Analysis of the Comodo hacker's manifesto
erratasec.blogspot.com
erratasec.blogspot.com
> that humans can no longer read the resulting binary "object"
> code. That is in incorrect. Code can easily be decompiled
> back to (nearly) the original source. In our (Errata
> Security) pentests, we regularly find embedded usernames and
> passwords that nobody believe hackers can read. It usually
> takes us less than 5 minutes.
Really now? When you are talking about .NET assemblies this is close to true (in some cases). Not so much for C. So much for a "high-end cyber security consulting company".
I'm also always willing to help people out here -- if anyone is interested in reversing, feel free to email me.
Anyone can read assembler.
I sure hope the original source code does not resemble this.
I didn't look carefully, but the screenshot in Rob's post didn't look like C/C++ code; I thought it might have been ActionScript.
That was my point. No sane person looks at the output of hex-rays and thinks they have received the original source code (minus comments and variable names). It is rare for me to find it even more readable than the assembly listing/graph view.
This is some of their past research. http://www.erratasec.com/research.html
Really.