Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @wxs
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @wxs
-
Prikvačeni tweet
"The popular definition of 'simple' among programmers has moved from 'few moving parts' to 'short invocation' (easy) and this is a problem."
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Though, to be fair... The original request for some of these features came from Sir Tom of the House of Lancaster (
@tlansec). Credit where credit is due, of course. ;)Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The reason I'm sharing all this is the PR will (hopefully) be merged for the next release and those of you hunting for this technique can start to leverage the increased functionality.pic.twitter.com/NNlE1QT6cX
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Since I convert the RVA to a file offset you can even check to see if enough functions are all "xor eax, eax; retn;" - which is pretty dope to be able to do so easily. There are other things this branch lets you do too, but I'll leave that up to you all to come up with. ;) 3/?
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
After trying it out he came up with these rules: https://gist.github.com/edeca/42c1961ecde43c8e26645fdad14f4405 … - which are MUCH nicer to read/write, and the extra features of the branch provide increased functionality. He can compare the compiled dll name (from the export table) to the legitimate one... 2/?
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Woke up this morning to a message from
@edeca about a crazy YARA rule he wrote (https://gist.github.com/edeca/cdc1657fa8a46b8ba45ad732377c035c …) to look for DLLs where exported functions are at the same RVA. I suggested he look into testing my pending PR (https://github.com/VirusTotal/yara/pull/1097 …). 1/?Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you're one of the places which use the dotnet module (we use it at
$job) it's worth noting that it will break rules if you're looking for specific user strings. I don't like breaking backwards compatibility but getting parsing correct is important in this case. 2/2Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
So
@MalwareUtkonos pointed out some weird user strings in some .NET binaries parsed by YARA. There were occasionally a trailing \x01. Turns out I missed a paragraph in the documentation which caused this bug, but I put up a fix at https://github.com/VirusTotal/yara/pull/1207 …. 1/2Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I spent this week without a laptop, with my family in Disney World. I’m super far behind on most things, but I don’t care. I’ll start digging out as soon as I’m home. Expect some neat projects from me this winter...
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
So
@silascutler is testing my base64 YARA work and discovered he can't use "base64" as a tag in his rule. This is not specific to base64 as you can't use any keyword as a tag. If you have base64 as a tag, your rule will fail to compile when my work is merged. Heads up!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Listening to On The Metal from yesterday and I suddenly need “f00f on your lambda” in shirt and sticker form. Seriously, there are some amazing stories in all the episodes.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
This report is a good example of confirmation bias and failure of critical analysis. The rule was triggering on strings that were unique to bat2exe which until now was only used by OilRig but is not indicative of malicious behavior. Be rigorous in your analysis!https://twitter.com/MalwareRE/status/1216807295092477959 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
These were not the first living robot. That distinction belongs to yours truly.https://twitter.com/simplenomad/status/1217459238215262208 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Performance management cycles are one of the top things I loathe. I do things I enjoy and am motivated to do, you pay me. That’s what I signed up for, that’s what I want. I don’t want to write down what I accomplished and the impact it had. I want to talk about what I’m proud of.https://twitter.com/bcantrill/status/1216491216356823040 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
And now that this is done I will go back to fixing up my base64 work so it can be included in the next release. Sometimes you just have to take a break and do something completely useless but fun.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
bf2y: Brainfuck to YARA. Are you a brainfuck coder who is also a YARA user? No? Well, I'm pretty sure nobody on the planet is but I just pushed my bf2y branch (https://github.com/wxsBSD/yara/tree/bf2y …) and wrote some notes: https://gist.github.com/wxsBSD/856e25fed737f0ed852e159679f32acb …. Completely pointless but a fun exercise.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Got new laptop and am seriously debating the value of slack. There are a handful of chats on there I mostly lurk in, but people do ping me on there. Migrating my keybase stuff was SO EASY, but do I really want to do the "log in to N slack teams" dance, again?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I've tested and it runs "hello world" and "cat" brainfuck programs. It's pretty dope if you're into esoteric languages running on a VM not meant to execute that language. ;)
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
So I have a working bf2y that compiles arbitrary brainfuck programs and executes them on the YARA VM (with 4 extra instructions, I may be able to reduce this down to 2 if I'm clever enough). Tomorrow I shall clean up the code and commit it.pic.twitter.com/3rPJ3fLTqA
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I implemented bf2y again over the last couple of nights. A simple "cat" program works but the more complex "hello world" does not. I know why, and it's due to a massive oversight on my part in the design. The fix requires another YARA instruction, which I don't want to do. :(
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you want to see the base64 modifiers land in YARA, now is your chance to voice your support. If people don't want it, it won't go in. Comment on the pull request (https://github.com/VirusTotal/yara/pull/1185 …) or in the earlier thread and we'll see if people want this or not.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
Security Engineer at Facebook. Interested in malware, protocols and reverse engineering. Retired FreeBSD committer. I also climb on fake rocks.