Unlikely most of the Denuvo cracks actually remove the virtualized code from the executable. Not feasible without extensive binary rewriter tooling (that, while being sloppable, still takes a lot of time to slop).
Interesting yeah you're right. Looking it up it seems that only 2 of the Denuvo cracks have completely removed Denuvo - oddly enough Assassin's Creed games both times. Usually they just use various tricks to fool the authentication, but leave the performance degradation and other issues of Denuvo.
It'll be interesting to see if LLMs do increase the rate of completely cleans.
I can't edit this post anymore but if you wanna read a bunch of stuff on the topic https://k0mkc.hatenablog.com/ is a nice blog. All in Japanese, but it should be perfectly translatable.
Funny thing is they removed all their blogposts on Griffin (an obfuscator several anticheats, including EA's, Riot's and FaceIT's utilize) for whatever reason.
I don’t think most obfuscators will care about self-modifying code anyway, outside of cases like packing (…and in that case you probably won’t be rewriting the unpacker stub anyway :D). Also self modifying code breaks on targets like Windows kernel drivers, which are a big target for SOTA obfuscation these days.
I guess Hex-Rays and Vector35 must be hallucinating their effects for, say, reverse engineering. OFC rev isn't be all and end all of computing but the effect LLMs had on security research and adjacent spaces (say, CTF) is interesting
Memories break Fable 5 for me as well in chatbot. I ask Opus a lot of sec related stuff and now if I even type “hello” in chat it gets insta-downgraded to Opus 5.
reply