Some decompiling, reverse engineering, and keygen tutorials
tuts4you.com
tuts4you.com
But after switching to a fully opensource stack, reverse engineering lost its charm. Understanding how things work is taken for granted and I can't imagine going back to an opaque proprietary environment.
Fravia passed away on 2009; but his archives are preserved here: http://71.6.196.237/fravia/index.htm
Fravia+'s last project - "Web Searchlores" was/is more aimed towards general reverse engineering and information searching. The site contains a huge collection of information, which curiously, although not updated for so many years, is still relevant today.pparently searchlores.org and fravia.com have expired and are "parked" by sombody. But looks like http://search.lores.eu/ is the only remaining official mirror that remains from
What you say about the F/OSS certainly rings true, but at least for me, software reverse engineering has always been more as a training ground for reversing in general than to cracking software copy protections.
+greythorne has stopped updating his pages and +HCU's Linux infor, but mammon_ is pretty active, and even moved to Github: http://mammon.github.io/ . Definitely worth checking out for more information about Software RE under GNU/Linux.
Nowadays there are a lot of opaque software in widespread use, so the main focus has shifted towards web platforms, where reversing is still applicable.
edit: style
Fravia died a few years ago: http://en.wikipedia.org/wiki/Fravia
For people interested in reversing I recommend to engage on the new http://reverseengineering.stackexchange.com/ and the "classic" http://www.reddit.com/r/ReverseEngineering/
One issue with reverse engineering information/community is the lack of organization. There are a lot of web resources about it but are not well interlinked (yes, the <a> tag). So, it is possible that a great tool is hidden in a page with low page rank. OpenRCE was successful in the past but nowadays people don't use it.
Yes, but 4 years are a considerable time on the web. Linkrot to and in some of the external resources can be felt.
I also remember many wonderful tools like PEiD (locating and identifying hash functions), hiew (hexeditor), RSATool (RSA cracking tool), FSG (file compressor). There was also OllyDbg and it seems that it's still actively developed.
Ah, memories.
I once created an "uncrackable" crackme (in Visual Basic 4, no less!) that had a part of its code encrypted with RC4, and the license key was the decryption ley.
Has anyone ever figured out who +orc was/is? That was one of the fun riddles of the day :)
Fun times. I remember the two best cracks I read about: One was to add functionality to binary software (the tut was to add something to Notepad). This was used to 'crack' w32dasm and add some other stuff (there were really cool w32dasm versions circulating).
The other was (and it is funny that is still quite relevant e.g. SimCity) to emulate a validation server (I think it was Flex validation) in localhost to register software that called home.
My personal best was to do keygens. For that, you really needed to understand the asm program routine which validated the username/pass.
I did all of my hacking on a Windows machine but now I use OSX almost exclusively. Does anyone know of roughly equivalent tools in this world? Maybe I'll take up the hobby again.
I do agree that for a tool used for a hobby it is expensive, but for hobbyists there are other, simpler tools that could be used.
[1] https://www.hex-rays.com/products/ida/support/download_freew...
I remember one of the tricks used by apps was to encrypt the code in some way, and rely on the DOS single-step interrupt to execute the decryption process as the code was run, one instruction at a time. The idea was to prevent static disassembly with the encryption while also discouraging run-time analysis (since a debugger would usually overwrite the single-step interrupt that fired off the decrypter).
I actually ended up writing my own TSR debugger that could step through such code by chaining the interrupts. It could also detect many of the self extracting compression formats and jump past the decompression stage on startup so you didn't spend the first 10 minutes trying to step through decompression code. I was quite proud of that app.
Then in the late 90s I moved on to Windows disassembly, when I became somewhat obsessed with uncovering the undocumented APIs in Windows 95. I even had a Geocities website where I used to publish some of my findings. The site is obviously gone now, but it's still mirrored in a few places.
In case anyone is interested, there's a mirror here: http://koti.mbnet.fi/vaultec/files/miscellaneous/undocw95/
I used to do reverse engineering when I was a teenager, just for the fun. It made me feel powerful in a certain way. RE is a great mind puzzler! It builds lots of skills: I learnt a lot of ASM, how OSes worked on the inside, compilers, problem solving...
Is it as safe as it looks?
However, I'm not prepared to make any statements about how safe it actually is. I don't have quite deep enough security expertise to know that.
In several countries, this is one of the expressly granted rights with respect to reverse engineering since it promotes interoperability and (more often than not) allows one to use a file format (or network service) long after the original software has expired [in the mortality sense].
I also highly recommend checking out the new http://reverseengineering.stackexchange.com/ since it is currently in its beta period and needs all the content it can get.
What to Submit
On-Topic: Anything that good hackers would find interesting. That includes more than hacking and startups.
If you had to reduce it to a sentence, the answer might be: anything that gratifies one's intellectual curiosity.
From: http://ycombinator.com/newsguidelines.html