More on fortifying Lotus Notes

Ben Laurie ben at algroup.co.uk
Sun, 06 Jun 1999 14:57:16 +0100


Dave Bird wrote:
> 
> In article <199906061307.OAA08481@notatla.demon.co.uk>,
> lists@notatla.demon.co.uk writes
> >The programmer can make life a bit more complicated by having more than one
> >check, and by not flagging the relevant instructions by putting them close
> >to the bail_with_error function.
> 
>  Another trick is to figure on automatic dis-assembly going straight
>  down the text (and put a valid load-with-32bit-constant opcode in
>  front) rather than jumped to (where it executes as a conditional junp).

Good disassemblers can spot this trick. Besides, the wise reverse
engineer reverse-engineers with a debugger (or an ICE if budget permits
:-), not a disassembler.

Cheers,

Ben.

--
http://www.apache-ssl.org/ben.html

"My grandfather once told me that there are two kinds of people: those
who work and those who take the credit. He told me to try to be in the
first group; there was less competition there."
     - Indira Gandhi