<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet href="http://rss.egloos.com/style/blog.xsl" type="text/xsl" media="screen"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
	<title>SecurityCode</title>
	<link>http://leony.egloos.com</link>
	<description>Geek Interests</description>
	<language>ko</language>
	<pubDate>Wed, 04 Nov 2009 00:32:44 GMT</pubDate>
	<generator>Egloos</generator>
	<image>
		<title>SecurityCode</title>
		<url>http://pds.egloos.com/logo/1/200507/18/64/c0026364.jpg</url>
		<link>http://leony.egloos.com</link>
		<width>80</width>
		<height>60</height>
		<description>Geek Interests</description>
	</image>
  	<item>
		<title><![CDATA[ X86 Opcode map  ]]> </title>
		<link>http://leony.egloos.com/5113456</link>
		<guid>http://leony.egloos.com/5113456</guid>
		<description>
			<![CDATA[ 
  <br><a href="http://ref.x86asm.net/geek32.html">http://ref.x86asm.net/geek32.html</a>			 ]]> 
		</description>
		<category>[x86]assem</category>

		<comments>http://leony.egloos.com/5113456#comments</comments>
		<pubDate>Wed, 04 Nov 2009 00:32:44 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ Javascript unicode encoded shellcode to hex(\x type) ]]> </title>
		<link>http://leony.egloos.com/5036073</link>
		<guid>http://leony.egloos.com/5036073</guid>
		<description>
			<![CDATA[ 
  <p>encodedShell = '%u10EB%u4B5B%uC933%uB966%u03B8%u3480%uBD0B%uFAE2%u05EB%uEBE8%uFFFF'<br>x = encodedShell.replace('%u','')<br>length = len(x)/4<br>sh = ''<br>for i in range(length):<br>&nbsp;sh = sh + r'\x' + x[2:4] + r'\x' + x[:2]<br>&nbsp;x = x[4:]<br>print sh<br></p>			 ]]> 
		</description>
		<category>Web</category>

		<comments>http://leony.egloos.com/5036073#comments</comments>
		<pubDate>Sun, 09 Aug 2009 14:15:29 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ Black Hat USA 2009 papers ]]> </title>
		<link>http://leony.egloos.com/5026659</link>
		<guid>http://leony.egloos.com/5026659</guid>
		<description>
			<![CDATA[ 
  <br><a href="http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html">http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html</a>			 ]]> 
		</description>
		<category>News</category>

		<comments>http://leony.egloos.com/5026659#comments</comments>
		<pubDate>Thu, 30 Jul 2009 01:12:04 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ GeoIP in WireShark 1.2 - interesting update ]]> </title>
		<link>http://leony.egloos.com/5017122</link>
		<guid>http://leony.egloos.com/5017122</guid>
		<description>
			<![CDATA[ 
  <p jquery1248067398547="90">WireShark 가 얼마전 1.2 로 업데이트 되면서 새로운 기능을 선보였다.<br></p><p>바로 GeoIP를 지원하는 것이다. </p><p>GeoIP는 특정 IP 주소가 &nbsp;어느 지역의 IP 인지 데이터베이스화 하고 있는 파일로 <br>이번 WireShark에 해당 기능이 삽입됨으로써 캡쳐된 파일의 IP 주소를 GeoIP 로 먼저 검색한&nbsp;후 검색된 지역을</p><p><a href="http://openstreetmap.org/">http://openstreetmap.org</a>&nbsp;의 맵 서비스를 이용하여&nbsp;&nbsp;찾는다.<br></p><p><br>Setting...<br></p><p>1. GeoIP 데이터 베이스 다운로드</p><p><a href="http://geolite.maxmind.com/download/geoip/database/GeoLiteCountry/GeoIP.dat.gz">http://geolite.maxmind.com/download/geoip/database/GeoLiteCountry/GeoIP.dat.gz</a><br><a href="http://geolite.maxmind.com/download/geoip/database/GeoLiteCity.dat.gz">http://geolite.maxmind.com/download/geoip/database/GeoLiteCity.dat.gz</a><br><a href="http://geolite.maxmind.com/download/geoip/database/asnum/GeoIPASNum.dat.gz">http://geolite.maxmind.com/download/geoip/database/asnum/GeoIPASNum.dat.gz</a></p><p>다운받은 파일을 압축을 풀어 C:\GeoIP&nbsp; 에 넣는다.</p><p>Edit -&gt; Preferences -&gt; Name Resolution -&gt; GeoIP database directory 를 클릭하여 edit 에서 C:\GeoIP 폴더를 추가<br></p><p>2. WireShark restart<br>3. 캡쳐<br>4. Statistics -&gt; Endpoints List -&gt; IPv4&nbsp; Click<br>5. Map Click<br><br></p><p>reference site: <br><a href="http://www.wireshark.org/lists/wireshark-dev/200902/msg00154.html">http://www.wireshark.org/lists/wireshark-dev/200902/msg00154.html</a></p><p><a href="http://www.lovemytool.com/blog/2009/07/joke_snelders2.html">http://www.lovemytool.com/blog/2009/07/joke_snelders2.html</a></p><p><a href="http://wireshark.cbn.net.id/download/win32/wireshark-win32-1.2.0.exe"></a>&nbsp;</p>			 ]]> 
		</description>
		<category>Network</category>

		<comments>http://leony.egloos.com/5017122#comments</comments>
		<pubDate>Mon, 20 Jul 2009 05:28:22 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ defcon ctf 2009 bin100 ]]> </title>
		<link>http://leony.egloos.com/4995323</link>
		<guid>http://leony.egloos.com/4995323</guid>
		<description>
			<![CDATA[ 
  defcon ctf 2009 prequal 에서 Binary Leetness 100 을 분석한 주요 내용이다.<br><br>Unix 및 Linux 계열의 OS에서 binary file를 분석할 때 해당 파일이 어떠한 정보를 가지고 있는지<br>확인해볼 필요가 있는데 file command를 이용하여 바이너리에 대한 파일 타입정보를 얻어 오면,,,<br><br>function이&nbsp;statically linked되어 있고 symbol information이 stripped 되어 있는걸 알 수 있다. -ㅁ-;;<br><br><img class="image_left" border="0" onmouseover="this.style.cursor='pointer'" alt="" src="http://pds13.egloos.com/pds/200906/28/64/c0026364_4a4771fc3522a.png" width="400" height="39.6460176991" onclick="Control.Modal.openDialog(this, event, 'http://pds13.egloos.com/pds/200906/28/64/c0026364_4a4771fc3522a.png');" align="left" /><br><br><br><br>binary 의 strings 결과 이다.<br><br># strings -a f414376cc2322d4ad4c5cd364e89fd34<br><br><img class="image_left" border="0" onmouseover="this.style.cursor='pointer'" alt="" src="http://pds13.egloos.com/pds/200906/28/64/c0026364_4a47729a32a9c.png" width="400" height="229.457364341" onclick="Control.Modal.openDialog(this, event, 'http://pds13.egloos.com/pds/200906/28/64/c0026364_4a47729a32a9c.png');" align="left" /><br><br><br><br><br><br><br><br><br><br><br><br><br>UPX 라는 ASCII문자열이 보인다.<br><br>binary가&nbsp;stripped 되어 있기 때문에&nbsp;IDA를 이용하여 원격 디버깅으로 팩을 풀어보았다.<br><br>This is remote debugging&nbsp;using IDA pro....&nbsp; if you execute this command port 6002 open... :)<br><br><img class="image_left" border="0" onmouseover="this.style.cursor='pointer'" alt="" src="http://pds13.egloos.com/pds/200906/28/64/c0026364_4a477c64478a7.png" width="329" height="48" onclick="Control.Modal.openDialog(this, event, 'http://pds13.egloos.com/pds/200906/28/64/c0026364_4a477c64478a7.png');" align="left" /><br><br><br><br>upx의 특정 signature인 popa retn 까지 커서를 이동시켜 파일을 실행한 후 이후의 코드를&nbsp;step over하여 팩을 풀면 original binary를 0x8048000 주소에 위치시킨다.<br><br><img class="image_left" border="0" onmouseover="this.style.cursor='pointer'" alt="" src="http://pds13.egloos.com/pds/200906/28/64/c0026364_4a477e334870b.png" width="400" height="167.2" onclick="Control.Modal.openDialog(this, event, 'http://pds13.egloos.com/pds/200906/28/64/c0026364_4a477e334870b.png');" align="left" /><br><br><br><br><br><br><br><br><br><br><br><br>scroll down 시키면 answer가 나오고 밑에 answer를 비교하는 루틴을 탄다.<br><br><img class="image_left" border="0" onmouseover="this.style.cursor='pointer'" alt="" src="http://pds12.egloos.com/pds/200906/28/64/c0026364_4a47794db555a.png" width="400" height="267.5944334" onclick="Control.Modal.openDialog(this, event, 'http://pds12.egloos.com/pds/200906/28/64/c0026364_4a47794db555a.png');" align="left" />			 ]]> 
		</description>
		<category>System</category>

		<comments>http://leony.egloos.com/4995323#comments</comments>
		<pubDate>Sun, 28 Jun 2009 13:19:49 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ computer security video ]]> </title>
		<link>http://leony.egloos.com/4928780</link>
		<guid>http://leony.egloos.com/4928780</guid>
		<description>
			<![CDATA[ 
  <a href="http://securitytube.net/"><br>http://securitytube.net/</a>			 ]]> 
		</description>
		<category>Etc..</category>

		<comments>http://leony.egloos.com/4928780#comments</comments>
		<pubDate>Tue, 28 Apr 2009 04:29:39 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ 바이너리 수정 ]]> </title>
		<link>http://leony.egloos.com/4924620</link>
		<guid>http://leony.egloos.com/4924620</guid>
		<description>
			<![CDATA[ 
  <br>유닉스 계열(유분투, 센트, etc...)&nbsp;시스템의 콘솔에서&nbsp;바이너리 헥스 값 수정<br><br>vi 에디터와 hexdump인 xxd 를 사용한다.<br><br># vi binary<br><br>:%!xxd<br><br>수정 후<br><br>:%!xxd -r<br><br>:wq<br><br><br>			 ]]> 
		</description>
		<category>SeLinux</category>

		<comments>http://leony.egloos.com/4924620#comments</comments>
		<pubDate>Fri, 24 Apr 2009 05:11:57 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ IPligence - 위치 정보 검색 ]]> </title>
		<link>http://leony.egloos.com/4893614</link>
		<guid>http://leony.egloos.com/4893614</guid>
		<description>
			<![CDATA[ 
  <br>구글맵을 이용하여 검색할 IP 및&nbsp;URL의&nbsp;위치 정보를 찾아주는 기능을 하는 사이트이다.<br><br><a href="http://www.ipligence.com/geolocation/?lang=en">http://www.ipligence.com/geolocation/?lang=en</a><br><br>최근 웜을 보면 Geoip 와 같은&nbsp;데이터베이스를&nbsp;&nbsp;이용하여 <br><br>위치정보를 검색하는&nbsp;넘이 등장하고 있다.<br><br>해당지역을 필터링 시키기 위해서다.<br><br>			 ]]> 
		</description>
		<category>News</category>

		<comments>http://leony.egloos.com/4893614#comments</comments>
		<pubDate>Fri, 27 Mar 2009 01:25:28 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ backtrack 4 beta released ]]> </title>
		<link>http://leony.egloos.com/4844842</link>
		<guid>http://leony.egloos.com/4844842</guid>
		<description>
			<![CDATA[ 
  <p>backtrack 4 베타 버전이 릴리즈 되었다.<br><br>주목할만한 점은 이번 베타 버전에 GPU computing을 할 수 있게 CUDA 를 지원한다는 것이고<br><br>pyrit 라는 파이썬 코드를 이용해 워드파일에 대한 wpa, wpa2-psk 의 해쉬 테이블을 gpu로 빠르게 생성할 수 있다.<br></p><p>aircrack-ng는 해당 해쉬테이블을 이용하여 대입속도를 높일 것이다.<br><br>CUDA를 지원하는 그래픽 카드: <a href="http://en.wikipedia.org/wiki/CUDA#Supported_GPUs">http://en.wikipedia.org/wiki/CUDA#Supported_GPUs<br><br></a>ref: <a href="http://www.remote-exploit.org/backtrack_download.html">http://www.remote-exploit.org/backtrack_download.html</a><br></p>			 ]]> 
		</description>
		<category>News</category>

		<comments>http://leony.egloos.com/4844842#comments</comments>
		<pubDate>Thu, 12 Feb 2009 01:32:35 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
	<item>
		<title><![CDATA[ POC2008 Reversing Mission 2 ]]> </title>
		<link>http://leony.egloos.com/4746178</link>
		<guid>http://leony.egloos.com/4746178</guid>
		<description>
			<![CDATA[ 
  <br>POC 2008의 Hacker's Dream&nbsp;&nbsp;-&gt; Reversing Mission 2<br><br><a href="http://pds13.egloos.com/pds/200811/23/64/POC2008_reversing2_solution.pdf">POC2008_reversing2_solution.pdf</a><br><br><br><br>			 ]]> 
		</description>
		<category>[x86]assem</category>

		<comments>http://leony.egloos.com/4746178#comments</comments>
		<pubDate>Sun, 23 Nov 2008 03:25:44 GMT</pubDate>
		<dc:creator>codexb</dc:creator>
	</item>
</channel>
</rss>
