4 ms·
Uhh yea, this is Running shellcode 101, works very well. My Red Team stuff at work all starts with a simple loader like this (with some encryption / obfuscation
by mox1 5y ago
Uhh yea, this is Running shellcode 101, works very well. My Red Team stuff at work all starts with a simple loader like this (with some encryption / obfuscation sprinkled in).
When I was first shown this I was like 'What non virus use case does this have!?!?'
- tptacek 5y agoInstrumenting and debugging live processes is the big one.
- dotancohen 5y agoWhich is not an end-user advantage but rather a tool to better understand end-user software - equally useful for improving said software or attacking it. Assuming GP meant "virus" as in "malware" then actually this supports his point.
- ssklash 5y agoRed teamer here too, and this was my exact thought. There's lots of legit uses for DLL injection, but straight up shellcode injection? Shady as hell. So of course it was an AV vendor...
- deleted 5y ago[deleted]