The Poor Man's Obfuscator
Action | Key |
---|---|
Play / Pause | K or space |
Mute / Unmute | M |
Toggle fullscreen mode | F |
Select next subtitles | C |
Select next audio track | A |
Show slide in full page or toggle automatic source change | V |
Seek 5s backward | left arrow |
Seek 5s forward | right arrow |
Seek 10s backward | shift + left arrow or J |
Seek 10s forward | shift + right arrow or L |
Seek 60s backward | control + left arrow |
Seek 60s forward | control + right arrow |
Decrease volume | shift + down arrow |
Increase volume | shift + up arrow |
Decrease playback rate | < |
Increase playback rate | > |
Seek to end | end |
Seek to beginning | beginning |
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamWhen subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
to prevent static analysis tools (like IDA, BinaryNinja, ...) from working correctly.
While these tricks do not break the execution of the original binary, when they are opened in IDA, BinaryNinja and, Radare2
the code looks obfuscated while only the file format is modified (not the instructions)
These modifications are leveraged by LIEF and the scripts will be published at the end
of the conference with an associated blog post.
Romain Thomas is a security engineer working on mobile applications and obfuscated code.
Author of LIEF, a library to parse and manipulate executable file formats (ELF, PE, Mach-O),
he enjoys going back and forth between reverse engineering and tool development to see which part of the process can be automated.
Romain is also interested in iOS, whitebox cryptography and reverse engineering app protocols.
He contributed in the past to the Triton project, especially on de-obfuscation based on symbolic execution.
Other media in the channel "2022"
- 21 views, 2 this year, 1 this monthClosingJuly 6th, 2022
- 56 views, 10 this yearkdigger: A Context Discovery Tool for Kubernetes Penetration TestingJuly 6th, 2022
- 45 views, 5 this yearDissecting NTLM EPA & building a MitM proxyJuly 6th, 2022
- 82 views, 23 this year, 1 this monthFinding Java deserialization gadgets with CodeQLJuly 6th, 2022
- 83 views, 6 this year, 1 this monthMobSF for penetration testersJuly 6th, 2022
- 81 views, 8 this year, 1 this monthImprove your Malware Recipes with CyberchefJuly 6th, 2022