corCTF 2021 vmquack writeup: Writing a Custom Binary Ninja Architecture Plugin to Devirtualize a Crackme
ID: d64191ff-37af-5c2a-abab-76de6d1e0d9b
STIX ID: report--d64191ff-37af-5c2a-abab-76de6d1e0d9b
Feed Name: Will's Root
This is a CTF challenge write-up for 'vmquack' (corCTF 2021) describing a custom x86_64-like CISC virtual machine implemented in assembly, its anti-debugging and virtualization techniques, the VM instruction set and operand encoding, a Binary Ninja plugin created to disassemble and lift the VM code, and the analysis steps used to derive the correct input that produces the flag.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
