<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: RSR</title>
	<atom:link href="http://blog.didierstevens.com/2007/07/24/rsr/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2007/07/24/rsr/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-19504</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Sun, 18 Nov 2007 20:21:42 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-19504</guid>
		<description><![CDATA[Take a look at the update:
http://blog.didierstevens.com/2007/10/02/autoit-malware-revisited/]]></description>
		<content:encoded><![CDATA[<p>Take a look at the update:<br />
<a href="http://blog.didierstevens.com/2007/10/02/autoit-malware-revisited/" rel="nofollow">http://blog.didierstevens.com/2007/10/02/autoit-malware-revisited/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ruined</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-18826</link>
		<dc:creator><![CDATA[ruined]]></dc:creator>
		<pubDate>Wed, 14 Nov 2007 13:51:50 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-18826</guid>
		<description><![CDATA[AutoIt is a interpretated language (script) so it mean that the password is stored somewhere in the interpreter slice of file. I think

ruined]]></description>
		<content:encoded><![CDATA[<p>AutoIt is a interpretated language (script) so it mean that the password is stored somewhere in the interpreter slice of file. I think</p>
<p>ruined</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian Pepin</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-17223</link>
		<dc:creator><![CDATA[Brian Pepin]]></dc:creator>
		<pubDate>Tue, 06 Nov 2007 13:26:56 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-17223</guid>
		<description><![CDATA[It is still possiable to decompile autoIT scripts past version 3.2.5.1 It is done constantly in the autoit forums. However it is kept a secret and is frowned upon. A  ban is in place for those who pursue the secret  =\

From what I have heard, it isn&#039;t all that hard.

ender998@hotmail.com]]></description>
		<content:encoded><![CDATA[<p>It is still possiable to decompile autoIT scripts past version 3.2.5.1 It is done constantly in the autoit forums. However it is kept a secret and is frowned upon. A  ban is in place for those who pursue the secret  =\</p>
<p>From what I have heard, it isn&#8217;t all that hard.</p>
<p><a href="mailto:ender998@hotmail.com">ender998@hotmail.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AutoIt Malware Revisited &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-15040</link>
		<dc:creator><![CDATA[AutoIt Malware Revisited &#171; Didier Stevens]]></dc:creator>
		<pubDate>Tue, 02 Oct 2007 10:17:39 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-15040</guid>
		<description><![CDATA[[...] Filed under: Malware, Reverse Engineering &#8212; Didier Stevens @ 10:17   Since I’ve blogged about malware written with the AutoIt scripting language, I got a couple of mails asking for [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Filed under: Malware, Reverse Engineering &#8212; Didier Stevens @ 10:17   Since I’ve blogged about malware written with the AutoIt scripting language, I got a couple of mails asking for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-14115</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Fri, 14 Sep 2007 20:03:24 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-14115</guid>
		<description><![CDATA[&gt; any version after 3.2.5.1 will not decompile.

Because no official decompiler is available?]]></description>
		<content:encoded><![CDATA[<p>&gt; any version after 3.2.5.1 will not decompile.</p>
<p>Because no official decompiler is available?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AutoIt Member</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-13976</link>
		<dc:creator><![CDATA[AutoIt Member]]></dc:creator>
		<pubDate>Wed, 12 Sep 2007 08:47:07 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-13976</guid>
		<description><![CDATA[FYI... any version after 3.2.5.1 will not decompile.]]></description>
		<content:encoded><![CDATA[<p>FYI&#8230; any version after 3.2.5.1 will not decompile.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-12454</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Fri, 10 Aug 2007 15:30:56 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-12454</guid>
		<description><![CDATA[Haven’t researched yet how to decompile without a password, but I discovered that a compiled AutoIt script contains the MD5 hash of the password starting position 24 (an MD5 hash is 16 bytes long). That’s for an .a3x file, if you have an .EXE file, you will have to unpack it with UPX and search the compiled script at the end of the file.

