HNHacker News
TopNewBestAskShowJobs

nicolodev

375 karma · joined February 17, 2021

https://nicolo.dev Email: seekbytes@protonmail.com
submissionscomments
nicolodev··on Stay discoverable in search while disallowing AI training
there have been a few links here on hn about content protection based on Markov’s chain. It might be interesting for Cloudflare to add damage for the scraper that tries to query the page, and not just blocking them.
nicolodev··on Show HN: I made a calculator that works over disjoint sets of intervals
It’s astonishing how nobody hasn’t mentioned abstract interpretation yet. Under classical static analysis, if you can “prove” that a variable does not have values in some unsound zones, you can e.g. “prove” soundness or apply further optimizations.

The interval abstract domain works under interval analysis with an algebra that’s the same of this calculator. It’s funny to implement something like that on source/binary level :)

nicolodev··on Disassembling a binary: linear sweep and recursive traversal
Hi! OP here, thanks for submitting it to hacker news, if anyone have any questions, feel free to write here!
nicolodev··on Capstone Disassembler Framework
Another good replacement for capstone/keystone based on LLVM is nyxstone https://github.com/emproof-com/nyxstone
nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
yeah I agree, and while everyone is suggesting tools which are really good but I designed mine to get rid of the flags and CLI interface. Good for tech people that keeps remembering flags, I'm not :(
nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
> mutool clean -d in.pdf out. pdf

My tool can do exactly the same (viewing internal structure, exporting objects, and see the uncompressed raw content for stream) with a graphical interface and without all this kind of flags (which one of the reasons I started to design this project with egui), but thanks for posting yours too.

nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
Thanks! Immediate paradigm might be a little bit scary if you used to play with Qt, but looks easy to manage and it's really interactive
nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
argh, that's too bad, feel free to open an issue, what's happening in the console? It's panicking, isn't it? Feel free to contact me via email if you prefer
nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
Nice! My tool should be runnable in the browser thanks to wasm compatibility with Rust + egui :) Btw I've just tried it, and it's a little bit buggy in Safari with a 504kb PDF (lots of objects though). Apart from that, is there a way to export the raw stream? Is there any reason of do you print all the raw streams as a text?
nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
:D Well, I'm sure that half of reverse engineering community needs to thank you, and Zynamics for the important contribution for tools of static analysis. I just take the occasion to thank you for being an inspiration with such awesome tools like in BinNavi, BinDiff, and ultimately PDF dissector. When I was reading that it got discontinued, I just had that idea and started to reason about something focused on analysis, and applying some approaches we've already seen for the binary analysis tools.
nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
Thanks for the list, the idea behind my tool was to try to code something that might fit an analyst that would take a fast look at the PDF. I'm also trying to figure out some fast heuristics to mark/highlight some peculiar stuff on the file itself.

Now regarding the tools you mentioned, I haven't checked out all of them, but part of them are interesting (and more mature, speaking of testing and compatibility). However some (at least the ones I was trying) are very basic, and they don't allow the "Save object as.." or uncompress it. I like the feature of displaying the PDF for preview :)

nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
I'd suggest you to code something along popular libraries for PDF manipulation. I've used pdf-rs for the tool.
nicolodev··on Show HN: IPA, a GUI for exploring inner details of PDFs
Thanks, it seems a great product too :) Do you have any particular feature that you share that product for?
nicolodev··on Hacking with PDF (2022)
I’m writing a little tool for analysing a pdf and its internals, if author is interested or anyone else, just let me know :)
nicolodev··on Microfeatures I love in blogs and personal websites
Neat, although some of them are actually helpful for specific articles. One thing that I actually seen as a pattern is over engineering the blog so much that features need maintenance.
nicolodev··on Show HN: MicroSCOPE – identify ransomware statically with heuristics
Hi! I just wanted to post this project into HN and collect some feedbacks. Don't feel bad to just say "lol your approach won't work" because static analysis has always limits (e.g. obfuscated software) and many more.

The main goal was to build (another) software that given a PE executable in input, parse it and outputs some indicators of the similarity of it across the ransomware I studied (the classic ones). Naturally most of the advanced ransomware employed nowadays is able to circumvent it, only with a little bit of modifications. TL;DR: "a more advanced" pattern matching.

The description is here as follows:

MicroSCOPE is a software program developed through the Go programming language that allows for the detection of a precise category of malicious software. The program is designed specifically for a class of malicious programs called ransomware whose operation consists of data encryption and ransom demand in order to gain access to the content again.

In particular, MicroSCOPE was developed to be able to support two of the mainly used formats: the PE (Portable Executable) format for Windows platforms and ELF (Executable and Linking Format) for Unix-based platforms. Through the application of certain heuristics, MicroSCOPE is able to assign a score that corresponds to the level of dangerousness of the file being analyzed. The higher the score, the more similar characteristics the software will exhibit to ransomware that has already been studied. The heuristics have been extrapolated from numerous case studies and will be improved over time.

nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Ghidra was somehow usable, I got several crashes with Hopper. One question for more expert people than me: does Hopper employ any telemetry inside its demo version? Some issues I discovered were fixed in two days and I did not report them.
nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Ops! Forgot to write about it (otherwise it would be so long). I did not mention the tools, but I was mainly referring to Hopper Decompiler/Disassembler (definitely no no for me). Altough it seemed the natural choice for reverse engineering macOS applications and daemons, it failed disastrousely on reverse engineering fairplayd. This is where obfuscation is really good at: feeling pain. Hopper tried to disassemblate the binary but still no luck (there was an error due to some bogus instructions referred by a dead branch). I'm seeing improvements for Hopper release by release, but there were some regressions that I noticed..

I tried to import it into Ghidra and it missed some informations during the pass of stack analysis. At the end it was a mess result to read, so I ended it up with IDA (free because I'm a student). Binary ninja also needs some license, I'm trying to afford it.

nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Thanks a lot!!! I can't believe I meet you on HN, great work so far
nicolodev··on Analysis of obfuscations found in Apple FairPlay
Sorry! My fault
nicolodev··on Analysis of obfuscations found in Apple FairPlay
Okay; this was originally sent by me yesterday. Not sure why it shows 1 hour ago.

I have this URL in my browser history of yesterday. Probably I'm hit by the second chance pool.

nicolodev··on Analysis of obfuscations found in Apple FairPlay
Not sure about what happened here.
nicolodev··on Analysis of obfuscations found in Apple FairPlay
1 hour ago? Why should I send again the URL?

I'm sure I did not send anything, that's very weird. @mod what happened here? Also how can I possibly send the same article if HN checks if any other articles has the exact same url?

nicolodev··on Starlink's User Terminal Firmware
> Tim Ferrell, from SpaceX's security team, for sending us a testing dish with root access.

They probably had a NDA or something that prohibits them to release the firmware publicy.

nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Thank you so much! This comment made my day :) The concept about story-telling was to explain in detail how I thought. Despite that, I do agree with some previous comments, some parts are too much.
nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Exactly!
nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Thanks for the detailed explanation.

> The software and hardware stack does itself need to be secure of course

Oh this is what I'm missing. It's a huge assumption that I wish that can be true!

nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Nice points! Thank you, I'll dig into ARM RME because it seems pretty interesting
nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Thanks for your comment. This obfuscation scheme is used only to complicate any attempt to reverse engineering (disassembling, decompilation) of the two processes involved in FairPlay DRM (I'm mainly talking about CoreFP and Fairplayd). Attackers need to spend more time on retrieving the original business logic. For sure, it's not the most hyper-defense technology Apple has employed (think about Secure Enclave).

> a properly implemented remote attestation and security architecture does obsolete it [obfuscation]

I'm not sure I've understood this part. So, if Apple implements remote attestation, would it be more difficult for attackers to reverse engineering the application? I am probably missing a point, would you mind if I ask you to expand that?

nicolodev··on Analysis of Obfuscation Techniques Found in Apple FairPlay
Thanks for the feedback again. I did really appreciate it. Oh the website you mentioned seems interesting, especially for a person that does not speak English daily. I'll keep in mind, and of course I bookmarked it.
Page 1 of 2Next →