AI-powered
podcast player
Listen to all your favourite podcasts with AI-powered features
How to Analyze a Gobinery?
When you look at se plus plus, there really aren't that many short cuts for splus plus. There's flirt signatures and other little tools that we can use to try to get some of the functionality out of the way. But that entrope that gets involved in the compilation process means, for example, that classes are gone, but class definitions are gone. We have no idea what reference is what. You don't even have a perfect control flow unless you're dynamically executing the samples. And it takes a lot of work to try to reverse engineer complex seplus plus binaries. Eventually we figured out that there are actually wonderful ways to rebuild gobinaries. Now we're looking at