<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: XORSearch</title>
	<atom:link href="http://blog.didierstevens.com/programs/xorsearch/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: K P</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-40845</link>
		<dc:creator><![CDATA[K P]]></dc:creator>
		<pubDate>Mon, 06 Dec 2010 02:49:47 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-40845</guid>
		<description><![CDATA[The idea would be to watch as the 010 Hex Operations (or the Decode tab in FileInsight) steps through adding binary 1, e.g.:
nddgqwythy -&gt; oeehrxzuiz -&gt; pffisy{vj{ and onward.
Then all the XOR keys (0 to 255) that XORSearch tries, e.g.:
nddgqwythy -&gt; oeefpvxuix -&gt; lffesu{vj{ and onward.
And the ROL/ROR transforms that XORSearch does.
Ideally it would dump these to a list that could be inspected to find the &quot;real&quot; string that has been obfuscated.]]></description>
		<content:encoded><![CDATA[<p>The idea would be to watch as the 010 Hex Operations (or the Decode tab in FileInsight) steps through adding binary 1, e.g.:<br />
nddgqwythy -&gt; oeehrxzuiz -&gt; pffisy{vj{ and onward.<br />
Then all the XOR keys (0 to 255) that XORSearch tries, e.g.:<br />
nddgqwythy -&gt; oeefpvxuix -&gt; lffesu{vj{ and onward.<br />
And the ROL/ROR transforms that XORSearch does.<br />
Ideally it would dump these to a list that could be inspected to find the &#8220;real&#8221; string that has been obfuscated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-40835</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Sun, 05 Dec 2010 21:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-40835</guid>
		<description><![CDATA[@Anonymous So you want to see each transformation so you can select the one that makes sense to you? No, don&#039;t know such a program.

I could add binary add, but this would double the execution time of XORSearch.]]></description>
		<content:encoded><![CDATA[<p>@Anonymous So you want to see each transformation so you can select the one that makes sense to you? No, don&#8217;t know such a program.</p>
<p>I could add binary add, but this would double the execution time of XORSearch.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-40829</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Sun, 05 Dec 2010 19:35:04 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-40829</guid>
		<description><![CDATA[Do you know of a program (or have a 010 Editor script, or FileInsight plugin)  that starts with an obfuscated string portion like nddgqwythy.net and applies those Hex Modifications XOR, ROL, and ROT in sequence, so we can spot the original string by eye?

Would adding binary add to XORSearch be useful?]]></description>
		<content:encoded><![CDATA[<p>Do you know of a program (or have a 010 Editor script, or FileInsight plugin)  that starts with an obfuscated string portion like nddgqwythy.net and applies those Hex Modifications XOR, ROL, and ROT in sequence, so we can spot the original string by eye?</p>
<p>Would adding binary add to XORSearch be useful?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: REMnux: A Linux Distribution for Reverse-Engineering Malware</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-39318</link>
		<dc:creator><![CDATA[REMnux: A Linux Distribution for Reverse-Engineering Malware]]></dc:creator>
		<pubDate>Sun, 25 Jul 2010 04:03:54 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-39318</guid>
		<description><![CDATA[[...]  [...]]]></description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: REMnux &#8211; Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; Tux Files</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-39304</link>
		<dc:creator><![CDATA[REMnux &#8211; Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; Tux Files]]></dc:creator>
		<pubDate>Sat, 24 Jul 2010 03:51:09 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-39304</guid>
		<description><![CDATA[[...] de protecciones y cifrados: upx, packerid, bytehist, xorsearch, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] de protecciones y cifrados: upx, packerid, bytehist, xorsearch, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcosof Informatica y Telecomunicaciones &#187; Blog Archive &#187; REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware Leer más: Noticias de Seguridad Informática &#8211; Segu-Info: REMnux, Distribución de Linux para e</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-39248</link>
		<dc:creator><![CDATA[Marcosof Informatica y Telecomunicaciones &#187; Blog Archive &#187; REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware Leer más: Noticias de Seguridad Informática &#8211; Segu-Info: REMnux, Distribución de Linux para e]]></dc:creator>
		<pubDate>Thu, 22 Jul 2010 05:16:33 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-39248</guid>
		<description><![CDATA[[...] objdump, Radare, shellcode2.exe Detección de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. Análisis de PDF maliciosos: Didier’s PDF tools, Origami framework, Jsunpack-n, pdftk. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] objdump, Radare, shellcode2.exe Detección de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. Análisis de PDF maliciosos: Didier’s PDF tools, Origami framework, Jsunpack-n, pdftk. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; Shadow Security</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-39227</link>
		<dc:creator><![CDATA[REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; Shadow Security]]></dc:creator>
		<pubDate>Wed, 21 Jul 2010 08:50:45 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-39227</guid>
		<description><![CDATA[[...] objdump, Radare, shellcode2.exe Detección de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. Análisis de PDF maliciosos: Didier’s PDF tools, Origami framework, Jsunpack-n, pdftk. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] objdump, Radare, shellcode2.exe Detección de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. Análisis de PDF maliciosos: Didier’s PDF tools, Origami framework, Jsunpack-n, pdftk. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; Command Line</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-39199</link>
		<dc:creator><![CDATA[REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; Command Line]]></dc:creator>
		<pubDate>Tue, 20 Jul 2010 16:05:57 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-39199</guid>
		<description><![CDATA[[...] Radare, shellcode2.exe Detecci&#243;n de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. An&#225;lisis de PDF maliciosos: Didier&#8217;s PDF tools, Origami framework, Jsunpack-n, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Radare, shellcode2.exe Detecci&oacute;n de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. An&aacute;lisis de PDF maliciosos: Didier&rsquo;s PDF tools, Origami framework, Jsunpack-n, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; Laboratorio de Seguridad y Hacking</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-39198</link>
		<dc:creator><![CDATA[REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; Laboratorio de Seguridad y Hacking]]></dc:creator>
		<pubDate>Tue, 20 Jul 2010 15:36:39 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-39198</guid>
		<description><![CDATA[[...] objdump, Radare, shellcode2.exe Detección de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. Análisis de PDF maliciosos: Didier’s PDF tools, Origami framework, Jsunpack-n, pdftk. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] objdump, Radare, shellcode2.exe Detección de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. Análisis de PDF maliciosos: Didier’s PDF tools, Origami framework, Jsunpack-n, pdftk. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; SinapsysMx.Net</title>
		<link>http://blog.didierstevens.com/programs/xorsearch/#comment-39195</link>
		<dc:creator><![CDATA[REMnux, Distribución de Linux para el Análisis e Ingeniería Inversa de Malware &#124; SinapsysMx.Net]]></dc:creator>
		<pubDate>Tue, 20 Jul 2010 14:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/xorsearch/#comment-39195</guid>
		<description><![CDATA[[...] objdump, Radare, shellcode2.exe Detección de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. Análisis de PDF maliciosos: Didier’s PDF tools, Origami framework, Jsunpack-n, pdftk. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] objdump, Radare, shellcode2.exe Detección de protecciones y cifrados: upx, packerid, bytehist, xorsearch, TRiD. Análisis de PDF maliciosos: Didier’s PDF tools, Origami framework, Jsunpack-n, pdftk. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

