Unpack Shellcode w/ Ghidra Emulator | Decode XOR Dynamically🔥

  Рет қаралды 2,686

stryker2k2

stryker2k2

Күн бұрын

Here's the deal. We've been asked to Reverse Engineer this program called 'payload'. It does nothing when we run it... but... in the background, it is calling back to someone's Kali Linux machine and they have an open shell.
Yet, when we throw it into Ghidra, we are greated with an "Bad Instruction" message and a do-while loop that performs an XOR through-out the entirety of the executable. We're blind.
We will be following along with Craig Young's Blog Post to find out the best way to reverse engineer and unpack the embeded shellcode!
Enough talking, let's get hacking!
Unpacking Shellcode with Ghidra Emulator
/ unpacking-shellcode-wi...
NVIDIA Broadcast 1.4 Eye Contact Effects
www.nvidia.com/en-us/geforce/...
0:00 Intro
0:23 Summary
2:22 Payload Generation
6:12 CodeBrowser Static Analysis
8:43 Emulator Dynamic Analysis
15:16 Exporting Decoded Data
17:17 Automatic Analysis of System Calls
22:22 Manual Analysis of System Calls
25:42 Conclusion

Пікірлер: 13
@andreasschommer5435
@andreasschommer5435 Жыл бұрын
Thanks alot. I hope to see more content like this from your in the future - you're doing great explaining concepts in an approachable way.
@stryker2k2
@stryker2k2 Жыл бұрын
I'm glad you enjoyed it!
@deathxe5
@deathxe5 11 ай бұрын
Cool vid, thanks for sharing!
@eltonsetan6045
@eltonsetan6045 8 ай бұрын
I'm a beginner in security and you explain very well. Thanks!
@stryker2k2
@stryker2k2 5 ай бұрын
My pleasure!
@LukeAvedon
@LukeAvedon 5 ай бұрын
Those were neat sunglasses
@stryker2k2
@stryker2k2 4 ай бұрын
Dollar Store Sunglasses for the win!
@MohamedTarek-em9rb
@MohamedTarek-em9rb 11 ай бұрын
i'am from Egypt ..thanks alot
@massimobevilacqua8640
@massimobevilacqua8640 Жыл бұрын
Fantastic tutorial, do you have anything for disassembling TriCore processors?
@stryker2k2
@stryker2k2 5 ай бұрын
Thanks! And, nope... I am not that smart on TriCore processors (yet).
@dewmi4403
@dewmi4403 Жыл бұрын
ohh yeah!
@stryker2k2
@stryker2k2 Жыл бұрын
Dew mi!
@dewmi4403
@dewmi4403 11 ай бұрын
@@stryker2k2 Owi OWi OWi
Ghidra Emulator | New Tool in 10.3!
13:34
stryker2k2
Рет қаралды 6 М.
Elon Musk fires employees in twitter meeting DUB
1:58
GeoMFilms
Рет қаралды 12 МЛН
Dynamic #gadgets for math genius! #maths
00:29
FLIP FLOP Hacks
Рет қаралды 19 МЛН
🍟Best French Fries Homemade #cooking #shorts
00:42
BANKII
Рет қаралды 42 МЛН
CAN YOU HELP ME? (ROAD TO 100 MLN!) #shorts
00:26
PANDA BOI
Рет қаралды 36 МЛН
CD Key Hack | Delta Force (1998)
0:57
stryker2k2
Рет қаралды 987
Reversing CrackMe with Ghidra (Part 1)
38:19
stryker2k2
Рет қаралды 40 М.
Intro to Shellcode Analysis: Tools and Techniques
59:49
SANS Digital Forensics and Incident Response
Рет қаралды 14 М.
x64dbg Demo | CrackMe Challenges
46:33
stryker2k2
Рет қаралды 30 М.
ECU hacking, finding DTC's with GHIDRA and winOLS. denso SH7058
6:42
everything is open source if you can reverse engineer (try it RIGHT NOW!)
13:56
Low Level Learning
Рет қаралды 1,2 МЛН
Ghidra quickstart & tutorial: Solving a simple crackme
11:30
stacksmashing
Рет қаралды 323 М.
Learn Reverse Engineering (for hacking games)
7:26
cazz
Рет қаралды 971 М.
Installing Ghidra 10 on Windows 10
17:22
stryker2k2
Рет қаралды 10 М.
Карточка Зарядка 📱 ( @ArshSoni )
0:23
EpicShortsRussia
Рет қаралды 518 М.
😱НОУТБУК СОСЕДКИ😱
0:30
OMG DEN
Рет қаралды 3,1 МЛН
МОЖНО ЛИ заряжать AirPods в чехле 🧐😱🧐 #airpods #applewatch #dyson
0:22
Apple_calls РЕПЛИКА №1 В РФ
Рет қаралды 23 М.