Mobile Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 5 May 2012

Blogging elsewhere for a bit

Posted on 03:03 by Unknown
I've been blogging at Infosec Institute (a little :)) and on the TeamMentor development blog (a lot) ... so that's why this isn't as updated with my experiences. Do peek at my work at II or on TeamMentor if you're interested in knowing what I am up to :)
Read More
Posted in | No comments

Wednesday, 4 April 2012

Olly - Hit trace..finding code flow

Posted on 10:54 by Unknown
Many a time we come across malware which is extremely confusing and has lots of JMP and CALL statements. It becomes very difficult to find out what exactly the malware is doing; if you use a purely manual technique..and you start seeing stars after a while. At least I did :)

So to help you understand the control flow better you can use something called a Hit Trace in Olly. Here is how you can best use a Hit Trace:-

a) Load the executable into Olly. You'll have to use 2.01; I couldn't find this in Olly 1.10.

b) Till what point in the code, do you want to understand code flow? Identify that point and set a breakpoint there using F2.

c) Once you've set the breakpoint, navigate to Trace - Run hit trace. This will automatically run the malware until the breakpoint that you had set earlier.

d) If there's some anti debug measures or the process simply exits before your breakpoint...you won't be able to see the Hit Trace at all. However, if the program is still active, you should see a little red dot to the left of each assembly instruction. This just says....'This instruction has been run at least once'.

You will notice a lot of gaps in between the 'red dot' lines. That is because those instructions were never triggered at all. You'll see this specially in cases of JMP instructions.

There's another feature called 'Run Trace' in Olly and the way to use that to identify code flow is to Log to File and then study the log.

Or lastly (as far as I know) you can set breakpoints and then use the 'Trace Over/Into and Animate over/Into) to step into and over code interactively using the '+' and '-' keys to go forward or back.

But the Hit Trace is quite neat and it offers a very nice option to identify control flow. Until next time ...bye :)
Read More
Posted in code, coverage, flow, hit, hittrace, olly, ollydbg, trace | No comments

EXE dependencies - Read from PEB

Posted on 10:34 by Unknown
I was trying to understand where executables load all their dependencies from. So for example: When I load up minesweeper (winmine.exe) there are a host of additional DLLs that are loaded up as well. That's fine as there are functions inside each of those DLLs that winmine uses. What was interesting to find out though, was how the list of those DLLs was built in the first place. Where did the OS loader look...into the process..to find out 'what else to load'?

So I loaded up winmine.exe in Olly, Dep Walker and a few other tools to get an understanding of 'what all' was loaded. Once that was done I read up a little about the PE header to understand where dependencies are accessed from. In PE terminology, these are called imports. It turned out there was a Data Directory for the Import Table. So i thought; lets read the import table; that should give me a list.

So I wrote a little bit of Python code [after learning Python from Google's Python class ;)] to read the IMPORT TABLE from the PE header. This did give me quite a few DLLs but it still did not tally with what Olly was displaying.

The next thing I did was to modify my code to be recursive. So...

--- Load EXE. Get dependent DLLs from import table.
--- Load 1st DLL from previous list. Get its dependent DLLs. Add to list.
--- Load 2nd DLL from previous list. Get its dependent DLLs. Add to list.

And so on... until all dependencies were resolved.This was doubtlessly an improvement as I was closer to what was displayed in Olly [Alt+E]. It still wasn't complete though.

Then I read some more, read how Dependency Walker works, asked on Woodmann and re-read a few sections from Xeno Kovah's Life Of Binaries class. Turns out there are somethings called Delayed Imports. These aren't loaded statically at load time; like the Import table but only when a particular function needs to be called..later on...at runtime.

So I modified the code a little to recursively get all the DELAYED IMPORTS too. This would have been enough but it gave me a huge huge list which contained much much more than what Olly ever showed me :). So obviously this wasn't efficient either and it was something else.

So as usual when I'm stuck I bug the nice guys on Woodmann and I'm rarely disappointed. This time was no exception and I was pointed in the direction of something called a PEB.

