<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Jason Raber</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/274-jason-raber" rel="self"/>
    <description>Latest security documents RSS feed for author Jason Raber</description>
    <language>en-us</language>
    <item>
      <title>[Slides] Reverse Engineering with Hardware Debuggers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1289-jason-cheatham"&gt;Jason Cheatham&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/274-jason-raber"&gt;Jason Raber&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/49-reverse-engineering"&gt;reverse engineering&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/85-debugger"&gt;debugger&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/86-debugging"&gt;debugging&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This is a brief tutorial of one of the reverse engineering tools (Hardware Emulator) used by the Air Force Research Laboratory to analyze application and driver code on x86 systems. It&#8217;s also a neat way to debug hypervisors!</description>
      <pubDate>Tue, 20 Sep 2011 20:26:13 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4034-reverse-engineering-with-hardware-debuggers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4034-reverse-engineering-with-hardware-debuggers</guid>
    </item>
    <item>
      <title>[Video] QuietRIATT: Rebuilding the Import Address Table Using Hooked DLL Calls</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/274-jason-raber"&gt;Jason Raber&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/915-brian-krumheuer"&gt;Brian Krumheuer&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/49-reverse-engineering"&gt;reverse engineering&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 17 Aug 2010 06:17:51 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2823-quietriatt-rebuilding-the-import-address-table-using-hooked-dll-calls</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2823-quietriatt-rebuilding-the-import-address-table-using-hooked-dll-calls</guid>
    </item>
    <item>
      <title>[Slides] QuietRIATT: Rebuilding the Import Address Table Using Hooked DLL Calls</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/274-jason-raber"&gt;Jason Raber&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/915-brian-krumheuer"&gt;Brian Krumheuer&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/49-reverse-engineering"&gt;reverse engineering&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 17 Aug 2010 06:17:50 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2821-quietriatt-rebuilding-the-import-address-table-using-hooked-dll-calls</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2821-quietriatt-rebuilding-the-import-address-table-using-hooked-dll-calls</guid>
    </item>
    <item>
      <title>[Audio] QuietRIATT: Rebuilding the Import Address Table Using Hooked DLL Calls</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/274-jason-raber"&gt;Jason Raber&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/915-brian-krumheuer"&gt;Brian Krumheuer&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/49-reverse-engineering"&gt;reverse engineering&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 17 Aug 2010 06:17:49 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2820-quietriatt-rebuilding-the-import-address-table-using-hooked-dll-calls</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2820-quietriatt-rebuilding-the-import-address-table-using-hooked-dll-calls</guid>
    </item>
    <item>
      <title>[Slides] Helikaon Linux Debuger</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/274-jason-raber"&gt;Jason Raber&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/85-debugger"&gt;debugger&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/22-recon-2008"&gt;REcon 2008&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: The Linux OS is not immune to malware and viruses. The reverse engineer is faced with fighting though anti-debugging protections when trying to understand these binaries. This can be a tedious and time consuming process. COTS debuggers, such as GDB and IDA Pro, are detected in Linux utilizing a variety of anti-debugging techniques. I have developed a stealthy Linux-driver-based debugger named "Helikaon" that will aid the reverse engineer in debugging a running executables without being detected. Guest Helikaon injects a jump at runtime from kernel land into a user mode running process rather than using standard debugger breakpoints like "INT 3" or DR0-DR7 hardware registers. Find out alternate techniques for dynamic analysis in the Linux environment.</description>
      <pubDate>Tue, 21 Apr 2009 23:34:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/770-helikaon-linux-debuger</link>
      <guid>http://secdocs.lonerunners.net/documents/details/770-helikaon-linux-debuger</guid>
    </item>
    <item>
      <title>[Video] Helikaon Linux Debuger</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/274-jason-raber"&gt;Jason Raber&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/85-debugger"&gt;debugger&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/22-recon-2008"&gt;REcon 2008&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: The Linux OS is not immune to malware and viruses. The reverse engineer is faced with fighting though anti-debugging protections when trying to understand these binaries. This can be a tedious and time consuming process. COTS debuggers, such as GDB and IDA Pro, are detected in Linux utilizing a variety of anti-debugging techniques. I have developed a stealthy Linux-driver-based debugger named "Helikaon" that will aid the reverse engineer in debugging a running executables without being detected. Guest Helikaon injects a jump at runtime from kernel land into a user mode running process rather than using standard debugger breakpoints like "INT 3" or DR0-DR7 hardware registers. Find out alternate techniques for dynamic analysis in the Linux environment.</description>
      <pubDate>Tue, 21 Apr 2009 23:34:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/771-helikaon-linux-debuger</link>
      <guid>http://secdocs.lonerunners.net/documents/details/771-helikaon-linux-debuger</guid>
    </item>
  </channel>
</rss>

