Reverse – reverse engineering tool with pseudo-C output
github.com
github.com
If only.
The easiest way to throw such a scheme off is to have an instruction jump into the middle of an operand and have the code be dual meaning, one reading gives you one disassembly, another a completely different one.
If you then try to convert the result to a pseudo-C construct (a function with a stackframe and the corresponding unwinding of that stackframe at the end of the fuction) then it no longer works...
The short version of the above is there is a 1:1 correspondence between a C language source code and the un-optimized output of a compiler. That coupling is a lot less hard when you start optimizing and when you use hand-crafted assembly as the input to a reverse-compiler the output may simply no longer be functionally equivalent because the mapping might be non-existent and this can be a hard situation to detect.
FWIW, jumping into the middle of an instuction is not actually a problem (even though I do realize it trips up a number of disassemblers: I actually publishef a proof-of-concept obfuscating assembler that was designed to specifically break all the best disassemblers at the time, and leaned heavily on that), as you just need to build your own graph of the execution of the program: don't try to mark regions of memory, as that will screw you.
What really gets you quickly are computed jumps: even super popular disassemblers often hiccup on simple switch tables, as there is no way to really know for sure all the cases that were proven to be impossible by the compiler and left out of the checks. And one could imagine a case where a jump is computer based on the output of a potentially undesirable function... you essentially need to be able to prove things about programs to even ask the question, and those proofs almost always fail due to incompleteness :(.
Decompilation for C is a very hard problem. Conceptually super easy but extremly hard if not impossible to implement. The java folks have it so much easier in this respect.
https://www.hex-rays.com/products/decompiler/compare_vs_disa...
It requires compiler generated code as input (which I don't find a huge restriction, but any assembly code will screw up the output).
computer based -> computed based undesirable -> uncomputable publishef -> published
I have a rule when I write reports: don't send it on the same day. Let it sit for a day and then re-read it, from paper if possible. That's when I spot the typos and the weird sentences. If I proofread right away I just read what I think it should say rather than what it really says. Frustrating!
???