I did all of my hacking on a Windows machine but now I use OSX almost exclusively. Does anyone know of roughly equivalent tools in this world? Maybe I'll take up the hobby again.
I did all of my hacking on a Windows machine but now I use OSX almost exclusively. Does anyone know of roughly equivalent tools in this world? Maybe I'll take up the hobby again.
I remember one of the tricks used by apps was to encrypt the code in some way, and rely on the DOS single-step interrupt to execute the decryption process as the code was run, one instruction at a time. The idea was to prevent static disassembly with the encryption while also discouraging run-time analysis (since a debugger would usually overwrite the single-step interrupt that fired off the decrypter).
I actually ended up writing my own TSR debugger that could step through such code by chaining the interrupts. It could also detect many of the self extracting compression formats and jump past the decompression stage on startup so you didn't spend the first 10 minutes trying to step through decompression code. I was quite proud of that app.
Then in the late 90s I moved on to Windows disassembly, when I became somewhat obsessed with uncovering the undocumented APIs in Windows 95. I even had a Geocities website where I used to publish some of my findings. The site is obviously gone now, but it's still mirrored in a few places.
In case anyone is interested, there's a mirror here: http://koti.mbnet.fi/vaultec/files/miscellaneous/undocw95/
I do agree that for a tool used for a hobby it is expensive, but for hobbyists there are other, simpler tools that could be used.
[1] https://www.hex-rays.com/products/ida/support/download_freew...