<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.1" -->
<rss version="0.92">
<channel>
	<title>Reverse Engineering Team Blog</title>
	<link>http://www.reteam.org/blog</link>
	<description></description>
	<lastBuildDate>Fri, 03 Aug 2007 17:23:14 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Notes on Windows Vista Forensics</title>
		<description>Hello,
With Vista many Forensics analysis need to be reviewed, so SecurityFocus published a paper where new Vista's features and relative Forensics analysis.

http://www.securityfocus.com/infocus/1889

http://www.securityfocus.com/infocus/1890

Useful to learn how to hide/discover "something" in this new Environment

Have a nice Day </description>
		<link>http://www.reteam.org/blog/2007/05/13/notes-on-windows-vista-forensics/</link>
			</item>
	<item>
		<title>ring3 vs ring0</title>
		<description>Me and my friend sgrakkyu (ciao sgra ) were talking about this nice feature to go to ring0 from ring3, altough it is not useable for evil or tricky purposes  There are some tricks to go to ring0 from ring3 (\device\phisicalmemory, some debug api related overflows etc), unluckily they ...</description>
		<link>http://www.reteam.org/blog/2007/05/04/ring3-vs-ring0/</link>
			</item>
	<item>
		<title>Yahoo Messenger Social Engineering Vulnerability</title>
		<description>A pseudo vulnerability which can be achieved using multi-transfer between two identities on Yahoo Messenger and social engineering.No practical attack but interesting none the less.
Attached is a paper describing the attack and an implementation.

All the best,
bLaCk

PoC </description>
		<link>http://www.reteam.org/blog/2007/02/05/yahoo-messenger-social-engineering-vulnerability/</link>
			</item>
	<item>
		<title>Paper on Vista networkin, and a vmware detection trick</title>
		<description>There is a nice paper about a research on windows vista new networking stack
http://www.securityfocus.com/brief/260

by the way, i was working on vmware, i have casually found it uses always the same "physical memory" address ranges to map bios and pci stuff (F0000000 - F0FFF000 and FE000000 - FE1FFFFF) on an emulated ...</description>
		<link>http://www.reteam.org/blog/2006/07/24/paper-on-vista-networkin-and-a-vmware-detection-trick/</link>
			</item>
	<item>
		<title>Metasploit info</title>
		<description>a friend posted me this stuff, which is a snippet of code used to retrieve the eip of the first instruction line. This is a common shellcode used in metasploit

D9 EE                 FLDZ
D9 74 24 ...</description>
		<link>http://www.reteam.org/blog/2006/01/08/metasploit-info/</link>
			</item>
	<item>
		<title>Cogito ergo sum</title>
		<description>Reversing applies to everything, not only to software or hardware. What about if we reverse our "reality" to understand how it works? Well usually this is the work of a physicist 
Let's see some trick! What we can feel with our senses is just information, what about this information? Could ...</description>
		<link>http://www.reteam.org/blog/2005/08/21/cogito-ergo-sum/</link>
			</item>
	<item>
		<title>Hook now pray later</title>
		<description>I was working on a small app to hook the keyboard, i used SetWindowsHookEx function to set a WH_KEYBOARD hook. My intent was to hook the "on screen keyboard" usage. So i write my dll with my nice hook procedure, but something goes wrong. Hook seems not to work properly! ...</description>
		<link>http://www.reteam.org/blog/2005/07/05/hook-now-pray-later/</link>
			</item>
	<item>
		<title>Nice TheMida tutorial</title>
		<description>Here is a nice tutorial on how to completely defeat TheMida

Click here to view the link..


Thanks to rce for this link!
Enjoy  
AndreaGeddon </description>
		<link>http://www.reteam.org/blog/2005/06/28/nice-themida-tutorial/</link>
			</item>
	<item>
		<title>Strongbit Execryptor Hardkey License Manager</title>
		<description>I was working on execryptor and the relative license manager, based on Hardkey4, an asymmetric algorithm. The packer itself is nice, the polmorphic engine is wonderful, there are several anti-debugging tricks:
PEB.BeingDebugged
PEB.NtGlobalFlag
Static tls callbacks
Crc on exe file (not image)
CheckRemoteDebuggerPresent (only &#62;xpsp1)
FindWindow (searches for ollydebug registered class name)
Olly Exe exports (searches in ...</description>
		<link>http://www.reteam.org/blog/2005/06/08/strongbit-execryptor-hardkey-license-manager/</link>
			</item>
	<item>
		<title>What The Hack event in danger of cancellation</title>
		<description>Zeelock recently brought it to my attention the matter of a Hack convention in the Netherlands is currently in discussions with the mayor of the location they wish to use over cancellation of the event. This website is not about hacking but I figure quite a number of visitors will ...</description>
		<link>http://www.reteam.org/blog/2005/05/29/what-the-hack-event-in-danger-of-cancellation/</link>
			</item>
</channel>
</rss>
