This website is supported, hosted and funded by Corelan Consulting - https://www.corelan-consulting.com. Please follow us on Facebook (@corelanconsulting) and Twitter (@corelanconsult). Corelan training schedules: https://www.corelan-training.com/index.php/training-schedules



Please consider donating: https://www.corelan.be/index.php/donate/


4,685 views

HITB 2011 CTF – Reversing Vectored Exception Handling (VEH)

Introduction

Today we will have a look at a CTF binary from HITB pre qualifications CTF 2011:

http://conference.hackinthebox.org/hitbsecconf2011ams/?p=1333

 

This is an interesting binary to reverse because Vectored Exception Handling (VEH) was used in the challenge. As this was new to me, I documented how it works and wanted to share a short reversing write-up of the binary.

You can download the binary (windows_challenge.exe) here

 

Thanks to skier_ and the HITB crew for generating such an awesome CTF binary.

Come along………..and enjoy!

Fancy

 

Note: I used windows XP SP3 so maybe the addresses here in this video may differ from the addresses on your box.

Video

You can watch a full screen version here or download the video here


© 2011 – 2015, Corelan Team (fancy). All rights reserved.

Related Posts:

Comments are closed.

Corelan Training

We have been teaching our win32 exploit dev classes at various security cons and private companies & organizations since 2011

Check out our schedules page here and sign up for one of our classes now!

Donate

Want to support the Corelan Team community ? Click here to go to our donations page.

Want to donate BTC to Corelan Team?



Your donation will help funding server hosting.

Corelan Team Merchandise

You can support Corelan Team by donating or purchasing items from the official Corelan Team merchandising store.

Protected by Copyscape Web Plagiarism Tool

Corelan on Slack

You can chat with us and our friends on our Slack workspace:

  • Go to our facebook page
  • Browse through the posts and find the invite to Slack
  • Use the invite to access our Slack workspace
  • Categories