+ Reply to Thread
Results 1 to 6 of 6

Thread: Tips & Hacks

  1. #1
    dukeBarman's Avatar

    Default Tips & Hacks

    Topic for short tips
    A hacker without a cat is not a hacker!

  2. #2
    dukeBarman's Avatar

    Default Re: Tips & Hacks

    Changing numeric base of immediate in r2 -> mov eax, 0x41414141 -> ahi 2 -> mov eax, 'AAAA' -> ahi 10 -> mov eax, 1094795585 (@Maijin212)
    A hacker without a cat is not a hacker!

  3. #3
    dukeBarman's Avatar

    Default Re: Tips & Hacks

    Want to profit from r2 on OS windows ? Stop using cmd.exe and embrace @conemumaximus5: http://conemu.github.io (@Maijin212)

    P.S. I use FAR Manager a very long time but didn't know about conemu. And it's a really good thing! :)
    Last edited by dukeBarman; 09-01-2016 at 23:02.
    A hacker without a cat is not a hacker!

  4. #4
    dukeBarman's Avatar

    Default Re: Tips & Hacks

    "s function_name" (after "aa" or "aaa") then "V" then "p" or "Vp" and "x" (after only V) you see there are number of xrefs displayed, you can type on the number corresponding on keyboard to get to the xref (@Maijin212 & my additions)

    https://radare.gitbooks.io/radare2bo...sassembly.html
    A hacker without a cat is not a hacker!

  5. 2 пользователя(ей) сказали cпасибо:
    Darwin (18-01-2016) ximera (18-01-2016)
  6. #5
    dukeBarman's Avatar

    Default Re: Tips & Hacks

    Find string with shellcode like a "\x90\x90..." and disassembly it:
    Code:
    curl -s http://pastebin.com/raw/T2zjAdZ5 | grep '"\\x' | tr -d '\\x' | tr -d '[" \r\n]' | rasm2 -d -
    A hacker without a cat is not a hacker!

  7. #6
    dukeBarman's Avatar

    Default Re: Tips & Hacks

    use rabin2 -D to detangle symbol names for java, c++, swift
    A hacker without a cat is not a hacker!

+ Reply to Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
All times are GMT. The time now is 01:24
vBulletin® Copyright ©2000 - 2018
www.reverse4you.org