADVANCED FOR ME!1:$!$:
@cagdasisk7640
@cagdasisk7640 10 ай бұрын
ur the best
@meharklair3755
@meharklair3755 10 ай бұрын
crow is so sexy
@theexplosionist2019
@theexplosionist2019 10 ай бұрын
I don't understand what you're trying to achieve. You can't do "useful" functions such as virtualalloc or openprocess to modify processes' memory without admin access. Inline assembly works in VS2022 just fine. I was thinking rax is the GetProcAddress but its a special number. That makes using syscall even more pointless. unsigned long long count = 9; __asm { mov rax, 31H lea r10, count xor edx,edx xor r8d, r8d xor r9d, r9d sub rsp,40 syscall add rsp,40 } std::cout
@lumikarhu
@lumikarhu 10 ай бұрын
psst hey kid, wanna buy some skooma?
@Sp00ky__12
@Sp00ky__12 13 күн бұрын
cool ass dude
@Bo_om2590
@Bo_om2590 10 ай бұрын
do you have a job? what is it?
@imahotdogdonteatme8722
@imahotdogdonteatme8722 10 ай бұрын
Holy shit! I thought yt assasinated him!
@crr0ww
@crr0ww 10 ай бұрын
THEY GOT REALLY *REALLY* close 😓 still have more videos to make, can't stop now :')
Malware's LAST Stand: SELF-DELETION
1:01:58
crow
Рет қаралды 57 М.
Buffer Overflows: A Symphony of Exploitation
30:18
crow
Рет қаралды 78 М.
Andro, ELMAN, TONI, MONA - Зари (Official Audio)
2:53
RAAVA MUSIC
Рет қаралды 8 МЛН
ССЫЛКА НА ИГРУ В КОММЕНТАХ #shorts
0:36
Паша Осадчий
Рет қаралды 8 МЛН
Breaking Bitlocker - Bypassing the Windows Disk Encryption
9:11
stacksmashing
Рет қаралды 1 МЛН
The Dome Paradox: A Loophole in Newton's Laws
22:59
Up and Atom
Рет қаралды 740 М.
(In)direct Syscalls: A Journey From High To Low - Daniel Feichter
27:22
Intro to Syscalls for Windows Malware
1:09:00
Prelude
Рет қаралды 17 М.
START HACKING: 10 Skills For BEGINNERS!
19:07
crow
Рет қаралды 59 М.
Malware Development: Processes, Threads, and Handles
31:29
An Introduction to Malware Analysis
1:10:01
crow
Рет қаралды 51 М.
How This Algorithm PROTECTS YOU
11:55
crow
Рет қаралды 18 М.