Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

Posted

Hi Guys

As I've been searching through this topic , I've got some interesting picture aside of VM Fingerprints.... like I/O Backdoor in VMware... but my main question is that how to find a way like VMware Method ? I've read that the more reliable technique for detecting is relying on assembly-level code that behaves differently in VM... so how can I observe this behavior ???

Any little tiny clue would be appreciated

Best Regards

sandboxie

  • loadlibrarya
  • virtualprotectex(some other ring3 thread stuff too)
  • PE struct

bufferzone

  • same as sandboxie(both also have IOCTL vulnerabilities)

virtualbox

  • IOCTL exposure, SSDT, GPT etc..
  • process enumeration structs..
  • ring3 threads(depending on configuration)

vmware

  • same as virtualbox plus a DLL interface xD

Noob authors usually just detect them and logic bomb out(wait till no detection for decryption and execution of payload). If you can get a driver loaded you can easily detect all through sniffing or table mirror or entry checks. This 'isn't a problem' though to the communities and devs..how productive..

3rd party tools like buster sandbox analyzer make medial efforts to hide them..noobs can still defeat it from ring3

most pros seem to roll their own through FASM vt/amdv lib.

Edited by chickenbutt

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.