The PEB or the Process Environment Block is apparently the only "part" (very loosely used) of a process that is in User Mode. Everything else is in Kernel mode. So if you want to find out every DLL that an EXE depends upon; its best to query the PEB instead of doing all that stuff I did earlier :)

I want to quickly touch upon the structure of the PEB before I finish this post. To look at the entire structure of the PEB you can visit this link. You need to query the PEB_LDR_DATA structure to get the list of Loaded DLLs. Here is an article that I found quite useful while I was learning stuff about all this.

And lastly..here is the complete thread of my discussion on Woodmann, if at all you are interested :).
Read More
Posted in loaderdata, olly, ollydbg, peb, peb_ldr_data, view | No comments

Tuesday, 7 February 2012

Links - All recent articles

Posted on 23:40 by Unknown
I've been primarily writing for Infosec Institute these days; so there's very few updates on my blog. I could duplicate stuff here; but that's not of much use to me or anyone :). So if you're interested in what I'm writing about, do take a look here.
Read More
Posted in | No comments

Wednesday, 12 October 2011

Freelancing - Infosec Institute

Posted on 10:17 by Unknown
I recently started writing for Infosec Institute on a freelance basis. You can read all my articles here.
Read More
Posted in appsec, attacks, basics, CRLF, introduction, response, splitting, web application | No comments

Sunday, 25 September 2011

Reverse Engineering - Know your tools...

Posted on 00:32 by Unknown
I've talked quite a bit about what tools to use and when in general. While all that is correct in principle, I recently, after a lot of painful 'research' [mostly already out there somewhere] , came up with a process for myself to use the right tools at the right time. Here is a short summary of the same:

1) Do your dynamic analysis and document what you found.

2) To learn more you have to now do static analysis; don't start off with IDA Pro; it overwhelms you very quickly... specially if you are new.

3) Put the EXE through Olly or Immunity and start identifying what each function does, step by step. I'm just saying... don't be worried initially about understanding everything about the malware. If you can even confirm what you found in dynamic analysis, via static analysis and say that...I know what these 5 functions do...that's good enough for a start.

4) Now once you know what these 5 functions do, open the EXE up in IDA Pro and rename the 'known' functions from sub_4012345 to something meaningful, like sub_malware_connect_irc. Repeat for each function you know. Go back to Olly now.

5) Now take each function(known); say sub_malware_connect_irc and identify all of its system function calls.. connect() send() getcommandline() etc etc.

6) Look at MSDN and understand the arguments that are passed to each. See where these arguments are stored in the disassembly you have. Is it stored on the stack or in a variable?

7) If its in a variable go to IDA and give that variable a meaningful name. So for e.g rename something like dword_ptr_401324 to malware_irc_host-name. This will result in every single place where that variable is accessed, getting renamed to the new variable. So dword_ptr_401234 will no longer exist; it will be referred to as malware_irc_host-name. Repeat this process for all known functions and all known variables.

8) Once you have a few functions and all corresponding variables renamed, use the GroupNodes feature in IDA (Right click on any block, select GroupNodes) to collapse blocks you have already analysed. Give each block a name that you will recognize instantly, without having to look at the disassembly again. Repeat this for all blocks that you have analyzed. So this will reduce the disassembly that you have to look at, in other parts of the program you have not yet analyzed.

9) So now, to summarize, for all known functions you have renamed the functions, renamed the variables, and grouped blocks of code that you have already analyzed and named the block. This should give you a nice 'pseudo codish' flowchart in IDA for quite a few functions :)

10)  Now use the 'Functions' submenu in IDA and sort by the first column to see how many functions are pending; you can get this by seeing how many start with sub_.

11) Go to each function and see where it is called from. You can do this first in Olly 1.10 by highlighting the first line (usually PUSH EBP) of the function and looking in the middle pane on where all it is called from. Visit each of the calls in the middle pane and see where they were called .. and so on. Do this till you get to the root of the call.. see if you can now understand 'when' it was triggered.. 'What' behavior triggered it? Do the renaming and grouping as before. If you can't understand.. at least give the function a name.. some name.. like dummy_notunderstood_1, dummy_notunderstood_2 and so on. That still is better than sub 401237.

