The Basics of Overlays in PE Files

  Рет қаралды 3,346

Dr Josh Stroschein - The Cyber Yeti

Dr Josh Stroschein - The Cyber Yeti

Күн бұрын

Пікірлер: 20
@vineetchauhan1144
@vineetchauhan1144 3 ай бұрын
Amazing ❤❤❤ thanks
@jstrosch
@jstrosch 3 ай бұрын
You're welcome 😊
@johnnywilliams2641
@johnnywilliams2641 2 ай бұрын
Does OLE in windows have anything to do with overlays?
@jstrosch
@jstrosch 2 ай бұрын
Not directly, no. I suppose an OLE object could be stored in an overlay, since they are just arbitrary content beyond the end of a "normal" PE file.
@amnaaldh9911
@amnaaldh9911 8 ай бұрын
Weirdly, the overlay cannot be extracted but great contents
@jstrosch
@jstrosch 7 ай бұрын
Depends on what you are using to analyze the PE file. I don't recall exactly what I said in this video so perhaps you're referring to a comment, but some tools make it easy to extract while others require a bit more work :)
@ciaobello1261
@ciaobello1261 Жыл бұрын
As always, an informative video
@jstrosch
@jstrosch Жыл бұрын
Glad you think so!
@paveekazhagana3106
@paveekazhagana3106 Жыл бұрын
Very Useful
@jstrosch
@jstrosch Жыл бұрын
Glad you found it helpful!
@christiangualteros36
@christiangualteros36 Жыл бұрын
Thank you
@jstrosch
@jstrosch Жыл бұрын
You're welcome!
@blueteams5495
@blueteams5495 Жыл бұрын
Thanks Josh for another informative video, Can you pls provide sample hash in description if possible.
@jstrosch
@jstrosch Жыл бұрын
Added - thanks for the reminder! You can find most, if not all, of the samples I use on the Malware Bazaar by AbuseCH.
@blueteams5495
@blueteams5495 Жыл бұрын
@@jstrosch Thanks of reply. I have question regarding overlays. If pe file contains valid digitalSiganture and if we try to add overlay to it, Will it be still valid digitalsignature or invalid?
@jstrosch
@jstrosch Жыл бұрын
@@blueteams5495 Hm, interesting question. I'm not sure off-hand, I would think that if there is a signature and you added an overlay, disregarding that sig, you would simply overwrite it. It looks like you can locate the digital signature and it's size via the Data Directory structures in the image_optional_header structure, so my thoughts are that you could append additional overlay data beyond that (xstackoverflow.com/questions/47646135/where-is-the-digital-signature-stored-when-code-signing-a-exe-file-in-windows). But, I haven't had a chance to try it out... so just a working theory at this point :)
@davidvamei218
@davidvamei218 Жыл бұрын
Nice can you please analyze XLL add-in
@jstrosch
@jstrosch Жыл бұрын
I’ll take a look and add it to my content schedule :)
@zebulonsaloum9935
@zebulonsaloum9935 Жыл бұрын
Excellent content!!! You could get the engagement you deserve with *Promosm*!!
@jstrosch
@jstrosch Жыл бұрын
Thanks :) What do you mean by promos though…?
The AddressOfEntryPoint and Tips for Finding Main
13:17
Dr Josh Stroschein - The Cyber Yeti
Рет қаралды 1,4 М.
🎥 Analyzing Portable Executable Files with PEStudio
1:12:09
Dr Josh Stroschein - The Cyber Yeti
Рет қаралды 17 М.
Как Я Брата ОБМАНУЛ (смешное видео, прикол, юмор, поржать)
00:59
Натурал Альбертович
Рет қаралды 3,9 МЛН
ТВОИ РОДИТЕЛИ И ЧЕЛОВЕК ПАУК 😂#shorts
00:59
BATEK_OFFICIAL
Рет қаралды 6 МЛН
Don't underestimate anyone
00:47
奇軒Tricking
Рет қаралды 18 МЛН
how is this hacking tool legal?
11:42
Low Level
Рет қаралды 408 М.
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН
Get Started With Ethical Hacking: Beginner To Master
15:47
Luke Dexter
Рет қаралды 7 М.
02 - Performing Basic Triage Analysis and Unpacking with x64dbg
20:30
Dr Josh Stroschein - The Cyber Yeti
Рет қаралды 1,1 М.
🔴 Portable Executable Files: Analyzing In-Memory versus On Disk
38:01
Dr Josh Stroschein - The Cyber Yeti
Рет қаралды 4 М.
Learn and use PowerShell with just three commands - OLD
13:26
TechThoughts
Рет қаралды 251 М.
Running a Buffer Overflow Attack - Computerphile
17:30
Computerphile
Рет қаралды 2 МЛН
03 - Identifying Signs of Runtime-Linking and Building Context for API Hashes
16:25
Dr Josh Stroschein - The Cyber Yeti
Рет қаралды 671
this Cybersecurity Platform is FREE
39:46
John Hammond
Рет қаралды 592 М.
Как Я Брата ОБМАНУЛ (смешное видео, прикол, юмор, поржать)
00:59
Натурал Альбертович
Рет қаралды 3,9 МЛН