Uploaded March 2014 | Updated September 2026, 2 weeks ago
*** Full title:
"Data, data, data! I can't make bricks without clay." A few practical notes on reverse-engineering.
The talk was done as part of Garage4Hackers Ranchoddas Series.
garage4hackers.com
*** Slides:
docs.google.com/presentation/d/1g50LuOfLRmOhgJHzNuia1rBVOmrrjUg3FePzav9zbko/edit
*** Sources, scripts, etc:
drive.google.com/folderview?id=0B5y5AGVPzpIOb0V6M1NONlRwMEk&usp=sharing
*** Timestamps (credit: Impuls)
0:00 Intro, sponsors
3:45 Data, data, data! I can't make bricks without clay
4:28 And you are...?
6:18 What's this all about?
7:30 TIP1 If asm is weird/hard, try translating to C
11:40 TIP2 Trace things
11:50 JMP spaghetti crackme
17:02 RarVM and CTFs
20:40 TIP3 Unknown arch? - Annotate instructions
24:35 TIP4 Don't rely on tools. Make your own
25:48 Disassembly engines and when to use them
28:40 Quick explanation what's ROP
30:32 Why make your own ROP gadget finder. Mixer CTF task
33:40 32/64 mode switching CTF task
37:12 Windows debug API
40:56 CPU specific (x86) debug features
43:55 TIP5 x86 runs on x86 (windows ↔ linux) + demo
53:30 GDB is your friend even if you date Olly
56:55 GDB scripting in Python
57:55 OCAML crackme GDB script
1:02:01 TIP6 Insider technique - attach when unpacked
1:05:30 Insider technique demo
1:06:49 TIP7 Paimei Stalker - locating funcs by elimination
1:14:17 TIP8 Monitor the environment (ltrace, strace, PM)
1:17:29 TIP9 GNU/Linux gotchas
1:18:32 RuCTF mixer task, dealing with linker
1:27:40 TIP10 Just be lazy. Treat a function as a blackbox
1:35:50 Know your own tools
1:36:45 Reversing takes time
1:37:27 Entropy is a good recon tool
1:39:12 Symbols and signatures speed up reversing
1:40:40 The end
*** Full title:
"Data, data, data! I can't make bricks without clay." A few practical notes on reverse-engineering.
The talk was done as part of Garage4Hackers Ranchoddas Series.
garage4hackers.com
*** Slides:
docs.google.com/presentation/d/1g50LuOfLRmOhgJHzNuia1rBVOmrrjUg3FePzav9zbko/edit
*** Sources, scripts, etc:
drive.google.com/folderview?id=0B5y5AGVPzpIOb0V6M1NONlRwMEk&usp=sharing
*** Timestamps (credit: Impuls)
0:00 Intro, sponsors
3:45 Data, data, data! I can't make bricks without clay
4:28 And you are...?
6:18 What's this all about?
7:30 TIP1 If asm is weird/hard, try translating to C
11:40 TIP2 Trace things
11:50 JMP spaghetti crackme
17:02 RarVM and CTFs
20:40 TIP3 Unknown arch? - Annotate instructions
24:35 TIP4 Don't rely on tools. Make your own
25:48 Disassembly engines and when to use them
28:40 Quick explanation what's ROP
30:32 Why make your own ROP gadget finder. Mixer CTF task
33:40 32/64 mode switching CTF task
37:12 Windows debug API
40:56 CPU specific (x86) debug features
43:55 TIP5 x86 runs on x86 (windows ↔ linux) + demo
53:30 GDB is your friend even if you date Olly
56:55 GDB scripting in Python
57:55 OCAML crackme GDB script
1:02:01 TIP6 Insider technique - attach when unpacked
1:05:30 Insider technique demo
1:06:49 TIP7 Paimei Stalker - locating funcs by elimination
1:14:17 TIP8 Monitor the environment (ltrace, strace, PM)
1:17:29 TIP9 GNU/Linux gotchas
1:18:32 RuCTF mixer task, dealing with linker
1:27:40 TIP10 Just be lazy. Treat a function as a blackbox
1:35:50 Know your own tools
1:36:45 Reversing takes time
1:37:27 Entropy is a good recon tool
1:39:12 Symbols and signatures speed up reversing
1:40:40 The end