12) At the end of all of this you should have a .IDB file fully named (as much as possible) and fully grouped. Now ..only now should you start drilling down into HOW exactly each function works...the exact algorithm behind each function and so on. Repeat this for as many interesting functions that you want.

13) Once this also is done, if you WANT , try rewriting this in a high level language, at least pseudo code so you can quickly refer back to it when you want.

I guess, this is all very intuitive for most reversers who have learnt this on their own or been reversing for a long time. It took me a long time though, to reach this level and hope it is helpful to any relative newbie reading this blog post and feeling lost. I know I was one a few months ago ;).

p.s.... Make sure you back the .IDB file up ;)

Here are 2 sample screen-shots:
Sample Graph of Grouped Functions  


Renamed functions - A sample list

Read More
Posted in beginner, debugger, engineering, flowchart, graph, howto, IDA, idapro, IDB, immunity, olly, procedure, reverse, start, tools, tutorial, understand | No comments

Thursday, 22 September 2011

Debugging threads - Olly

Posted on 08:57 by Unknown
Recently I was debugging a piece of malware which launched numerous threads inside, after it ran. Now, after the thread spawned, I could no longer F7 or F8 my way through the malware and understand things. This was because it was the thread which was doing all the work. So somehow I needed to get into the thread.

The first thing I did was 'Right click' and then select a thread from the Threads sub menu. That though just seemed to take me to system space, which was kind of useless. I wanted to see what the Thread did in User Space.

I looked at the CreateThread API then, which was what was being used. The 3rd argument to the function was a start address for the thread. I did a Ctrl+G, went to that address in Olly and put a breakpoint there, and then restarted the program. Went on as normal till CreateThread and then F9'd to run till next breakpoint. The main thread still "hung" but I did break inside UserMode for the Thread and could debug it.. yay :)

If you want to break even before UserMode and want to track it the moment the thread is launched, you can set debugging options in Olly to break each time a new thread is started or stopped. There's simple check boxes under the Options menu. Go search :)

The last bit is when  the Thread itself exits..it just says Thread Terminated and you again cannot F7 or F8 because there is nothing left to F7 or F8 into. You need to get back to the main thread, where the CreateThread API was called. Makes sense ..rt? Main.. created a thread...I debugged thread...now I come back to main...once I finish debugging the thread.

To do so, pause the program(F12) after the thread terminates and hit Alt+F9 to return to user mode. This will bring you right to the spot after CreateThread was first called.


Hope this helps someone newish to reversing :). Have fun!!
Read More
Posted in breakpoint, debugger, engineering, example, olly, ollydbg, reverse, set, thread | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Nvidia has a Logan-powered Shield 2 console in development!!!
    Nvidia CEO Jen-Hsun Huang has revealed to  Engadget  that a successor to the Shield is in development, and it will likely be powered by a ne...
  • John Carmack isn't convinced that Steam Machines will be a hit!!!
    Gaming legend John Carmack recently took the stage at  Nvidia’s Montreal conference  where he  talked  a bit on the subject of Valve and the...
  • Yahoo Tops Google In Web Traffic Again!!!
    NEW YORK (AP) — For the third month in a row, more Americans visited Yahoo's websites than Google's, according to comScore Inc.'...
  • EMC Defenders CTF - Week 3 - Contest 14 - Reversing
    I played the EMC defenders CTF with a few of my friends a while back. We sadly couldn't complete all the challenges. All the same it was...
  • 20 Life Hacks and Tools to Boost Productivity on Your Computer!!!
    With the flood of  new technologies , websites, apps, news, work files, pictures, articles and the like, staying organized and focused is be...
  • ASRock unveils a pair of motherboards designed specifically for Bitcoin mining!!!
    Those looking to generate some extra cash by mining for Bitcoin now have a couple of new hardware options courtesy of ASRock. The motherboar...
  • AuthenTec co-founder discusses how Touch ID fingerprint reader evolved from early prototypes!!!
    AuthenTec co-founder F. Scott Moody recently stopped by his alma mater to deliver a  speech  about the company he helped launch. His company...
  • A peek at the inside of Sony's PlayStation 4!!!
    See  what's inside the PlayStation 4 with these exclusive photos  Inside Sony headquarters, at the heart of Tokyo’s Shinagawa district, ...
  • Asus reveals Chromecast-like Miracast Dongle, has new smartphone and Chromebook line-ups on the way!!!
    Asus has made its way mainly in the PC business for quite some time now, but new reports have  surfaced pointing at the company looking to e...
  • Google Nexus 5: The geekysupport Review!!!
    It’s that time of the year again, where Google releases a new Nexus handset for those wanting a cheap yet powerful device running stock Andr...

Categories

  • 100
  • 12.04
  • 2.2
  • 2013
  • 21
  • 4848
  • 8080
  • add
  • alternative
  • analysis
  • android
  • apk
  • app
  • applet
  • applets
  • appletviewer
  • application
  • appsec
  • asmx
  • assembly
  • attack
  • attacks
  • basic
  • basics
  • beginner
  • blazeds
  • blog
  • book
  • books
  • breakpoint
  • breakpoints
  • browser
  • burp
  • CALL
  • capture
  • certificate
  • chain
  • cheops
  • client side
  • code
  • conference
  • console
  • content-type
  • coverage
  • CRLF
  • cross
  • crossdomain
  • csrf
  • ctf
  • customer service
  • database
  • deblaze
  • debug
  • debugger
  • decision
  • defcon
  • delete
  • deleting
  • dll
  • dogbert
  • dom
  • dynamic
  • element
  • emulator
  • encryption
  • engineering
  • entity
  • environment
  • example
  • executable
  • external
  • firebug
  • flash
  • flex
  • FlourineFX
  • flow
  • flowchart
  • forensics
  • fs
  • fuzz
  • glassfish
  • graph
  • handbook
  • harden
  • hash
  • hints
  • hit
  • hittrace
  • howto
  • IDA
  • idapro
  • IDB
  • immunity
  • in use
  • incremental
  • inetsim
  • injection
  • install
  • introduction
  • java
  • java.policy
  • javaee
  • javascript
  • jks
  • jump
  • keyboard
  • lab
  • loaderdata
  • malware
  • management
  • mapper
  • market
  • MD Description
  • MD FAQ
  • MD Technical Support
  • MD Updates
  • MD User Guide
  • md5deep
  • mount
  • msdn
  • network
  • newbie
  • olly
  • ollydbg
  • options
  • packet
  • password
  • pbkdf
  • pcap
  • peb
  • peb_ldr_data
  • penetration
  • pentest
  • permissions
  • phone
  • pkcs12
  • policytool
  • port
  • practical
  • procedure
  • proxy
  • resign
  • resignation
  • response
  • restrict
  • reverse
  • reversing
  • review
  • salt
  • same origin
  • sample
  • scripting
  • sdk
  • secure
  • security
  • set
  • setup
  • sharif
  • shortcuts
  • SI
  • signed
  • site
  • snapshot
  • soapui
  • source
  • splitting
  • ssl
  • start
  • static
  • steps
  • stunnel
  • superblock
  • support
  • test
  • thoughts
  • thread
  • tips
  • tool
  • tools
  • tor
  • trace
  • truecrypt
  • tutorial
  • ubuntu
  • umask
  • understand
  • university
  • unsigned
  • video
  • view
  • virgin
  • virtual
  • virtual box
  • virtual machine
  • virtualbox
  • vm
  • watch
  • web
  • web application
  • web service
  • work
  • wsdl
  • xhr
  • xml
  • xss
  • xxe

