<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>port knocking on Reverse Engineering</title>
    <link>https://reverse.put.as/tags/port-knocking/</link>
    <description>Recent content in port knocking on Reverse Engineering</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <managingEditor>reverser@put.as (fG!)</managingEditor>
    <webMaster>reverser@put.as (fG!)</webMaster>
    <copyright>&amp;copy; 2025 fG!</copyright>
    <lastBuildDate>Fri, 17 Dec 2021 14:20:59 +0000</lastBuildDate><atom:link href="https://reverse.put.as/tags/port-knocking/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Knock Knock! Who&#39;s There? - An NSA VM</title>
      <link>https://reverse.put.as/2021/12/17/knock-knock-whos-there/</link>
      <pubDate>Fri, 17 Dec 2021 14:20:59 +0000</pubDate>
      <author>reverser@put.as (fG!)</author>
      <guid>https://reverse.put.as/2021/12/17/knock-knock-whos-there/</guid>
      <description>&lt;p&gt;Back in 2017 (feels like ages ago) I decided to take a peek into the ShadowBrokers leaks and reverse some of the tools.&lt;/p&gt;
&lt;p&gt;I started on &lt;code&gt;dewdrop&lt;/code&gt; simply because it had a macOS version. I made local presentations at &lt;a href=&#34;https://www.meetup.com/0xOPOSEC/&#34;&gt;0xOpoSec&lt;/a&gt; and &lt;a href=&#34;https://www.bsideslisbon.org&#34;&gt;BSidesLisbon&lt;/a&gt; but those slides were never published for obvious reasons (aka live implants all over the Internet).&lt;/p&gt;
&lt;p&gt;Significant time has passed and everyone went crazy last week with the beautiful &lt;a href=&#34;https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html&#34;&gt;NSO exploit VM&lt;/a&gt; published by Project Zero, so why not ride the wave and present a simple NSA BPF VM. It is still an interesting work and you have to admire the great engineering that goes behind this code. It&amp;rsquo;s not everyday that you can take a peek at code developed by a well funded state actor.&lt;/p&gt;
&lt;p&gt;This post is only going to focus on the BPF part of the implant so you will have to fill in the blanks about everything else.&lt;/p&gt;</description>
    </item>
    
  </channel>
</rss>
