1 of 63

Dissecting the Unknown

Introduction to Reverse Engineering

2 of 63

Who are we?

  • The University’s CTF team
  • A community for passionate hackers and curious people
  • Some of us work in the Cybersecurity industry

  • Aaaaand… 2nd place winners at UNbreakable 2024 Finals

2

https://dothidden.xyz

Instagram: @dothidden_

3 of 63

What will we cover?

  • Disclaimer
  • History of RE
  • High-Level Intro to RE
  • How does code execute?
  • Binary Formats
  • Static Analysis
  • Dynamic Analysis
  • Types of Targets

3

https://dothidden.xyz

Instagram: @dothidden_

4 of 63

Disclaimer

ANY FORM OF TAMPERING WITH PROPRIETARY PRODUCTS CAN LEAD TO LEGAL CONSEQUENCES. WE WILL NOT BE RESPONSIBLE FOR YOUR ACTIONS!

STAY SAFE AND WASH YOUR HANDS!

4

5 of 63

A few examples

6 of 63

Reverse Engineering Examples

  • Going from Ancient Greek to understanding the ancient language of Egypt �-> Hieroglyphic

6

7 of 63

Reverse Engineering Examples

  • The Russian Tu-4 is a copy of the American Boeing B-29
  • Reverse-engineered from aircraft which performed emergency landings in the USSR

7

8 of 63

Reverse Engineering Examples

  • The Launch of the IBM-compatible PC era
  • MPC 1600 -> the first clone of the IBM PC
  • Reverse engineering of the IBM BIOS firmware
  • Today’s computers are still largely based on the original IBM design

8

https://archive.org/stream/byte-magazine-1982-10/1982_10_BYTE_07-10_Computers_in_Business#page/n81/mode/2up

9 of 63

Reverse Engineering Examples

Other examples

  • The Enigma Machine
  • Genetics
  • Neurobiology
  • 3D printing
  • etc.

9

10 of 63

Reverse Engineering Examples

Software RE:

  • Wine
  • Libre Office
  • SAMBA
  • Cracks
  • Cheats / Anticheats
  • Malware Analysis
  • Vulnerability Research

10

11 of 63

Back to basics

12 of 63

How does a computer work?

  • The computer is a series of electronic components that manipulate current to perform calculations

12

13 of 63

How does a computer work?

13

14 of 63

How does a computer work?

14

15 of 63

How does a computer work?

15

16 of 63

How does code execute?

16

Input

Output

Central Processing Unit (CPU)

Registers

Arithmetic Logic Unit

Control Unit

Memory Unit

17 of 63

How does code execute?

17

Input

Output

“Hello!”

“Hi!”

18 of 63

How does code execute?

18

19 of 63

How does code execute?

19

20 of 63

How does code execute?

ARM

x64

RISC-V

20

21 of 63

How does code execute?

  • Base 10 (decimal)

21

  • Base 2 (binary):

1101 1110 1010 1101 � 1011 1110 1110 1111

compression � (more) human readable

  • Base 16 (hexa(decimal)):

0xDEADBEEF

22 of 63

How does code execute?

Machine code instructions (x64) that print “Hello, world!” to standard output

55 48 89 e5 48 8d 05 ac 0e 00 00 48 89 c7 e8 f0 fe ff ff b8 00 00 00 00 5d c3

22

23 of 63

How does code execute?

55

48 89 e5

48 8d 05 ac 0e 00 00

48 89 c7

e8 f0 fe ff ff

b8 00 00 00 00

5d

c3

23

24 of 63

How does code execute?

55

48 89 e5

48 8d 05 ac 0e 00 00

48 89 c7

e8 f0 fe ff ff

b8 00 00 00 00

5d

c3

Instructions in x64 assembly that print “Hello, world!” to the console

push rbp

mov rbp, rsp

lea rax, [rip+0xeac]

mov rdi, rax

call 1050 <puts@plt>

mov eax, 0x0

pop rbp

ret

24

25 of 63

How does code execute?

Instructions in C that print “Hello, world!” to the console

int main() {

puts(“Hello, world!”);

return 0;

}

push rbp

mov rbp, rsp

lea rax, [rip+0xeac]

mov rdi, rax

call 1050 <puts@plt>

mov eax, 0x0

pop rbp

ret

25

26 of 63

How does code execute?

int main() {

puts(“Hello, world!”);

return 0;

}

push rbp

mov rbp, rsp

lea rax, [rip+0xeac]

mov rdi, rax

call 1050 <puts@plt>

mov eax, 0x0

pop rbp

ret

55 48 89 e5 48 8d 05 ac 0e 00 00 48 89 c7 e8 f0 fe ff ff b8 00 00 00 00 5d c3

compile

assemble

run

Hello, world!

55 48 89 …

libc

link

26

1

2

3

4

5

27 of 63

How does code execute?

> There are multiple standardised� file formats for executable files

> The most popular are:

> Portable Executable (PE, Windows)

> Executable and Linkable Format (ELF, Linux)

27

28 of 63

How does code execute?

28

29 of 63

How does code execute?

