Here's a binary obfuscated with the current CVM version. It's still in a very early development phase and the mutation complexity is very simple compared to the plans I have for later, but it should already stop quite a few newbies from easily reversing a mutated block of code.
The obfuscated application is a SHA-1 implementation with a self-test program which computes a checksum of predefined values and compares them to the expected result. The original program's source can be found here: http://www.packetizer.com/security/sha1/
Download the obfuscated binary here: http://chaplja.net/SHA1_2011_05_30.exe
Hopefully I'll be able to release a test version for testing to public soon.
Reverse engineering, software development, free software protection tools and resources
Monday, May 30, 2011
ChapljaVM progress update
Labels:
chaplja,
chapljavm,
cvm,
obfuscation,
packer,
pe,
protection,
virtual machine
Thursday, May 19, 2011
ChapljaVM v2 - Code mutation/virtualization engine (work in progress, pre-alpha)
Previous release: chapljaVM assembler/scripting
Ok, this is not really related to it because this is now a completely different and way more complex project, but the tool I'm working on now will also support a language similar to what I linked above to be inserted into the executable binary or to be executed from memory using an SDK function.
Click here for a small pre-alpha screenshot
I have done quite a lot of research and have done a lot of testing, which I believe is the hardest part of the work. Now I need to implement everything I've done so far in simpler tests. It's not very hard, but it's a lot of work because really many instructions and cases need to be covered.
The goal is to make a codevirtualizer/vmprotect-like application which allows you to select areas of code you'd like to protect within your C/C++ sources - but with the actual obfuscation being priority, the anti-debugging and similar things being less of a priority and will be implemented after everything else is.
It doesn't do much yet, of course not everything is implemented what is seen in the application window, but almost everything has been tested in various console apps and now needs to be implemented into actual obfuscation engine and this gui version.
I've tested relocation of selected code blocks into a new section which the tool generates and it's working fine (though not finished yet - need to take care of relocations so DLLs are supported in case they're loaded at a different address, but it won't be hard to implement).
These are the first important features I'd like to cover:
- Code mutation (one instruction is transformed into multiple instructions which end up having the same result)
- Code virtualization (will come after mutation is fully implemented)
- Junk code insertion between original instructions
- Other 'standard' features such as IAT obfuscation, debug information removal, etc, not really giving much attention to it now, it's not very hard to implement these)
Hopefully I'll have an alpha version for testing or at least a produced binary of some more complex code within some reasonable amount of time.. will post more updates as the development progresses further.
Ok, this is not really related to it because this is now a completely different and way more complex project, but the tool I'm working on now will also support a language similar to what I linked above to be inserted into the executable binary or to be executed from memory using an SDK function.
Click here for a small pre-alpha screenshot
I have done quite a lot of research and have done a lot of testing, which I believe is the hardest part of the work. Now I need to implement everything I've done so far in simpler tests. It's not very hard, but it's a lot of work because really many instructions and cases need to be covered.
The goal is to make a codevirtualizer/vmprotect-like application which allows you to select areas of code you'd like to protect within your C/C++ sources - but with the actual obfuscation being priority, the anti-debugging and similar things being less of a priority and will be implemented after everything else is.
It doesn't do much yet, of course not everything is implemented what is seen in the application window, but almost everything has been tested in various console apps and now needs to be implemented into actual obfuscation engine and this gui version.
I've tested relocation of selected code blocks into a new section which the tool generates and it's working fine (though not finished yet - need to take care of relocations so DLLs are supported in case they're loaded at a different address, but it won't be hard to implement).
These are the first important features I'd like to cover:
- Code mutation (one instruction is transformed into multiple instructions which end up having the same result)
- Code virtualization (will come after mutation is fully implemented)
- Junk code insertion between original instructions
- Other 'standard' features such as IAT obfuscation, debug information removal, etc, not really giving much attention to it now, it's not very hard to implement these)
Hopefully I'll have an alpha version for testing or at least a produced binary of some more complex code within some reasonable amount of time.. will post more updates as the development progresses further.
Friday, August 7, 2009
chapljaVM - my own x86-like assembler/virtual machine
I have no idea if these are the right terms to name something like this, but I call it my own virtual machine/assembler.
I work on a lot of stuff that relies on security-through-obscurity and also own legal licenses for some commercial protection tools, but I always wanted to make something on my own. I believe that home made protection is usually better than anything else, even if it's technically weaker.
Basically this is an assembler that gets "compiled" into an executable image that can be loaded using appropriate runtime library.
This archive contains an example assembler source code and a "compiler" plus code required to execute binaries.
More information available in the readme.
Download: chapljaVM.rar
I work on a lot of stuff that relies on security-through-obscurity and also own legal licenses for some commercial protection tools, but I always wanted to make something on my own. I believe that home made protection is usually better than anything else, even if it's technically weaker.
Basically this is an assembler that gets "compiled" into an executable image that can be loaded using appropriate runtime library.
This archive contains an example assembler source code and a "compiler" plus code required to execute binaries.
More information available in the readme.
Download: chapljaVM.rar
Browsing vBulletin mysql database dumps
If you have a mysql dump of a vBulletin forum, you don't have to install the entire forum package to read it, you can instead use this simple script I made.
Download: vb_reader.rar
Download: vb_reader.rar
Parsed metasploit windows syscall table
Someone on game-deception is working on something based on this, so I shared what I did a while ago, but also posting it here for anyone interested.
I am of course talking about the following website:
http://www.metasploit.com/users/opcode/syscalls.html
... this file is basically a C (and C++) header based on information on that webpage. It does not include all syscalls, only those that are available on all listed versions of windows. Windows 7 is not included. It contains a table of syscall numbers sorted per windows version and also function prototypes.
Download: Parsed_Syscalls.h
I am of course talking about the following website:
http://www.metasploit.com/users/opcode/syscalls.html
... this file is basically a C (and C++) header based on information on that webpage. It does not include all syscalls, only those that are available on all listed versions of windows. Windows 7 is not included. It contains a table of syscall numbers sorted per windows version and also function prototypes.
Download: Parsed_Syscalls.h
MassImport - Import tons of WINAPIs to create confusion
Just a small code snippet that will reference (import) many WINAPIs at compile time.
This is pretty lame, but I often don't want people to know exactly which WINAPIs I use and feel lazy for importing them manually, so I made something that will import many APIs and it won't be obvious which ones exactly I use. :P
Download: MassImport.rar
This is pretty lame, but I often don't want people to know exactly which WINAPIs I use and feel lazy for importing them manually, so I made something that will import many APIs and it won't be obvious which ones exactly I use. :P
Download: MassImport.rar
Subscribe to:
Posts (Atom)