病毒樣本分析







DOC
  ∗ 3ea648fe161d27a22d68cd8d6ee6b37294532e82
XLS 4.0
  ∗ 3fb082368a8062316976fdfeeceae130d98a3247
如何製作TLS PE檔案
如何製作XLS 4.0檔案
如何製作AutoRun PDF檔案
解決"loadlocale.c:129: _nl_intern_locale_data: Assertion"問題
解決"convert-im6.q16: attempt to perform an operation not allowed by the security policy"問題




IDA Pro







Python
  ∗ Hello, world!
  ⊕ x86
    ∗ Get Register Name
IDC
  ∗ Hello, world!
  ⊕ x86
    ∗ Entry Point
    ∗ Start Address
    ∗ Get Label Name
    ∗ Define Function
    ∗ Get Operand Type
    ∗ Disassembly Line
    ∗ Get DWORD Binary
    ∗ Get Operand Value
    ∗ Get Next Instruction
    ∗ Get Mnemonics、Operand
    ∗ Global、Local Variable
SDK v6.4
  ∗ Rebuild
  ⊕ Loader
    ∗ Build nesldr
    ∗ Build ida-snes-ldr
  ⊕ Plugins
    ∗ Build bankswitch
    ∗ Build Hello world!
SDK v6.8
  ∗ Debug ROM(NES)
  ∗ Debug ROM(SMD)
  ∗ Debug ROM(DOSBox)
SDK v7.3
  ∗ Rebuild
如何顯示OPCode
Tracing function
安裝IDA Free v7.0
Patch License(v7.3)
如何輸出Graph overview




OllyDbg







JMP $
快速鍵
Obfuscation
逆向MFC編譯的程式
解決"GetProcessImageFileNameW could not ..."問題



Ghidra







安裝環境




FCEUX







讓NES遊戲支援振動功能
  ∗ Register
  ∗ 移植FCEUX(支援振動)
  ⊕ Hack ROM
    ∗ Mighty Final Fight(街頭快打)
    ∗ Ninja Ryukenden III(忍者龍劍傳3)
Debug ROM
Patch Sprite(ASCII)
Patch Sprite(Index)




MAMED







Debug ROM
Debug Command




DOSBox







Debug ROM