lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAAhuQpPz=rpVwKZN8_+JcP_rJ87MuumV18F11mQyRB5rgj_QXg@mail.gmail.com>
Date: Tue, 3 Apr 2012 05:53:19 +0900
From: アドリアンヘンドリック
	<unixfreaxjp22@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re(3):  An April Fools' Day Android Payload

Oh, you noticed it. Good.
Of course not missing it, but just can't reverse it properly thru ARM
base at that moment..
That was why I wrote "x86".
Dan was kind enough to put his asm PoC code too & since the commands
was simple so a quick x86 logic reversing match will do fine to
confirm that the #shellcode wasn't an April's fool.

Or, you have a better idea jotting an ARM shellcode to asm within
5minutes during a train ride on a laptop?
If so, go ahead mock me. :)

BTW, like I said, is just a curiosity. And I rest my case.

Best regards.

----
 ZeroDay Japan http://0day.jp
 Hendrik ADRIAN /アドリアン・ヘンドリック

2012/4/3 Andrew Farmer <andfarm@...il.com>:
> On 2012-04-02, at 11:42, アドリアンヘンドリック wrote:
>> Just for the curiosity of "April fool",
>> actually I did a double check the $payload in x86 ASM code.
>
> Er... did you miss the part that said "ARM payload"? ARM is not x86. :)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