4 ms·
As others have pointed out, while it's easy at a quintessential level, it's not easy if you're dealing with actually complex (and clever) structures. I don't k
by nathanlied 7y ago
As others have pointed out, while it's easy at a quintessential level, it's not easy if you're dealing with actually complex (and clever) structures.
I don't know if you've ever had that experience in your OllyDbg-using days, but did you ever try to analyse software that was using some form of hashing function, or cryptography (ECDSA, for instance) with OllyDbg, without knowing what it was? The idea is kind of like that. While it's easy to get a concrete idea of what that block of code is doing (feed it an ASCII string and some memory structures, it spits gobledygook out), it's not so easy to look at it and conclude "Ha! This implements AES-CBC!" without some strong intuition or experience.
- saagarjha 7y agoI will note that it doesn’t actually take all that much reverse engineering experience to be able to recognize most algorithms if you how they work “in code”.
- mlyle 7y agoIf they're inlined and optimized, it's often hard to tell where they begin and end... and if anything else is interleaved into the beginning or end.
- saagarjha 7y agoHard, but not impossible. Usually the really annoying bit is if it ends up being split across multiple functions with stuff in between.