<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-14788166.post6759082786781427384..comments</id><updated>2010-03-09T10:33:05.691+01:00</updated><title type='text'>Comments on nzight: A PE trick, the Thread Local Storage</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.dkbza.org/feeds/6759082786781427384/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html'/><author><name>Ero Carrera</name><uri>http://www.blogger.com/profile/12212132879580765574</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-14788166.post-3206199810830702097</id><published>2007-11-19T21:42:00.000+01:00</published><updated>2007-11-19T21:42:00.000+01:00</updated><title type='text'>Thanks for sharing this information. I was searchi...</title><content type='html'>Thanks for sharing this information. I was searching for the explanation of this behavior for 2 days. I thought that my program had the bug.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/3206199810830702097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/3206199810830702097'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html?showComment=1195504920000#c3206199810830702097' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html' ref='tag:blogger.com,1999:blog-14788166.post-6759082786781427384' source='http://www.blogger.com/feeds/14788166/posts/default/6759082786781427384' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-9141826854532033126</id><published>2007-05-24T13:40:55.240+02:00</published><updated>2007-05-24T13:40:55.240+02:00</updated><title type='text'>Thanks for the info. I didn't know that the window...</title><content type='html'>Thanks for the info. I didn't know that the windows loader was so forgiving in that case.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/9141826854532033126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/9141826854532033126'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html?showComment=1180006855240#c9141826854532033126' title=''/><author><name>Ero Carrera</name><uri>http://www.blogger.com/profile/12212132879580765574</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02474828569054846513'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html' ref='tag:blogger.com,1999:blog-14788166.post-6759082786781427384' source='http://www.blogger.com/feeds/14788166/posts/default/6759082786781427384' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-789870189569852403</id><published>2007-05-24T13:30:00.000+02:00</published><updated>2007-05-24T13:30:00.000+02:00</updated><title type='text'>Also, FYI, the Windows loader (which IMHO is as br...</title><content type='html'>Also, FYI, the Windows loader (which IMHO is as brainded as it can be and tries to load anything that even looks like PE without performing validation - probably in the name of "backwards compatibility") executes TLS even if in the Data Directory the size is specified as zero, but IDA doesn't show it in this case (of course you can always patch it with a hex editor  ;-)).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/789870189569852403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/789870189569852403'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html?showComment=1180006200000#c789870189569852403' title=''/><author><name>cdman83</name><uri>http://www.blogger.com/profile/05030326541176171725</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html' ref='tag:blogger.com,1999:blog-14788166.post-6759082786781427384' source='http://www.blogger.com/feeds/14788166/posts/default/6759082786781427384' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-5961669651463273261</id><published>2007-05-21T07:59:00.000+02:00</published><updated>2007-05-21T07:59:00.000+02:00</updated><title type='text'>http://www.amazon.com/Computer-Virus-Research-Defe...</title><content type='html'>http://www.amazon.com/Computer-Virus-Research-Defense-Symantec/dp/0321304543/ref=sr_1_1/002-1556081-5220863?ie=UTF8&amp;s=books&amp;qid=1179727152&amp;sr=8-1&lt;BR/&gt;&lt;BR/&gt;using TLS as entry point. just a quick mention - not sure if it is worth to buy the book just to read about it :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/5961669651463273261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/5961669651463273261'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html?showComment=1179727140000#c5961669651463273261' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html' ref='tag:blogger.com,1999:blog-14788166.post-6759082786781427384' source='http://www.blogger.com/feeds/14788166/posts/default/6759082786781427384' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-7309955233788484638</id><published>2007-05-02T18:53:00.000+02:00</published><updated>2007-05-02T18:53:00.000+02:00</updated><title type='text'>I don't know if you have read this but here's an i...</title><content type='html'>I don't know if you have read this but here's an interesting article discussing the Shrug aka Chifton Virus &lt;A HREF="http://pferrie.tripod.com/papers/chiton.pdf" REL="nofollow"&gt;LINK&lt;/A&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/7309955233788484638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/7309955233788484638'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html?showComment=1178124780000#c7309955233788484638' title=''/><author><name>Alex</name><uri>http://ihatealex.org/WordPress/</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html' ref='tag:blogger.com,1999:blog-14788166.post-6759082786781427384' source='http://www.blogger.com/feeds/14788166/posts/default/6759082786781427384' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-7787474336047985845</id><published>2007-04-01T23:33:08.095+02:00</published><updated>2007-04-01T23:33:08.095+02:00</updated><title type='text'>According to Symantec the virus W32.Shrug was the ...</title><content type='html'>&lt;A HREF="http://www.symantec.com/security_response/writeup.jsp?docid=2002-031314-2134-99&amp;tabid=2" REL="nofollow"&gt;According to Symantec&lt;/A&gt; the virus W32.Shrug was the first know to use TLS</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/7787474336047985845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/7787474336047985845'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html?showComment=1175463188095#c7787474336047985845' title=''/><author><name>Ero Carrera</name><uri>http://www.blogger.com/profile/12212132879580765574</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02474828569054846513'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html' ref='tag:blogger.com,1999:blog-14788166.post-6759082786781427384' source='http://www.blogger.com/feeds/14788166/posts/default/6759082786781427384' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-4738406416417763107</id><published>2007-03-20T23:42:15.474+01:00</published><updated>2007-03-20T23:42:15.474+01:00</updated><title type='text'>Could you elaborate a bit more on that please?</title><content type='html'>Could you elaborate a bit more on that please?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/4738406416417763107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/4738406416417763107'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html?showComment=1174430535474#c4738406416417763107' title=''/><author><name>Ero Carrera</name><uri>http://www.blogger.com/profile/12212132879580765574</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02474828569054846513'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html' ref='tag:blogger.com,1999:blog-14788166.post-6759082786781427384' source='http://www.blogger.com/feeds/14788166/posts/default/6759082786781427384' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-14788166.post-3696590305996349648</id><published>2007-03-20T22:33:00.000+01:00</published><updated>2007-03-20T22:33:00.000+01:00</updated><title type='text'>FYI: virii use TLS' entry points too."comparing ex...</title><content type='html'>FYI: virii use TLS' entry points too.&lt;BR/&gt;&lt;BR/&gt;"comparing execution paths..." respect.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/3696590305996349648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14788166/6759082786781427384/comments/default/3696590305996349648'/><link rel='alternate' type='text/html' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html?showComment=1174426380000#c3696590305996349648' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dkbza.org/2007/03/pe-trick-thread-local-storage.html' ref='tag:blogger.com,1999:blog-14788166.post-6759082786781427384' source='http://www.blogger.com/feeds/14788166/posts/default/6759082786781427384' type='text/html'/></entry></feed>