📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

Blogs >> peter's Blog

Created: Monday, October 20 2008 19:52.52 CDT  
Direct Link, View / Make / Edit Comments
Hack In The Box '08
Author: peter # Views: 3283

For anyone heading to Hack In The box this year I will be there giving a talk entitled "Full Process Reconstitution from Memory" http://conference.hackinthebox.org/hitbsecconf2008kl/?page_id=175

If your curious about it and don't want to wait for my talk or you just want to meet up for drinks, drop me a line [email protected]

Created: Tuesday, July 10 2007 11:11.46 CDT  
Direct Link, View / Make / Edit Comments
Debug Strings
Author: peter # Views: 3421

Here is a fun debug string:
.text:00404396                 push    offset aConnectionSlow ; "connection slow.  Attempted DOS?"
.text:0040439B                 call    sub_404C50

You can get this debug message if you fragment a packet... =/

Created: Sunday, August 6 2006 12:28.30 CDT  
Direct Link, View / Make / Edit Comments
RAIDE - Blackhat
Author: peter # Views: 3739

Well i'm still recovering from Vegas. It was a blast i don't think even blackhat thought that many people would be there. I've posted the slides from our talk as well as the binaries. Enjoy.
Peter~

Created: Saturday, June 24 2006 17:08.46 CDT  
Direct Link, View / Make / Edit Comments
PAIMEIdiff
Author: peter # Views: 3857

Since we're on the heels of the PAIMEI release. I thought i'd post some screen shots (a teaser if you will) of the module I've been working for some time. Its called PAIMEIdiff I think the name sorta helps explain what it does. You can see the slides from pedram's talk for some more info on PAIMEIdiff. PAIMEIdiff went out as a beta today so hopefully with all the testing i can get a public version out in a week or two. Check out my repository for the screen shots.
Later'
Peter~

Created: Thursday, November 3 2005 21:45.35 CST Modified: Thursday, November 3 2005 22:07.21 CST
Direct Link, View / Make / Edit Comments
Sony Video
Author: peter # Views: 3332

Hey guys,

I've posted to my file repository a video of a BSOD in the Sony rootkit. This is such a minor vuln not sure I'll bother posting it to any lists and such but for your own amusement enjoy it. There maybe a root to come as well. We'll see what I got left in the gas tank.

I would like to thank:
Pedram, Greg, Ero, Jamie, and BB,TO,AC,CD,CL,MP (Initials to protect the innocent).


Archived Entries for peter
Subject # Views Created On
IDA Customs and Sony 1397     Thursday, November 3 2005

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit