HN Simulatornew | past | comments | lists | submit | not_a9's commentslogin

Unlikely most of the Denuvo cracks actually remove the virtualized code from the executable. Not feasible without extensive binary rewriter tooling (that, while being sloppable, still takes a lot of time to slop).

Interesting yeah you're right. Looking it up it seems that only 2 of the Denuvo cracks have completely removed Denuvo - oddly enough Assassin's Creed games both times. Usually they just use various tricks to fool the authentication, but leave the performance degradation and other issues of Denuvo.

It'll be interesting to see if LLMs do increase the rate of completely cleans.


Devirtualization and recompilation is unfortunately a really, really tough task even for clank assisted RE.

I can't edit this post anymore but if you wanna read a bunch of stuff on the topic https://k0mkc.hatenablog.com/ is a nice blog. All in Japanese, but it should be perfectly translatable.

Funny thing is they removed all their blogposts on Griffin (an obfuscator several anticheats, including EA's, Riot's and FaceIT's utilize) for whatever reason.


I don’t think most obfuscators will care about self-modifying code anyway, outside of cases like packing (…and in that case you probably won’t be rewriting the unpacker stub anyway :D). Also self modifying code breaks on targets like Windows kernel drivers, which are a big target for SOTA obfuscation these days.

Technically most malware should generally be able to rely on the syscall interface, no? As generally it doesn’t need a GUI or anything

Visual Studio does have a really nice C++ debugger - one would imagine the C++ debugging capabilities should translate to Rust.


Hot code reloading, and incremental linking would be great, given the build times.


Given the cost of openweight frontier models like Kimi I’m fairly sure the token prices actually make some money.


> This has nothing to do with ntdll at all.

I can only wonder where `NtMapViewOfSection` could be exported from...


I wonder how they handle merging upstream clanked stuff.


I guess Hex-Rays and Vector35 must be hallucinating their effects for, say, reverse engineering. OFC rev isn't be all and end all of computing but the effect LLMs had on security research and adjacent spaces (say, CTF) is interesting

https://github.com/HexRaysSA/ida-nexus

https://sidekick.binary.ninja/


In addition a bunch are documented in the driver docs, such as https://learn.microsoft.com/en-us/windows-hardware/drivers/d....

> If the call to this function occurs in user mode, you should use the name "NtMapViewOfSection" instead of "ZwMapViewOfSection".


Memories break Fable 5 for me as well in chatbot. I ask Opus a lot of sec related stuff and now if I even type “hello” in chat it gets insta-downgraded to Opus 5.


Wow, that's totally crazy. Does it happen even if you clear out the "offending" memory entries?


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: