A forum for reverse engineering, OS internals and malware analysis 

Search found 12 matches

 Go to advanced search

Re: WanaCrypt0r 2.0

 by Orkblutt ¦  Thu May 18, 2017 1:44 pm ¦  Forum: Malware ¦  Topic: WanaCrypt0r 2.0 ¦  Replies: 15 ¦  Views: 26595

ETW discussion

 by Orkblutt ¦  Thu May 18, 2017 10:26 am ¦  Forum: User-Mode Development ¦  Topic: ETW discussion ¦  Replies: 0 ¦  Views: 12004

Hi all, I am playing with Event Trace for Windows, ETW, to trace down some kernel events like files, disk IO and network. ( https://msdn.microsoft.com/fr-fr/library/windows/desktop/bb968803(v=vs.85).aspx ) No problem to get realtime events from userland but I try to achieve reboot persistency and tr...

Re: WanaCrypt0r 2.0

 by Orkblutt ¦  Tue May 16, 2017 9:40 am ¦  Forum: Malware ¦  Topic: WanaCrypt0r 2.0 ¦  Replies: 15 ¦  Views: 26595

@EP_X0FF: +1 :(

Re: TRON & SMP issue

 by Orkblutt ¦  Tue Sep 28, 2010 7:11 am ¦  Forum: Kernel-Mode Development ¦  Topic: TRON & SMP issue ¦  Replies: 17 ¦  Views: 22105

Hey Alex,

i forgot Ivanlef0u's blog... Really nice resources in there.

Gabben, can you say me more about that app? Did you try to hook SwapContext to avoid TLB flushing?

Regards,

Orky

Re: TRON & SMP issue

 by Orkblutt ¦  Sun Sep 26, 2010 10:03 pm ¦  Forum: Kernel-Mode Development ¦  Topic: TRON & SMP issue ¦  Replies: 17 ¦  Views: 22105

here a an interesting thread on the subject:
http://www.rootkit.com/board.php?did=pr ... 0&lastx=15
Where are you Bugcheck... I miss you!! ;)

Re: TRON & SMP issue

 by Orkblutt ¦  Fri Sep 24, 2010 8:28 am ¦  Forum: Kernel-Mode Development ¦  Topic: TRON & SMP issue ¦  Replies: 17 ¦  Views: 22105

Thanks Alex! Very interesting stuffs here.

Have now to resolve the PAE issue... :)

Regards,

Orkblutt

Re: TRON & SMP issue

 by Orkblutt ¦  Mon Sep 20, 2010 10:08 am ¦  Forum: Kernel-Mode Development ¦  Topic: TRON & SMP issue ¦  Replies: 17 ¦  Views: 22105

Why don't you give it a go and try it?
In fact I am since 2 weeks and it looks to work fine with just some minor modifications. I was wondering there is something I couldn't see needing a major rewrite to be SMP compatible. Looks like I was wrong.
Anyway, thanks.

Orkblutt

Re: TRON & SMP issue

 by Orkblutt ¦  Sun Sep 19, 2010 9:25 am ¦  Forum: Kernel-Mode Development ¦  Topic: TRON & SMP issue ¦  Replies: 17 ¦  Views: 22105

Hi DBS, When writing to usermode memory in order to delete the Dll-Entries from the Ldr-Lists, he simply delays all interrupts with CLI on the actual CPU, which is unsafe for multiprocessor systems. Yes... I noticed this point. In fact I'm not interested at all by this part. The only interesting par...

Re: TRON & SMP issue

 by Orkblutt ¦  Fri Sep 17, 2010 7:51 pm ¦  Forum: Kernel-Mode Development ¦  Topic: TRON & SMP issue ¦  Replies: 17 ¦  Views: 22105

Hi Alex, You can find the src and the slide here: http://www.openrce.org/downloads/details/234/ It's in fact an improvment of the "Shadow walker" rootkit. ( http://www.blackhat.com/presentations/bh-jp-05/bh-jp-05-sparks-butler.pdf ) One of the knowed issue to this thechnic is to not support SMP syst...

TRON & SMP issue

 by Orkblutt ¦  Thu Sep 16, 2010 3:36 pm ¦  Forum: Kernel-Mode Development ¦  Topic: TRON & SMP issue ¦  Replies: 17 ¦  Views: 22105

Hi,

I'm currently studying Tron's code... I'm not sure to understand why this technic can't be used on SMP systems without a major rewrite.
Someone can give me more information about this issue?

Regards,

Orkblutt