x86byte

138 posts

x86byte banner
x86byte

x86byte

@x86byte

iOS & Windows Vulnerability Researcher & Exploit Developer — Reverse engineer, Obfuscation & De-Obfuscation Practitioner & Compilers Backend 👾🥤

securekernel.exe Entrou em Eylül 2022
700 Seguindo352 Seguidores
Tweet fixado
x86byte
x86byte@x86byte·
Whatever the brands of your smartphone are no guarantee of digital security because attackers keep evolving their game. 👨‍💻🏴
x86byte tweet media
English
0
0
2
0
x86byte
x86byte@x86byte·
@SpinkaMilan looks like was developed by lumma stealer developers, they use like this kind of encryption tricks, lol (kidding)
English
1
0
3
58
Milan Špinka
Milan Špinka@SpinkaMilan·
Sometimes, reversing #malware teaches you random fun facts. For example: Did you know that encrypted Discord tokens stored on disk are prefixed with the YouTube ID of "Never Gonna Give You Up" by Rick Astley? 🎸
Milan Špinka tweet mediaMilan Špinka tweet media
English
1
2
25
908
x86byte
x86byte@x86byte·
@HackingLZ S3 bucket is alive with 849 files 😱😱😱
English
0
0
2
1.6K
Justin Elze
Justin Elze@HackingLZ·
Free research Fridays? hXXp://139.162.182.252:8080/
Justin Elze tweet media
English
37
68
606
55.3K
x86byte
x86byte@x86byte·
@0xfluxsec honestly I’d resolve those targets faster with a tiny IDAPython script (or manually)
English
0
0
0
41
flux
flux@0xfluxsec·
@x86byte You’d think it’s something common enough they’d figure it out, but then, I’ve never written a decompiler haha. I wanna try Microsoft’s rust plugin to see if that tries to resolve dynamic dispatch. I’ll try tonight
English
1
0
0
268
flux
flux@0xfluxsec·
For Red Team tools, to make it harder and more annoying for static analysis, at least by to a human eye, vtables in dynamic dispatch can help (somewhat) obfuscate calls. I would quite like to disas this with some Ida rust plugins and see if it can be smarter about pulling out vtables in the decomp. If you can write some absolutely diabolic code that decompiles to noise and stick some cheeky dyn's in there it could be hard to spot. See also the massive difference in how the compiler treated both dynamic dispatch scenarios, the first decompiles as we would expect with vtables, the second - the compiler was smart enough about. I mentioned a human eye above, this is a very simple program obv, but I attached an MCP and asked Claude to tell me what the program did and you can see what it said in the screenshot.
flux tweet mediaflux tweet mediaflux tweet media
English
2
10
108
10.1K
x86byte
x86byte@x86byte·
@vxunderground MSRC blog post basically: please stop leaking 0days bro we can fix this relationship
GIF
English
0
0
3
268
vx-underground
vx-underground@vxunderground·
Microsoft Security Response Center put out a blog post today about Eclipse Nightmare guy Basically they think he's super mean and totally not cool he's dropping zero days. They say you're a jerk if you do this stuff because it's dangerous and stuff microsoft.com/en-us/msrc/blo…
English
86
181
2K
99.8K
x86byte
x86byte@x86byte·
sbox Compile-time AES string obfuscation for C++. No XOR. No delimiters. No plaintext in .rdata. github.com/x86byte/sbox
English
5
22
186
11.6K
parkie
parkie@unknowncheatsme·
@x86byte Cool., I give star. REspect.
English
1
0
1
355
x86byte
x86byte@x86byte·
@PELock until it hits real world cfg flattening, handler indirection, self modifying VMs and 20k+ instruction traces!!?
English
0
0
0
160
PELock
PELock@PELock·
@x86byte Well, the Claude 4.7 handles obfuscation and virtualization like VMprotect pretty good ;)
English
1
0
0
203
x86byte
x86byte@x86byte·
@PELock i tested LLM assisted reversing before against Obfusk8 At some point you're just feeding thousands of transformed instructions and CFG noise into the context window 😭 mostly turns into token burning instead of meaningful analysis :(
English
1
0
1
508
PELock
PELock@PELock·
@x86byte Nice work, have you tried it against LLMs?
English
1
0
1
603
x86byte
x86byte@x86byte·
IDA seeing random db 58h, db E9h blocks while the CPU executes them perfectly: ‘bro skipped the disassembler tutorial’
x86byte tweet media
English
1
8
97
7.3K
x86byte retweetou
Simplifying AI
Simplifying AI@simplifyinAI·
Someone just dropped a pre-built, fully jailbroken IOS 26 virtual machine. You can test tweaks and exploits without ever risking your real Iphone. It comes ready-to-run with rootless, Sileo, Filza, and TrollStore vibes. 100% Open Source.
Simplifying AI tweet media
English
11
114
1.1K
72.9K