My favorites | Sign in
Project Home Downloads Issues Source
Project Information
Members
Featured
Downloads
Wiki pages
Links

about Corkami

misc

PDF

Portable Executable

  • poster (2012/05/03-2012/12/05) PE 101 - a Windows executable walkthrough (an easy introduction)

  • PoC a fully working PE in a tweet (encoded in a python string): "MZR\xc3"+"\0"*56+"@\0\0\0PE\0\0L\1"+"\0"*16+"\2\0\x0b\1"+"\0"*28+"@\0\1\0\0\0\1\0"+"\0"*10+"\4"+"\0"*7+"H\1\0\0G\1"+"\0"*6+"\3"+"\0"*171
  • presentation first at Hack In Paris, then reworked and extended at hashdays, Luzern (Switzerland)
    1. (2012/06/22) a bit more of PE (+video)
    2. (2012/11/03) Binary Art - byte-ing the PE that fails you
  • article with PoCs (2011/09/26 - 2013/02/01) the PE format
  • source a rewrite of the PE header of Traceless demo
  • PoC (2012/08/01) CorkaMIX, an all-in-one PE/PDF/Html[+JavaScript]/(Jar[Class+Zip] ^ PY) file written by hand
  • PoCs (2011/02) Binary corpus is a group of non malicious binaries, exhibiting various file formats, and more specifically, aspects of PE files (Formats: NE, PE, Elf, LX, LE, COM, EXE / Compilers: Digital Mars C, Lcc, Masm, Tasm, FreeBasic, FreePascal, OpenWatcom, Fasm, GoAsm...)
  • graphics (2010/10) PE file format (file & memory layout, headers, data directories)

Mach Object

  • PoC (2013/01/02) CorkaM-OsX, a Mach-O/PDF/HTML/Java file

brainteasers

Executable and Linkable Format

  • PoC (2012/12/13) CorkaMInuX, an ELF/PDF/HTML/Java file

x86/x64 asm

packers

more

...for more information, check the (old) blog map, and the downloads tab.

Powered by Google Project Hosting