<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for KOrUPt</title>
	<atom:link href="http://korupt.co.uk/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://korupt.co.uk</link>
	<description>Disassembling logic at its best...</description>
	<lastBuildDate>Sat, 13 Feb 2010 01:35:26 +0000</lastBuildDate>
	
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Unpacking ASPack by XPN</title>
		<link>http://korupt.co.uk/?p=42&#038;cpage=1#comment-2387</link>
		<dc:creator>XPN</dc:creator>
		<pubDate>Sat, 13 Feb 2010 01:35:26 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=42#comment-2387</guid>
		<description>Excellent tut mate, just getting into unpacking and this was a good first step.

Thanks again
XPN</description>
		<content:encoded><![CDATA[<p>Excellent tut mate, just getting into unpacking and this was a good first step.</p>
<p>Thanks again<br />
XPN</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Revised PE infecter source by Bill</title>
		<link>http://korupt.co.uk/?p=112&#038;cpage=1#comment-2322</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Fri, 05 Feb 2010 15:26:40 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=112#comment-2322</guid>
		<description>KOrUPt thanks for sharing it with us.
I need your help though; I tried to infect a packed exe with UPX, and now it does not start at all. It says &quot;Error executing program&quot;. Do you have any idea why ?
Thanks in advance.</description>
		<content:encoded><![CDATA[<p>KOrUPt thanks for sharing it with us.<br />
I need your help though; I tried to infect a packed exe with UPX, and now it does not start at all. It says &#8220;Error executing program&#8221;. Do you have any idea why ?<br />
Thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PE Infection by sunorr</title>
		<link>http://korupt.co.uk/?p=75&#038;cpage=1#comment-2218</link>
		<dc:creator>sunorr</dc:creator>
		<pubDate>Wed, 13 Jan 2010 14:25:07 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=75#comment-2218</guid>
		<description>if we move the exe file which infected by this program to the other windows OS Version. I don`t think it can run normaly.

sorry,my English is poorrr~</description>
		<content:encoded><![CDATA[<p>if we move the exe file which infected by this program to the other windows OS Version. I don`t think it can run normaly.</p>
<p>sorry,my English is poorrr~</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on JmpFinder by Pradeep</title>
		<link>http://korupt.co.uk/?p=80&#038;cpage=1#comment-2002</link>
		<dc:creator>Pradeep</dc:creator>
		<pubDate>Mon, 12 Oct 2009 13:36:48 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=80#comment-2002</guid>
		<description>Hi,

Can we conclude anything if JMP instruction is found in code.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Can we conclude anything if JMP instruction is found in code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PE Infection by Pradeep</title>
		<link>http://korupt.co.uk/?p=75&#038;cpage=1#comment-2001</link>
		<dc:creator>Pradeep</dc:creator>
		<pubDate>Mon, 12 Oct 2009 12:56:59 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=75#comment-2001</guid>
		<description>Hi,

very good post KOrUPt!!
How would you detect this kind of infection.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>very good post KOrUPt!!<br />
How would you detect this kind of infection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Unpacking DLL&#8217;s without LoadDLL by Twink</title>
		<link>http://korupt.co.uk/?p=25&#038;cpage=1#comment-1478</link>
		<dc:creator>Twink</dc:creator>
		<pubDate>Fri, 11 Sep 2009 22:03:32 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=25#comment-1478</guid>
		<description>Thanks! Good work.</description>
		<content:encoded><![CDATA[<p>Thanks! Good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Defcon CTF 09 Quals&#8230; by psifertex</title>
		<link>http://korupt.co.uk/?p=135&#038;cpage=1#comment-1279</link>
		<dc:creator>psifertex</dc:creator>
		<pubDate>Tue, 25 Aug 2009 23:23:17 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=135#comment-1279</guid>
		<description>Matang_Lawin: Depends on what role you&#039;d like to take.  I&#039;ve got a lot of suggestions in the talk.

The updated slides are online on the Defcon site but also here:  http://capture.thefl.ag/2009/DefconPresentation/

As soon as I can dig up audio or video I&#039;ll put it online.  Unfortunately I forgot to record audio myself.  :-(</description>
		<content:encoded><![CDATA[<p>Matang_Lawin: Depends on what role you&#8217;d like to take.  I&#8217;ve got a lot of suggestions in the talk.</p>
<p>The updated slides are online on the Defcon site but also here:  <a href="http://capture.thefl.ag/2009/DefconPresentation/" rel="nofollow">http://capture.thefl.ag/2009/DefconPresentation/</a></p>
<p>As soon as I can dig up audio or video I&#8217;ll put it online.  Unfortunately I forgot to record audio myself.  <img src='http://korupt.co.uk/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Revised PE infecter source by KOrUPt</title>
		<link>http://korupt.co.uk/?p=112&#038;cpage=1#comment-1138</link>
		<dc:creator>KOrUPt</dc:creator>
		<pubDate>Sat, 15 Aug 2009 17:07:50 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=112#comment-1138</guid>
		<description>Gary, what kind of further information are you looking for? Please be specific. Thanks in advance.

Now, C++Noob...

Take note of the call to UnloadFile() and the following LoadFile() call just after, the file is first unloaded an then re-mapped into memory in the expanded form... 

lpMapInfo = LoadFile(target, dwStubSize);

This line appends dwStubSize bytes to the file and maps it into memory.

dwWriteOffset = (GetFileSize(lpMapInfo-&gt;hFile, NULL)) - dwStubSize;

This line acquires the length of the file including the newly appended null bytes and subtracts the size of the stub in bytes to make sure there&#039;s enough room to place the stub into the file.

I hope this helps to clarify the issue, if not, please let me know.

Apologies for late approval of comments.

KOrUPt.</description>
		<content:encoded><![CDATA[<p>Gary, what kind of further information are you looking for? Please be specific. Thanks in advance.</p>
<p>Now, C++Noob&#8230;</p>
<p>Take note of the call to UnloadFile() and the following LoadFile() call just after, the file is first unloaded an then re-mapped into memory in the expanded form&#8230; </p>
<p>lpMapInfo = LoadFile(target, dwStubSize);</p>
<p>This line appends dwStubSize bytes to the file and maps it into memory.</p>
<p>dwWriteOffset = (GetFileSize(lpMapInfo->hFile, NULL)) &#8211; dwStubSize;</p>
<p>This line acquires the length of the file including the newly appended null bytes and subtracts the size of the stub in bytes to make sure there&#8217;s enough room to place the stub into the file.</p>
<p>I hope this helps to clarify the issue, if not, please let me know.</p>
<p>Apologies for late approval of comments.</p>
<p>KOrUPt.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Revised PE infecter source by C++Noob</title>
		<link>http://korupt.co.uk/?p=112&#038;cpage=1#comment-1135</link>
		<dc:creator>C++Noob</dc:creator>
		<pubDate>Sat, 15 Aug 2009 07:55:55 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=112#comment-1135</guid>
		<description>Hey Korupt, I was examining the source and im a little confused on something... InfectionHelper.cpp line 168: Wouldnt using GetFileSize on the handle from CreateFile return the original size of the file? therefore, writing to GetFileSize - dwStubSize would be overwriting part of the original PE file wouldnt it?</description>
		<content:encoded><![CDATA[<p>Hey Korupt, I was examining the source and im a little confused on something&#8230; InfectionHelper.cpp line 168: Wouldnt using GetFileSize on the handle from CreateFile return the original size of the file? therefore, writing to GetFileSize &#8211; dwStubSize would be overwriting part of the original PE file wouldnt it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Favourite Wargame Level&#8230; by dong</title>
		<link>http://korupt.co.uk/?p=65&#038;cpage=1#comment-1066</link>
		<dc:creator>dong</dc:creator>
		<pubDate>Mon, 10 Aug 2009 06:28:26 +0000</pubDate>
		<guid isPermaLink="false">http://korupt.co.uk/?p=65#comment-1066</guid>
		<description>likewise, any pointers or just tough luck?</description>
		<content:encoded><![CDATA[<p>likewise, any pointers or just tough luck?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
