<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-14788166.post4954367391157707325..comments</id><updated>2010-11-18T09:21:23.303+01:00</updated><category term='visualization'/><category term='astronomy'/><category term='tools'/><category term='linguistics'/><category term='vacation'/><category term='idapython'/><category term='pefile'/><category term='security'/><category term='basic blocks'/><category term='programming'/><category term='reverse engineering'/><category term='astrophysics'/><category term='analysis recipes'/><category term='ida2sql'/><category term='travel'/><category term='economics'/><category term='pythonika'/><category term='python'/><category term='BinNavi'/><category term='mathematics'/><category term='code opimization'/><category term='pydot'/><category term='training'/><category term='science'/><category term='bindiff'/><category term='humor'/><title type='text'>Comments on Ero Carrera's blog: Tiny (and crazy) PE</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.dkbza.org/feeds/4954367391157707325/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html'/><author><name>Ero Carrera</name><uri>http://www.blogger.com/profile/12212132879580765574</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_Ppb6-5N0H80/SWTe3dGAmRI/AAAAAAAAClE/wbE8E0WDTOg/S220/bangkok.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-14788166.post-6180499287998178333</id><published>2007-03-19T13:09:00.000+01:00</published><updated>2007-03-19T13:09:00.000+01:00</updated><title type='text'>I use the fantastic &lt;a href="http://www.omnigroup....</title><content type='html'>I use the fantastic &lt;A HREF="http://www.omnigroup.com/applications/omnigraffle/" REL="nofollow"&gt;OmniGraffle&lt;/A&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/6180499287998178333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/6180499287998178333'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html?showComment=1174306140000#c6180499287998178333' title=''/><author><name>Ero Carrera</name><uri>http://www.blogger.com/profile/12212132879580765574</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://dkbza.org/data/gc.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html' ref='tag:blogger.com,1999:blog-14788166.post-4954367391157707325' source='http://www.blogger.com/feeds/14788166/posts/default/4954367391157707325' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-189873416'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-3467799770698847095</id><published>2007-03-19T10:04:00.000+01:00</published><updated>2007-03-19T10:04:00.000+01:00</updated><title type='text'>I'm really amazed by your pictures. Could you tell...</title><content type='html'>I'm really amazed by your pictures. Could you tell what tool are you using to do it ?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/3467799770698847095'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/3467799770698847095'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html?showComment=1174295040000#c3467799770698847095' title=''/><author><name>Emmanuel</name><uri>http://www.labri.fr/perso/fleury/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html' ref='tag:blogger.com,1999:blog-14788166.post-4954367391157707325' source='http://www.blogger.com/feeds/14788166/posts/default/4954367391157707325' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-422821747'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-995784618831660303</id><published>2007-03-14T23:59:00.000+01:00</published><updated>2007-03-14T23:59:00.000+01:00</updated><title type='text'>I think it's more robustness than "messiness". At ...</title><content type='html'>I think it's more robustness than "messiness". At least it does seem to handle well really broken files where other tools just break.&lt;BR/&gt;&lt;BR/&gt;I haven't reversed engineered the Windows loader myself so I don't have a fully informed opinion. It's just intuition.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/995784618831660303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/995784618831660303'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html?showComment=1173913140000#c995784618831660303' title=''/><author><name>Ero Carrera</name><uri>http://www.blogger.com/profile/12212132879580765574</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://dkbza.org/data/gc.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html' ref='tag:blogger.com,1999:blog-14788166.post-4954367391157707325' source='http://www.blogger.com/feeds/14788166/posts/default/4954367391157707325' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-189873416'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-9004105870333246601</id><published>2007-03-14T23:36:00.000+01:00</published><updated>2007-03-14T23:36:00.000+01:00</updated><title type='text'>Doesn't the "robustness" of the WIndows PE loader ...</title><content type='html'>Doesn't the "robustness" of the WIndows PE loader end up meaning "it's full of complicated code"?&lt;BR/&gt;&lt;BR/&gt;Won't this "robustness" lead to some weird-beard kernel attacks via combinations of field header offsets and stuff?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/9004105870333246601'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/9004105870333246601'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html?showComment=1173911760000#c9004105870333246601' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html' ref='tag:blogger.com,1999:blog-14788166.post-4954367391157707325' source='http://www.blogger.com/feeds/14788166/posts/default/4954367391157707325' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1924194500'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-3620720837435950480</id><published>2007-03-14T08:15:00.000+01:00</published><updated>2007-03-14T08:15:00.000+01:00</updated><title type='text'>Well done job,&lt;br&gt;I think another good idea would ...</title><content type='html'>Well done job,&lt;BR/&gt;I think another good idea would be to use an Hex editor that lets you color different fields and setup a legend for each color and its meaning...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/3620720837435950480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/4954367391157707325/comments/default/3620720837435950480'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html?showComment=1173856500000#c3620720837435950480' title=''/><author><name>arkon</name><uri>http://ragestorm.net</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/tiny-and-crazy-pe.html' ref='tag:blogger.com,1999:blog-14788166.post-4954367391157707325' source='http://www.blogger.com/feeds/14788166/posts/default/4954367391157707325' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-979868157'/></entry></feed>
