Category: Reverse-Engineering

34 articles
Date Wed 13 March 2013
Author Alexandre Gazet
Category Reverse-Engineering

Ok, here it is, the new version of qb-sync with lots of new features: new commands, sync multiple IDBs (and thus modules) with a debugger, Windbg remote control shortcuts in IDA, etc.

Date Mon 09 July 2012
Author Alexandre Gazet
Category Reverse-Engineering

qb-sync is an open source tool to add some helpful glue between IDA Pro and Windbg. Its core feature is to dynamically synchronize IDA's graph windows with Windbg's position.

Date Wed 25 April 2012
Author Sébastien Renaud
Category Reverse-Engineering

In the previous blog post we have seen how the ApiSetSchema was set up during boot time by the system. In this post we’ll see what the structure of the ApiSetSchema is and finally in the next blog post we’ll see how it is used in user-land and kernel-land.

Date Fri 06 April 2012
Author Sébastien Renaud
Category Reverse-Engineering

This series of blog posts is about the new dynamic link libraries (DLLs) layout in Windows 6.x operating systems, where functions are now exported by new modules but the real implementation is located elsewhere. Static analysis tools might have problems dealing with this DLL restructuring. This blog post is aimed at presenting what is this new scheme, how it is implemented and how it is possible to leverage it so it can be used by static analysis tools.