Blog Archive

  • ▼  2013 (496)
    • ▼  November (143)
      • EMC Defenders CTF - Week 3 - Contest 14 - Reversing
      • Report details Intel Broadwell-K CPUs, Iris Pro gr...
      • What happens if you plug an Xbox One into... itsel...
      • Google completes upgrading its SSL certificates to...
      • Honda, Hyundai and Toyota showcase vehicles powere...
      • Valve readying invites for local game streaming be...
      • Liquid metal alloy could allow hobbyists to print ...
      • AMD is giving away 1,000 copies of Battlefield 4 o...
      • Acer's replacement CEO resigns before taking offic...
      • Jury awards Apple $290 million in patent infringem...
      • HBO Go now supports Chromecast on both iOS and And...
      • Half-Life mod Black Mesa approved for sale on Stea...
      • Xbox One teardown reveals standard PC hardware com...
      • University in Cyprus becomes world's first to acce...
      • Adobe opens $9.99 per month Photoshop + Lightroom ...
      • Building a coding machine becomes fun with the $99...
      • Motorola signs deal with 3D Systems to help build ...
      • Google sends out developer invites to Chromecast h...
      • Sprint finishes dead last in Consumer Reports' lat...
      • MediaFire's new desktop file-sharing client brings...
      • Infographic: A timeline of Sony's PlayStation fran...
      • FCC may allow passengers to make in-flight cellula...
      • Pogoplug launches $49 Safeplug to anonymize your h...
      • Silk Road mastermind allegedly ordered six murders...
      • Intel Atom SoC roadmap updated, new chips and 64-b...
      • Upcoming MMORPG by Ex-Blizzard devs, WildStar to b...
      • A Software Challenge: Why Users Uninstall Apps!!!
      • geeky support 2013 gift Guide/recommendations!!!
      • Yahoo to announce the hire of Katie Couric as 'Glo...
      • Microsoft matches Sony, sells over a million Xbox ...
      • What Black Friday deals are you eyeballing this ye...
      • Instagram said to be working on private messaging ...
      • Doom co-creator John Carmack resigns from id Softw...
      • Motorola signs deal with 3D Systems to help build ...
      • The state of self-driving cars, Intel details upco...
      • Xbox One Review!!!
      • Qualcomm reveals new Snapdragon 805 processor with...
      • MediaTek showcases world's first true octa-core mo...
      • Logitech releases PowerShell controller with integ...
      • Firefox’s streamlined “Australis” user interface l...
      • Flickr rolls out new printed photo book options st...
      • Greedy wireless carriers aren't interested in smar...
      • New details on Elder Scrolls Online campaign, stor...
      • Google launches free prepaid debit card, links to ...
      • End of an era: Winamp is shutting down after more ...
      • Are you sure you're clean?
      • John McAfee Responds To Wrongful Death Lawsuit!!!
      • Google Nexus 5: The geekysupport Review!!!
      • Tesla chief Elon Musk updates Model S warranty to ...
      • Command & Conquer not dead after all, revival immi...
      • MOGA unveils the Ace Power gamepad for iPhone, iPo...
      • Yahoo to encrypt all products in light of NSA spyi...
      • Call of Duty: Ghosts patch adds e-sports features,...
      • Sony's $399 PlayStation 4 costs roughly $381 to bu...
      • Snapchat turns down $3 billion acquisition offer f...
      • Samsung has now shipped 800,000 Galaxy Gears, new ...
      • Snapchat surpasses photo sharing activities of Fac...
      • Nokia Lumia 2520 available at Verizon this week, p...
      • Valve set to reveal its own Steam integrated virtu...
      • Google to pay $17 million for unauthorized trackin...
      • New Toshiba Kira Ultrabook lasts 22 hours on a sin...
      • Senate hosts hearing on Bitcoin and other virtual ...
      • Apple reportedly buying PrimeSense, the company be...
      • Decade-long study claims video games don't affect ...
      • FBI memo claims Anonymous has been hacking US gove...
      • ZTE Open smartphone with Firefox OS review!!!
      • Sony sells more than a million PlayStation 4s with...
      • Ouya unveils limited edition white console with do...
      • Qualcomm's $350 Toq smartwatch releases on Decembe...