You could extract the MD5 hash from the file and try to find the password, with bruteforcing, dictionary attack or rainbow tables (there are some online rainbowtable crackers, but plaintext.info seems to be out of business).

Success.]]></description>
		<content:encoded><![CDATA[<p>Haven’t researched yet how to decompile without a password, but I discovered that a compiled AutoIt script contains the MD5 hash of the password starting position 24 (an MD5 hash is 16 bytes long). That’s for an .a3x file, if you have an .EXE file, you will have to unpack it with UPX and search the compiled script at the end of the file.</p>
<p>You could extract the MD5 hash from the file and try to find the password, with bruteforcing, dictionary attack or rainbow tables (there are some online rainbowtable crackers, but plaintext.info seems to be out of business).</p>
<p>Success.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ice</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-12453</link>
		<dc:creator><![CDATA[Ice]]></dc:creator>
		<pubDate>Fri, 10 Aug 2007 14:55:08 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-12453</guid>
		<description><![CDATA[I really need help decompiling an AutoIt file that is screwing with my computer, but I can&#039;t figure out how to bypass the passphrase! I&#039;ve hex-edited the .exe and cannot find anything in particular, and Google-searching brings up nothing I can really understand.

Thanks for the help!]]></description>
		<content:encoded><![CDATA[<p>I really need help decompiling an AutoIt file that is screwing with my computer, but I can&#8217;t figure out how to bypass the passphrase! I&#8217;ve hex-edited the .exe and cannot find anything in particular, and Google-searching brings up nothing I can really understand.</p>
<p>Thanks for the help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-11907</link>
		<dc:creator><![CDATA[Rick]]></dc:creator>
		<pubDate>Tue, 31 Jul 2007 19:34:48 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-11907</guid>
		<description><![CDATA[Excellent article. I had a few thoughts on this. Would the AutoIT guys really store two versions of the script in the EXE? I know this sounds the most efficient, but we all know programmers are people and they do not always follow the path of least resistance. Just storing the encrypted/compressed script and then running it on the fly would be the path I think some programmers would take. 

It would be interesting to run this in a sandbox and see if the code shows up unencrypted in memory. The MD5 could just be a permissions check more than anything to see if the decompiler has the password and thereby also having the &quot;permission&quot; to view the code.

*I am not a programmer by trade so this may all seem like complete gibberish to you pro&#039;s. :)

Keep up the great work!]]></description>
		<content:encoded><![CDATA[<p>Excellent article. I had a few thoughts on this. Would the AutoIT guys really store two versions of the script in the EXE? I know this sounds the most efficient, but we all know programmers are people and they do not always follow the path of least resistance. Just storing the encrypted/compressed script and then running it on the fly would be the path I think some programmers would take. </p>
<p>It would be interesting to run this in a sandbox and see if the code shows up unencrypted in memory. The MD5 could just be a permissions check more than anything to see if the decompiler has the password and thereby also having the &#8220;permission&#8221; to view the code.</p>
<p>*I am not a programmer by trade so this may all seem like complete gibberish to you pro&#8217;s. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Keep up the great work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: www.andrewhay.ca &#187; Suggested Blog Reading - Tuesday/Wednesday July 24th/25th, 2007</title>
		<link>http://blog.didierstevens.com/2007/07/24/rsr/#comment-11645</link>
		<dc:creator><![CDATA[www.andrewhay.ca &#187; Suggested Blog Reading - Tuesday/Wednesday July 24th/25th, 2007]]></dc:creator>
		<pubDate>Wed, 25 Jul 2007 21:50:31 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/24/rsr/#comment-11645</guid>
		<description><![CDATA[[...] Really Simple Reversing (RSR) - This is quite cool. This is an example of Really Simple Reversing of a piece of malware. It’s written in the AutoIt scripting language and compiled to an EXE. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Really Simple Reversing (RSR) &#8211; This is quite cool. This is an example of Really Simple Reversing of a piece of malware. It’s written in the AutoIt scripting language and compiled to an EXE. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

