48 Followers
11 Following
6 Posts
I have a bottle of scotch, roll of toilet paper and 1.5kg of cheese - #why2025 im ready;)
If you are around and feel like it swing by Chrząszczyżewoszyce (https://wiki.why2025.org/Village:Chrz%C4%85szczy%C5%BCewoszyce) and say hello:)
Village:Chrząszczyżewoszyce - WHY2025 wiki

Few more scraps of code for #FlareOn11 this time c10 - #binja lifter and emulator for inner vm https://gist.github.com/mak/16d342594d26a9be8d0345c87d82bb3d
flare-on 2024 - c10

flare-on 2024 - c10. GitHub Gist: instantly share code, notes, and snippets.

Gist
I kinda enjoy this year #flareon11 learned a thing about ecc and spend way to much time writing deobfuscator for c9 here is the gist of it while writeup is in writing https://gist.github.com/mak/62cec665fa3339c4424317dedca004ee this should give a nice and clean disasm :)
gist:62cec665fa3339c4424317dedca004ee

GitHub Gist: instantly share code, notes, and snippets.

Gist

I can finally reveal some research I've been involved with over the past year or so.

We (@redford, @mrtick and I) have reverse engineered the PLC code of NEWAG Impuls EMUs. These trains were locking up for arbitrary reasons after being serviced at third-party workshops. The manufacturer argued that this was because of malpractice by these workshops, and that they should be serviced by them instead of third parties.

1/4

Yesterday i did a small presentation at @OMHconf about fixing pe files - you can find my slides here https://malwarelab.pl/t/omh2023
...

Ups forgot about this one:)
Since everyone is flexing with their #flareon10 chal13 deobfuscators - here is my https://lokalhost.pl/dump/f2023_13_deob.py - pipe it to nasm and you’ll have a nice new binary ready to be analyzed ;)