My favorites | Sign in
Project Home Downloads Issues Source
Project Information
Members
Featured
Wiki pages
Links

About Corkami - sources & PoCs - posters - order prints

Posters (prints)

mini

101 walkthroughs

  • (2013/12/24) ZIP, Java Class, PDF
  • (2013/11/20-2013/12/06) ELF (32b, 64b, AT&T, Pro, ARM)
  • (2013/03/26) COM (also explains PEs' DOS stub)
  • (2012/05/03-2013/06/28) PE 32b, 64b, Russian, French, German, Polish, Japanese, Arabic, Chinese, Korean, Spanish

overview

Binary files

  • 2014/09/08 PoC a PDFLaTeX quine+polyglot: A PDF that is also its own .TeX source
  • 2014/08/10 PoC PoC||GTFO 0x5 a Flash, Iso, PDF, ZIP polyglots
    • article A cryptographer and a binarista walk into a bar
  • 2014/06/27 PoC PoC||GTFO 0x4 a TrueCrypt, PDF , ZIP polyglots
    • This Encrypted Volume is also a PDF; or, A Polyglot Trick for Bypassing TrueCrypt Volume Detection
    • How to Manually Attach a File to a PDF
  • 2014/04/02 When your slides read themselves: a binary inception (follow-up to 44Con 2013 slides)
  • 2014/03/30 a JPG/ZIP/PDF binary chimera (the file is a JPG image, a ZIP containing the same image, a PDF showing the same image, but the image data is present only once) - 1 data body, 3 heads of different types.
  • (2014/03/17) PoC||GTFO 0x03 is a PDF/ZIP/JPG/Audio (raw AFSK)/PNG (encrypted with AES)
    • This PDF is a JPEG; or, This Proof of Concept is a Picture of Cats
    • A Binary Magic Trick, Angecryption
  • (2013/12/28) a MBR/PDF/ZIP polyglot + article
  • (2013/10/06) a schizophrenic PE + article
  • (2013/09/13) 'inception' slides a PE+PDF+HTML+ZIP polyglot and PDF schizophrenic file - the PE file is a PDF viewer, viewing itself.
  • (2013/01/02) CorkaM-OsX, a Mach-O+PDF+HTML+Java polyglot file
  • (2012/12/13) CorkaMInuX, an ELF+PDF+HTML+Java polyglot file
  • (2012/08/01) CorkaMIX, a PE+PDF+HTML(+JavaScript)+(Jar[Class+Zip] ^ PY) polyglot file

Crypto

Presentations

Portable Executable

  • article with PoCs (2011/09/26 - 2013/10/07) the PE format
  • PoC a fully working PE in a tweet (encoded in a python string): "MZR\xc3"+"\0"*56+"@\0\0\0PE\0\0L\1"+"\0"*16+"\2\0\x0b\1"+"\0"*28+"@\0\1\0\0\0\1\0"+"\0"*10+"\4"+"\0"*7+"H\1\0\0G\1"+"\0"*6+"\3"+"\0"*171
  • source a rewrite of the PE header of Traceless demo
  • PoCs (2011/02) Binary corpus is a group of non malicious binaries, exhibiting various file formats, and more specifically, aspects of PE files (Formats: NE, PE, Elf, LX, LE, COM, EXE / Compilers: Digital Mars C, Lcc, Masm, Tasm, FreeBasic, FreePascal, OpenWatcom, Fasm, GoAsm...)
  • graphics (2010/10) PE file format (file & memory layout, headers, data directories)

misc

PDF

brainteasers

x86/x64 asm

packers

more

...for more information, check the (old) blog map, and the downloads tab.

Powered by Google Project Hosting