📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

Blogs >> Piotr's Blog

Created: Tuesday, September 18 2007 10:01.00 CDT Modified: Tuesday, September 18 2007 10:32.30 CDT
This is an imported entry. View original. Printer Friendly ...
SpiderPig and The Childs.
Author: Piotr # Views: 3007

It has been a while since ive published first post about SpiderPig, currently i think i may found a really suitable solution for speeding up the process (as far as it can be speeded). Also i think i will power off the emulator and exchange it with SpiderPig mini regions, i just need to find a way to describe specified regions result basing on the defined object appearance and intersection, thats bit messy for current time being.

Also ive made some simple screenshots regarding child objects creation, generally thats based on some intersection rules and it can support currently 8/16/32 bit mode, but without FPU and MMX stuff, i may think about including support the FPU stuff since many cool Media apps are using it :) Clickable graphs are out of the scope right now.

Im starting to developing new SpiderPig model next week, so maybe i will shoot something here.

Some child graphs, we start with 0x402000 as protected memory:

# EXAMPLE 1 (click to expand)







# EXAMPLE 2 (click to expand)







# EXAMPLE 3 (MOVSD, click to expand)







# EXAMPLE 4 (aka child array chain, click to expand)






Seems thats all.


If you wish to comment on this blog entry, please do so on the original site it was imported from.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit