1. EachPod

Danny Quist & Valsmith: Covert Debugging: Circumventing Software Armoring Techniques

Author
Danny Quist & Valsmith
Published
Mon 09 Jan 2006
Episode Link
http://www.blackhat.com/html/bh-usa-07/bh-usa-07-speakers.html

Software armoring techniques have increasingly created problems for reverse engineers and software analysts. As protections such as packers, run-time obfuscators, virtual machine and debugger detectors become common newer methods must be developed to cope with them. In this talk we will present our covert debugging platform named Saffron. Saffron is based upon dynamic instrumentation techniques as well as a newly developed page fault assisted debugger. We show that the combination of these two techniques is effective in removing armoring from the most advanced software armoring systems. As a demonstration we will automatically remove packing protections from malware.

Share to: