Live data from Hacker News

Research paper is also an executable x86 program [pdf]

tom7.org

21–30 of 30 posts

Re: Research paper is also an executable x86 program [pdf]

#22
Lazy question, sorry briefly skimmed the PDF and this doesn’t do this, but hypothetically could one design a PDF file generator technique the produces a spec compliant file that uses this technique to chain load another arbitrary base64 encoded binary stored inside the PDF. Maybe someone has already done that.

Re: Research paper is also an executable x86 program [pdf]

#23
When he talked about the inability to jump to certain places it reminded me of a powerpoint I read a decade or two back that discussed the disassembly of Skype. They used any and every trick in the book to make disassembly impossible, like calculating an int, feeding it to a cosine instruction and the result would be the jump distance. I tried finding the powerpoint but alas Google is garbage these days, maybe the author can find some hints in there to reduce the amount of code coming out of the compiler.

Wish I had come up with this compiler, great stuff.

Re: Research paper is also an executable x86 program [pdf]

#24

When he talked about the inability to jump to certain places it reminded me of a powerpoint I read a decade or two back that discussed the disassembly of Skype. They used any and every trick in the book to make disassembly impossible, like calculating an int, feeding it to a cosine instruction and the result would be the jump distance. I tried finding the powerpoint but alas Google is garbage these days, maybe the au…

Is this the presentation that you're referring to?

https://www.blackhat.com/presentations/bh-europe-06/bh-eu-06...

https://archive.org/details/Fabrice_Desclaux_and_Kostya_Kort...

Re: Research paper is also an executable x86 program [pdf]

#26
post #4

Earlier quoted context omitted.

Yep, it has the telltale MZ header at the top. Either a DOS or windows executable. [1] The pdf appears to be a readable formatted version, to get the actual executable you’ll need the raw text sans newlines (as described in the paper) 1: https://en.m.wikipedia.org/wiki/DOS_MZ_executable

Trivia: all Windows EXEs run on DOS, but most of them just print something like "this program doesn't run on DOS" and terminate. There are exceptions, like REGEDIT.EXE of Windows 95.

Even the DLL's are executables. It is about 100 bytes in where it says the real executable type. Some are OS1.x, win3x, win32... and so on. Think there is also a platform byte (x86, arm, mips, etc). My google fu is failing on the list of different types at the moment.

Re: Research paper is also an executable x86 program [pdf]

#27

Not only that, but it is an executable x86 program written in a printable subset of x86 instructions (so no self-modifying code), as noted in the section 3 with a comparison to the similarly printable EICAR anti-virus test file.

Yes. This is nuts (in a good way). I remember the first time I saw the video on youtube and the author was going through how he's going to do this with only printable chatacter and i had a "no fucking way" moment followed by being in awe at the solution that was found.

Re: Research paper is also an executable x86 program [pdf]

#30

When he talked about the inability to jump to certain places it reminded me of a powerpoint I read a decade or two back that discussed the disassembly of Skype. They used any and every trick in the book to make disassembly impossible, like calculating an int, feeding it to a cosine instruction and the result would be the jump distance. I tried finding the powerpoint but alas Google is garbage these days, maybe the au…

Is this the presentation that you're referring to? https://www.blackhat.com/presentations/bh-europe-06/bh-eu-06... https://archive.org/details/Fabrice_Desclaux_and_Kostya_Kort...

It isn't, unfortunately. Thanks for looking, though. The presentation I had was a powerpoint that focussed entirely on the disassembly and anti-debugging tricks, nothing about networking or traffic analysis.
Post reply on HN