Flag: Tornado! Hurricane!

Blogs >> RolfRolles's Blog

Created: Wednesday, October 10 2007 14:24.15 CDT  
Printer Friendly ...
T2 2006 VM Analysis
Author: RolfRolles # Views: 4016

I've been intending to write a blog entry about dynamic approaches towards breaking VMs (as opposed to the pure static solution that I employed in my HyperUnpackMe2 article), but writer's block has kept me from finishing it.  I decided to go ahead and release the supplement to that forthcoming entry, which had been collecting dust on my hard drive for sixteen months, so here's part of my solution to the T2 challenge from 2006.  You still have work to do if you intend to complete that challenge.

The linked package contains an analysis of the VM, the logging DLL that I coded in order to generate a run trace of the VM program, and a sample output from the logger.  What's not in the package is any analysis of the VM program nor any of the code that I wrote to break it.  This was two days' worth of work, for which I earned ninth place in the contest.  

Hopefully the entry explaining this method will be published next week.




Add New Comment
Comment:









There are 28,228 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
cmathieu
Feb/07
Hacker Carnival

waleedassar
Feb/06
OllyDbg v1.10 And Hardware ...

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

waleedassar
Jan/13
An OllyDbg Bug Disables Sof...

More ...


Recent Blog Comments
waleedassar on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/05
Yet Another Anti-Debug Trick

trolotou on:
Feb/05
Doudoune Moncler -Pennies F...

waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit