<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Very small update&#8230;</title>
	<atom:link href="http://reverse.put.as/2010/06/08/very-small-update/feed/" rel="self" type="application/rss+xml" />
	<link>http://reverse.put.as/2010/06/08/very-small-update/</link>
	<description>Reverse Engineering for fun and pleasure!</description>
	<lastBuildDate>Sat, 04 Feb 2012 02:28:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: skuret</title>
		<link>http://reverse.put.as/2010/06/08/very-small-update/comment-page-1/#comment-7523</link>
		<dc:creator>skuret</dc:creator>
		<pubDate>Fri, 02 Jul 2010 10:11:10 +0000</pubDate>
		<guid isPermaLink="false">http://reverse.put.as/?p=652#comment-7523</guid>
		<description>thank you very much for the help. and also thanks for pointing out that svn trunk of otx has x64 support. (i guess i read it here somewhere)</description>
		<content:encoded><![CDATA[<p>thank you very much for the help. and also thanks for pointing out that svn trunk of otx has x64 support. (i guess i read it here somewhere)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fG!</title>
		<link>http://reverse.put.as/2010/06/08/very-small-update/comment-page-1/#comment-7308</link>
		<dc:creator>fG!</dc:creator>
		<pubDate>Fri, 25 Jun 2010 23:07:05 +0000</pubDate>
		<guid isPermaLink="false">http://reverse.put.as/?p=652#comment-7308</guid>
		<description>Macserialjunkies.</description>
		<content:encoded><![CDATA[<p>Macserialjunkies.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gunther</title>
		<link>http://reverse.put.as/2010/06/08/very-small-update/comment-page-1/#comment-7305</link>
		<dc:creator>Gunther</dc:creator>
		<pubDate>Fri, 25 Jun 2010 16:40:59 +0000</pubDate>
		<guid isPermaLink="false">http://reverse.put.as/?p=652#comment-7305</guid>
		<description>Hi fG!,

but may i know the website you got the crackmes from MSJ challenge?

Thanks in advance.

BR,
[ Gunther ]</description>
		<content:encoded><![CDATA[<p>Hi fG!,</p>
<p>but may i know the website you got the crackmes from MSJ challenge?</p>
<p>Thanks in advance.</p>
<p>BR,<br />
[ Gunther ]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fG!</title>
		<link>http://reverse.put.as/2010/06/08/very-small-update/comment-page-1/#comment-7155</link>
		<dc:creator>fG!</dc:creator>
		<pubDate>Mon, 21 Jun 2010 22:03:41 +0000</pubDate>
		<guid isPermaLink="false">http://reverse.put.as/?p=652#comment-7155</guid>
		<description>Check out http://vxheavens.com/lib/vsc04.html

It&#039;s the false breakpoint trick (int3). There is one int3 in the code but that one isn&#039;t breaking. I bet the binary has obfuscated code protecting that int3 that&#039;s confusing gdb. You will have to trace since the entrypoint and manually find where it is (yeah it&#039;s a pain in the ass but works all the time!).
I don&#039;t have the time at the moment to further analyse it! But it seems like an interesting time. First time I ever saw someone using this trick at OS X.
Have fun!</description>
		<content:encoded><![CDATA[<p>Check out <a href="http://vxheavens.com/lib/vsc04.html" rel="nofollow">http://vxheavens.com/lib/vsc04.html</a></p>
<p>It&#8217;s the false breakpoint trick (int3). There is one int3 in the code but that one isn&#8217;t breaking. I bet the binary has obfuscated code protecting that int3 that&#8217;s confusing gdb. You will have to trace since the entrypoint and manually find where it is (yeah it&#8217;s a pain in the ass but works all the time!).<br />
I don&#8217;t have the time at the moment to further analyse it! But it seems like an interesting time. First time I ever saw someone using this trick at OS X.<br />
Have fun!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fG!</title>
		<link>http://reverse.put.as/2010/06/08/very-small-update/comment-page-1/#comment-7154</link>
		<dc:creator>fG!</dc:creator>
		<pubDate>Mon, 21 Jun 2010 21:43:03 +0000</pubDate>
		<guid isPermaLink="false">http://reverse.put.as/?p=652#comment-7154</guid>
		<description>Hello,
Sorry for the late answer. I think 06 is the error for a anti-debug technique published by Apple. I cannot remember the name right now. I will have to find my notes to see what is it!
Let me see if I can find it. Not sure if it is into one of the removed tutorials.

fG!</description>
		<content:encoded><![CDATA[<p>Hello,<br />
Sorry for the late answer. I think 06 is the error for a anti-debug technique published by Apple. I cannot remember the name right now. I will have to find my notes to see what is it!<br />
Let me see if I can find it. Not sure if it is into one of the removed tutorials.</p>
<p>fG!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: skuret</title>
		<link>http://reverse.put.as/2010/06/08/very-small-update/comment-page-1/#comment-6797</link>
		<dc:creator>skuret</dc:creator>
		<pubDate>Wed, 16 Jun 2010 15:29:46 +0000</pubDate>
		<guid isPermaLink="false">http://reverse.put.as/?p=652#comment-6797</guid>
		<description>Hi! I could not find out anywhere else to ask you this so I am posting a comment. I am an intermediate reverser. I can write keygens for mac. But I cannot circumvent anti debugging techniques. Nowadays I am working on it. I was looking at Postbox 1.1.5 and i cannot even figure out what anti debugging technique is used. If you have time and see which technique is used i can start to work on it. I know it is a little too much to ask but i figured i should try my chances.

by the way in gdb, program exits with code 06.

thanks for this fantastic blog</description>
		<content:encoded><![CDATA[<p>Hi! I could not find out anywhere else to ask you this so I am posting a comment. I am an intermediate reverser. I can write keygens for mac. But I cannot circumvent anti debugging techniques. Nowadays I am working on it. I was looking at Postbox 1.1.5 and i cannot even figure out what anti debugging technique is used. If you have time and see which technique is used i can start to work on it. I know it is a little too much to ask but i figured i should try my chances.</p>
<p>by the way in gdb, program exits with code 06.</p>
<p>thanks for this fantastic blog</p>
]]></content:encoded>
	</item>
</channel>
</rss>

