Igor Skochinsky (@[email protected])

2.4K posts

Igor Skochinsky (@IgorSkochinsky@infosec.exchange)

Igor Skochinsky (@[email protected])

@IgorSkochinsky

software developer at Hex-Rays*, hobby reverse engineer. Advanced cleartext hacker. 日本語おk *For Hex-Rays support/inquiries: https://t.co/rxVwo1npoQ

Belgium Katılım Haziran 2015
291 Takip Edilen4.5K Takipçiler
Igor Skochinsky (@IgorSkochinsky@infosec.exchange)
@struppigel Hi Karsten, AFAIK there should be checks to prevent such problem, but perhaps some corner case was missed. I can't seem to be able to DM you, so could you please DM me or use support.hex-rays.com so that we understand better how exactly you ended up in this situation?
English
0
0
3
200
Karsten Hahn
Karsten Hahn@struppigel·
To the people suggesting use Ghidra/Binja instead -- I already do depending on the sample, whether I am at home or at work, or just how I feel. Tools are not mutually exclusive unless you are religious about them. About cracks not having this issue: That is sadly true.
English
3
0
162
6.6K
Karsten Hahn
Karsten Hahn@struppigel·
IDA, why are you doing this? I lost my work because IDA refused to save. I needed to reboot the system to get network connection again. Without network there is no licensing server available. Surely there must be a better way to not loose work?
Karsten Hahn tweet media
English
64
66
2.2K
137.5K
ESET Research
ESET Research@ESETresearch·
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/6
ESET Research tweet media
English
57
662
2.7K
408.2K
e. v. m.
e. v. m.@evm_sec·
This seems like a common situation I run into but first time I scripted it. Do other folks run into this? (Needing to analyze or compare a static lib) What do you normally do?
English
2
1
3
0
e. v. m.
e. v. m.@evm_sec·
Yesterday I worked through a scenario where I generated stub C code in order to link a static library (.a) so Ghidra would properly analyze it in a single address space. I wrote a script that diffed readelf output in order to make a list of missing symbols that needed stubs. 1/2
English
1
2
7
0
Igor Skochinsky (@[email protected]) retweetledi
Savin Yeatman-Eiffel
Savin Yeatman-Eiffel@EiffelSavin·
This is no modern sculpture but an exemple of the ancient Japanese technique of #kamatsugi: a stylish & beautiful assembly technique allowing to join two carved beams together without using any nails. To learn more check the exhibition at the #MCJP in Paris😉 #Japan #Paris #wood
Savin Yeatman-Eiffel tweet media
English
0
3
21
2.8K
Halvar Flake
Halvar Flake@halvarflake·
@ghosted_sound To clarify: I need the syms belonging to the above executables, not a different JVM with syms.
English
1
0
0
247
Halvar Flake
Halvar Flake@halvarflake·
Dear Java Twitterverse, I am looking for the symbols for the JVMs found under jdk.java.net/21/ -- does anyone know where I could find them?
English
2
3
2
7.4K
Igor Skochinsky (@IgorSkochinsky@infosec.exchange)
@matalaz You probably need to use higher level info, such as the inter-function relationship (callers/callers, neighbor functions etc.). Maybe even approach it like an optimization problem over the whole binary.
English
0
0
1
65
Igor Skochinsky (@IgorSkochinsky@infosec.exchange)
【報告】今週から東京に行ってCODEBLUEとAVTokyoに参加する予定です。お会いしたい方はDMやLINEを送ってください。
日本語
0
6
32
0
Cristina Cifuentes
Cristina Cifuentes@criscifuentes·
I’ll be giving my talk “From Student of Compilation to Mother of Decompilation” on Tuesday at 5 pm AEST at UQCS; details below uqcs.org
English
2
2
23
0
Tamir Bahar
Tamir Bahar@tmr232·
I wanna write a web crawler/scraper - should I use Python or Go?
English
6
0
0
0
Brendan Dolan-Gavitt
@bitemyapp clang appears to link in the set_fast_math function when you use -Ofast too, probably for "gcc compatibility" :p
Brendan Dolan-Gavitt tweet media
English
2
0
1
0
Igor Skochinsky (@IgorSkochinsky@infosec.exchange)
@moyix I once had “fun“ debugging a crash in a Borland-compiled DLL called from an MSVC-compiled program. Turns out the two compilers use different FPU control word defaults so the called code was raising FPU exceptions not expected by the caller (but only on *some* inputs)
English
0
0
0
0
Yarden Shafir
Yarden Shafir@yarden_shafir·
fun RE fact: when an app has several identical functions, the compiler will merge them into one and pick a single symbol name. This can be confusing when looking at disassembled code that seems to call unrelated functions
Yarden Shafir tweet media
English
3
14
118
0
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
W3C: "Good URIs don't change" Microsoft web admin, putting on sunglasses: "Well then I guess our URIs are just bad to the bone"
English
1
0
27
0