      • A behind-the-scenes look at how YouTube handles an...
      • NFL and MLB ask the Supreme Court to hear a challe...
      • Trademark application points to impending Fallout ...
      • Raspberry Pi has now sold 2 million units, doubles...
      • Hackers breach vBulletin support forum using zero-...
      • Sony publishes guide to troubleshoot PlayStation 4...
      • 12 Ways Black Friday 2013 Will Be Different!!!
      • Apple iPad Air: The geekysupport Review!!!
      • VMware Tools now available for nested ESXi with th...
      • VMware Tools now available for nested ESXi with th...
      • VMware Tools now available for nested ESXi with th...
      • Prepare yourself for the looming deadline of Windo...
      • Final PS4 & Xbox One specs compared, why users uni...
      • What's the oldest gadget you still use regularly?!!!
      • Newly appointed FCC chairman calls for wireless ca...
      • ASRock unveils a pair of motherboards designed spe...
      • Europe allows airlines to install 3G and LTE netwo...
      • The PlayStation 4 is officially here, some systems...
      • Republic Wireless offers Moto X for $299 contract-...
      • FCC's Speed Test app for Android now available on ...
      • Jolla to launch inaugural smartphone with Sailfish...
      • Quantum computers looking more realistic with majo...
      • Samsung reportedly planning to launch smartphone w...
      • Minecraft: The Story of Mojang now available on Yo...
      • Jawbone's first wireless fitness tracker Up24 is a...
      • Yahoo to auction off more than 100 long-lost domai...
      • Computer History Museum publishes Apple II DOS sou...
      • CyanogenMod one-click installer for Android arrive...
      • PlayStation 4 Review: (In Progress), But Do You Ne...
      • MIT showcases impressive dynamic shape display tec...
      • snapchat turns down $3 billion acquisition offer f...
      • Intel's 9-series chipsets not expected to support ...
      • Xperia Z1 Review: Testing Sony's Latest Android Fl...
      • Google and HP pause sales of the Chromebook 11 fol...
      • AMD's upcoming mobile APUs make 'Jaguar' next-gen ...
      • 24 accidental scientific discoveries that reshaped...
      • Firefox OS Review!!!
      • IBM's new Watson supercomputer developer platform ...
      • Leaked Dragon Age: Inquisition video showcases com...
      • Asus reveals Chromecast-like Miracast Dongle, has ...
      • Double-sided YotaPhone will go on sale this holida...
      • New bill would give online video services protecti...
      • Coin is the all-in-one credit card designed to sli...
      • Blizzard says it was wrong to include offline mode...
      • Isis Mobile Wallet launches across the country wit...
      • Western Digital hoping for 5x larger hard drives w...
      • Hot PC Games for the 2013 Holiday Season!!!
      • Amazon and USPS team up to offer Sunday delivery!!!
      • A peek at the inside of Sony's PlayStation 4!!!
      • Smartphone adoption forecasted to reach 5.6 billio...
      • Microsoft's Xbox One arrives two weeks early for s...
      • Netflix and YouTube account for 50% of North Ameri...
      • Moto X customization with Moto Maker now available...
      • FCC seeks your help in testing mobile broadband sp...
      • Next iPhones to have large curved displays and bet...
      • Original iPod first went on sale 12 years ago with...
      • Latest Google Chrome beta makes it easy to locate ...
      • Microsoft releases hotfix for Windows 8.1 mouse ac...
      • Sony expects to sell three million PlayStation 4 c...
    • ►  October (297)
    • ►  September (51)
    • ►  August (2)
    • ►  March (1)
    • ►  January (2)
  • ►  2012 (16)
    • ►  October (3)
    • ►  September (1)
    • ►  August (4)
    • ►  June (1)
    • ►  May (4)
    • ►  April (2)
    • ►  February (1)
  • ►  2011 (22)
    • ►  October (1)
    • ►  September (2)
    • ►  August (1)
    • ►  July (9)
    • ►  June (1)
    • ►  May (2)
    • ►  April (6)
  • ►  2010 (8)
    • ►  August (3)
    • ►  April (2)
    • ►  January (3)
  • ►  2009 (6)
    • ►  December (6)
Powered by Blogger.

About Me

Unknown
View my complete profile