<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>jz in reverse engineering</title>
    <link>https://jumpzero.tistory.com/</link>
    <description>who cares about reverse engineering anyway?</description>
    <language>ko</language>
    <pubDate>Wed, 17 Jun 2026 16:54:14 +0900</pubDate>
    <generator>TISTORY</generator>
    <ttl>100</ttl>
    <managingEditor>jz-</managingEditor>
    <image>
      <title>jz in reverse engineering</title>
      <url>https://t1.daumcdn.net/cfile/tistory/164ED5054C4184BAA0</url>
      <link>https://jumpzero.tistory.com</link>
    </image>
    <item>
      <title>new blog</title>
      <link>https://jumpzero.tistory.com/70</link>
      <description>blogspot으로 옮겼습니다...http://jz.pe.kr 를 연결해놨는데 잘 되려나</description>
      <category>Life</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/70</guid>
      <comments>https://jumpzero.tistory.com/70#entry70comment</comments>
      <pubDate>Thu, 3 Mar 2016 04:34:56 +0900</pubDate>
    </item>
    <item>
      <title>oldskewl from secuinside 2013</title>
      <link>https://jumpzero.tistory.com/69</link>
      <description>Secuinside 2013 예선에&amp;nbsp;낸&amp;nbsp;문제입니다.관심 있으시면 풀어보시라고 블로그에 올려봅니다.이것과 save the zombie 두문제를 냈었는데, zombie는 서버 세팅이 필요한지라...압축암호는 'secuinside'입니다.</description>
      <category>Reverse Code Engineering</category>
      <category>crackme</category>
      <category>oldskewl</category>
      <category>secuinside</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/69</guid>
      <comments>https://jumpzero.tistory.com/69#entry69comment</comments>
      <pubDate>Tue, 11 Jun 2013 03:25:07 +0900</pubDate>
    </item>
    <item>
      <title>PEView + file share patch</title>
      <link>https://jumpzero.tistory.com/67</link>
      <description>peview - http://www.magma.ca/~wjr/&amp;nbsp;
&amp;nbsp;
유용한 툴인데 파일을 열 때 FILE_SHARE_WRITE|FILE_SHARE_DELETE를 주지 않아서
&amp;nbsp;
peview로 연 파일을 hex editor에서 바로 수정할 수가 없습니다.
&amp;nbsp;
그걸 패치한 파일입니다. 
&amp;nbsp;
&amp;nbsp;


&amp;nbsp;

&amp;nbsp;
&amp;nbsp;</description>
      <category>Reverse Code Engineering</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/67</guid>
      <comments>https://jumpzero.tistory.com/67#entry67comment</comments>
      <pubDate>Wed, 19 Sep 2012 22:59:45 +0900</pubDate>
    </item>
    <item>
      <title>healiat - IAT recovery tool. basically aimed for Themida</title>
      <link>https://jumpzero.tistory.com/66</link>
      <description>&amp;nbsp;
http://code.google.com/p/healiat/
&amp;nbsp;
휴가때 잠깐 Themida의 API Redirection을 봤고 
&amp;nbsp;
복구해주는 툴을 만들어 봤습니다.
&amp;nbsp;
첫 아이디어는 간단했는데 .. 원래 Obfuscation은 한가지 방식을 걷어내면&amp;nbsp;다른 방식이 튀어나오기 마련이죠 ㅠㅠ
&amp;nbsp;
결국 처음에 생각했던 기능보다 많이 나가서, obfuscation도 해제하고, 함수코드들도&amp;nbsp;비교..</description>
      <category>개발새발</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/66</guid>
      <comments>https://jumpzero.tistory.com/66#entry66comment</comments>
      <pubDate>Fri, 14 Sep 2012 01:04:30 +0900</pubDate>
    </item>
    <item>
      <title>pework. pe parsing class (c++)</title>
      <link>https://jumpzero.tistory.com/65</link>
      <description>http://code.google.com/p/pework/pe header를 파싱할 때 편하게 사용할 수 있습니다.만든지는 오래 됐는데 이제야 공개하네요themida api redirection 복구툴을 공개하려고 코드를 정리하다가 이걸 먼저 해야 할 것 같아서.. ㅎㅎlib 형태로 두시고 static linking 하며 쓰면 편합니다.내일은 api redirection 복구툴을 공개할&amp;nbsp;예정...pework pe;pe.Open( &quot;c:\\win..</description>
      <category>개발새발</category>
      <category>C++</category>
      <category>pe header</category>
      <category>pework</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/65</guid>
      <comments>https://jumpzero.tistory.com/65#entry65comment</comments>
      <pubDate>Thu, 13 Sep 2012 01:20:23 +0900</pubDate>
    </item>
    <item>
      <title>windows null page allocation</title>
      <link>https://jumpzero.tistory.com/63</link>
      <description>



