KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I'm working on an x86 asm obfuscator that takes Intel-syntax code as a string and outputs an equivilent set of opcodes that are obfuscated. Here's an example: mov eax, 0x5523 or eax, [ebx] push eax call someAPI Becomes something like: mov eax, 0xFFFFFFFF ; mov eax, 0x5523 and eax, 0x5523 ; push [ebx] ; xor eax, [ebx] or [esp], eax ; pop eax ; push 12345h ; push eax mov [esp], eax ; call getEIP ; call someAPI getEIP: ; add [esp], 9 ; jmp someAPI ; This is just an example, I've not checked that this doesn't screw up flags (it probably does). Right now I have an XML document that lists instruction templates (e.g. push e*x ) and a list of replacement instructions that can be used. What I'm looking for is a way to automatically generate opcode sequences that produce the same result as an input. I don't mind doing an educated bruteforce, but I'm not sure how I'd approach this.
Tags (comma-separated)
Save Edits
Cancel