29

30 of 63

Tools of the craft

31 of 63

Decompilation

> The reverse of compilation

> A lot of information from the source code is lost during the compilation process

> So decompilation will (almost) NEVER show us the ORIGINAL source code

55 48 89 e5 48 8d 05 ac 0e 00 00 48 89 c7 e8 f0 fe ff ff b8 00 00 00 00 5d c3

push rbp

mov rbp, rsp

lea rax, [rip+0xeac]

mov rdi, rax

call 1050 <puts@plt>

mov eax, 0x0

pop rbp

ret

int main() {

puts(“Hello, world!”);

return 0;

}

Disassembly

Decompilation

31

32 of 63

Decompilation

32

33 of 63

A look at Ghidra

Decompilation pane

Symbol tree

Assembly pane

33

34 of 63

A look at Ghidra

Decompilation pane

Symbol tree

Assembly pane

34

35 of 63

A look at Ghidra

Header

.bss

.data

.rodata

.text

> Header of the executable file

35

> Stores the executable machine code

> Stores global variables initialised to 0

> Stores mutable global variables

> Stores constants and immutable global data

36 of 63

A look at Ghidra

36

Alternative disassembly view which emphasises branching and higher level code flow

conditional branch

loop

37 of 63

Not all programs �are the same

38 of 63

Higher Level Languages

38

> Some languages do not (usually) compile to machine code

> Higher-level bytecode which can be fed into an interpreter or JIT

> The bytecode is usually available

public static void Main() {

Console.WriteLine(“hello world”);

}

Some kind of bytecode�

Java bytecode | DEX | CIL | MSIL

etc.

Runtime

JVM | CLR | ART

Compilation

Execution

39 of 63

Higher Level Languages

39

public static void Main() {

Console.WriteLine(“hello world”);

}

Some kind of bytecode�

Java bytecode | DEX | CIL | MSIL

etc.

Decompilation

> Bytecode can be reverse engineered

> a very common example?

40 of 63

Higher Level Languages

40

public static void Main() {

Console.WriteLine(“hello world”);

}

Some kind of bytecode�

Java bytecode | DEX | CIL | MSIL

etc.

Decompilation

> Bytecode can be reverse engineered

> a very common example?

> Android APKs

41 of 63

Android Packages (APKs)

41

https://medium.com/@banmarkovic/deep-insight-into-apk-1cd7f04a53f5

Glorified zip file

42 of 63

Android Packages (APKs)

42

43 of 63

A look at JADX

43

Decompiled Java code

SMALI

44 of 63

Preventing RE

45 of 63

Obfuscation

45

  • used by Vendors to protect proprietary information from competitors
  • used by malicious actors to evade protection mechanisms and avoid being caught
  • used in the IOCCC: https://www.ioccc.org/

https://www.ioccc.org/2020/endoh2/index.html

46 of 63

Obfuscation

46

.ps1

ELF

.js

47 of 63

Obfuscation

47

Deobfuscation

  • Some times, obfuscated code can be easily deobfuscated
  • Other times, not so easily
  • LLMs are decent at this job: https://ojs.aaai.org/index.php/AAAI/article/view/30517

48 of 63

Further analysis

49 of 63

Dynamic Analysis

49

  • Obfuscation can sometimes be very hard to reverse
  • We might be interested in details which are not available through static analysis
  • Behavior cannot always be inferred through static analysis

gdb

50 of 63

Case-by-Case

51 of 63

Malware analysis

51

  • Setting up a test lab, such as a VM with all the necessary tools
  • Analysing the permission requests, traffic generated, files accessed, and, persistence, spread, etc.
  • Diffing, analysing fingerprints
  • Analysing (encrypted) shellcode

52 of 63

Vulnerability Research

52

  • Attempting to find bugs and paths of exploitation
  • Fuzzing: automated way to provide unexpected input to a program in order to derive unintended behavior
  • Symbolic execution: analysis technique, based in Logic. Determines what inputs lead to each path of execution
  • Concolic execution: a combination of the latter two (smart fuzzing)

https://www.youtube.com/watch?v=QrtGOrSrVPQ

53 of 63

Dynamic Analysis - Tools

53

  • Debuggers:
  • Memory corruption detectors:
    • Valgrind: https://valgrind.org/
  • Fuzzers:
    • AFL++: https://aflplus.plus/
  • Symbolic execution engines

54 of 63

Other tools

  • There are other useful tools for program analysis:
    • strings: prints all sequences of bytes that can be decoded as ascii
    • plugins for gdb:
    • strace: prints syscalls made by the program
    • ltrace: prints library function calls made by the program

54

55 of 63

CHALLENGE !

55

  • Crack the binary
    • Download the binary and attempt to find the passphrase
    • Hint: It’s in ELF format, BUT using static analysis you can analyse it on any platform
    • We recommend trying it out with Ghidra

56 of 63

Follow us for more

56

Instagram: @dothidden_

Website: https://dothidden.xyz

57 of 63

Feedback

57

Short anonymous feedback form <3

58 of 63

Questions?

59 of 63

Thanks!

Survey time?

60 of 63

Annex

61 of 63

Annex A: Proces de boot

BIOS

Bootloader

Kernel

Apps

61

62 of 63

Annex B: Kernel

Kernel

> Kernel-ul este “sămânța” sau “nucleul” sistemului de operare

> Interacționează cu hardware-ul și gestionează memoria și procesele sistemului

> https://github.com/torvalds/linux

62

63 of 63

Back to Basics

63