#include 

typedef DWORD (__stdcall *NTALLOCATEVIRTUALMEMORY)( DWORD handle,
											IN OUT PVOID baseaddr,
											DWORD zerobits,
											IN OUT PULONG size,
											DWORD type,
											DWORD protect ); 

void main()
{
	NTALLOCATEVIRT..</description>
      <category>개발새발</category>
      <category>windows null page allocation</category>
      <category>windows null page mapping</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/63</guid>
      <comments>https://jumpzero.tistory.com/63#entry63comment</comments>
      <pubDate>Tue, 17 May 2011 22:30:41 +0900</pubDate>
    </item>
    <item>
      <title>Adobe Reader X sandboxing?</title>
      <link>https://jumpzero.tistory.com/62</link>
      <description>

Adobe Reader X가 영문판만 릴리즈 됐습니다.&amp;nbsp;


한글 브라우저는 한글판 9.4로 리다이렉트되기때문에 ...&amp;nbsp;


궁금하신 분들은 아래 링크로 받아보시면 됩니다.


http://ardownload.adobe.com/pub/adobe/reader/win/10.x/10.0.0/en_US/AdbeRdr1000_en_US.exe





reader x는 샌드박싱을 홍보했는데.. ring3 후킹이 약~간 돼있네요.. 설마 이게..</description>
      <category>Reverse Code Engineering</category>
      <category>Adobe Reader X</category>
      <category>pdf</category>
      <category>sandbox</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/62</guid>
      <comments>https://jumpzero.tistory.com/62#entry62comment</comments>
      <pubDate>Sun, 21 Nov 2010 05:39:42 +0900</pubDate>
    </item>
    <item>
      <title>ollydbg.ini for your eye</title>
      <link>https://jumpzero.tistory.com/61</link>
      <description>

보기 편한 색과 글꼴로 맞춰놓은 ollydbg 설정파일입니다.&amp;nbsp;




scheme 5번에 저장돼있습니다.




plugin path, udd path, symbol path, lib path 등은 새로 다 맞춰주셔야 합니다.




그리고 24인치에서 맞춘 설정이라 창배치 다시하셔야할듯...







아니면 제 ollydbg.ini에서 appearance 관련 몇몇 부분만 copy&amp;amp;paste 하셔도 됩니다.










..</description>
      <category>Reverse Code Engineering</category>
      <category>OllyDbg</category>
      <category>ollydbg.ini</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/61</guid>
      <comments>https://jumpzero.tistory.com/61#entry61comment</comments>
      <pubDate>Tue, 26 Oct 2010 19:53:57 +0900</pubDate>
    </item>
    <item>
      <title>IDA + gdb with gdbserver</title>
      <link>https://jumpzero.tistory.com/60</link>
      <description>gdbserver와 ida를 이용하면 elf binary를 ida로 디버깅할 수 있습니다.


편하겠죠.


gdbserver host:port file


ubuntu rocks!




port 5555로 해봤습니다. 서버 세팅 됐고 이제 ida로 접속해보죠.




windows에도 ls를 복사해놓았습니다. 사실 binary는 둘중 하나에만 있어도 되긴 하지만...





debugger 설정하고






그다음엔 process options
..</description>
      <category>Reverse Code Engineering</category>
      <category>GDB</category>
      <category>gdbserver</category>
      <category>IDA</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/60</guid>
      <comments>https://jumpzero.tistory.com/60#entry60comment</comments>
      <pubDate>Sat, 3 Jul 2010 02:48:25 +0900</pubDate>
    </item>
    <item>
      <title>ollydbg 1.10 and its vulnerable dbghelp.dll</title>
      <link>https://jumpzero.tistory.com/59</link>
      <description>

&lt;button type=&quot;button&quot; class=&quot;btn_more&quot; id=&quot;more59_0&quot; data-id=&quot;59_0&quot;&gt;in english&lt;/button&gt;&lt;div class=&quot;moreless_content&quot; id=&quot;content59_0&quot; style=&quot;display: none;&quot;&gt;&lt;button type=&quot;button&quot; class=&quot;btn_less&quot; id=&quot;less59_0&quot; data-id=&quot;59_0&quot;&gt;&lt;span class=&quot;txt_fold&quot;&gt;fold&lt;..</description>
      <category>Reverse Code Engineering</category>
      <category>buffer overflow</category>
      <category>Crash</category>
      <category>dbghelp.dll</category>
      <category>export name bug</category>
      <category>OllyDbg</category>
      <author>jz-</author>
      <guid isPermaLink="true">https://jumpzero.tistory.com/59</guid>
      <comments>https://jumpzero.tistory.com/59#entry59comment</comments>
      <pubDate>Mon, 28 Jun 2010 13:25:34 +0900</pubDate>
    </item>
  </channel>
</rss>