3 ms·
Do you have any references for the old-school assembly obfuscation?
by cced 7y ago
Do you have any references for the old-school assembly obfuscation?
- heavenlyblue 7y agoI had once worked on an executable packed by Themida. It used: - 8 layers of decrypting the initial executable - one of them decrypted the import table from the executable - each of those layers employed several methods of detecting that you're running under debugger - each of those layers employed methods of causing exceptions in popular debugging software - every single memory page was also encrypted while running, and a breakpoint was set up whenever a jump was made to it. The protection mechanism would first decrypt the next page and then encrypt the previous page. Even back then (15 years ago), the more complex option of Themida would generate a unique virtual machine with a unique bytecode for itself for a given executable, which would then execute itself. [1] https://reverseengineering.stackexchange.com/questions/16966/unpacking-a-themida-packed-x64-executable https://reverseengineering.stackexchange.com/questions/16966...
- SiempreViernes 7y agoSo does Themida represent the state of the art on obfuscation, or is that found in state sponsored malware, do you have any idea?
- Quarrel 7y agoThe current version of themida is good, and widely used, but not much of an obstacle to experienced people (although it depends on what you're trying to do). Denuvo is widely used on AAA titles and seems like a pain in the ass to deal with (ie games seem to take a while to pirate when protected with it and it adds a stupid CPU burden at times), but it doesn't have the edge it once had in the battle. https://en.wikipedia.org/wiki/Denuvo https://en.wikipedia.org/wiki/Denuvo