<?xml version="1.0" encoding="utf-8"?>
				<!-- generator="e107" -->
				<!-- content type="Downloads" -->
				<rss  version="2.0" 
					xmlns:content="http://purl.org/rss/1.0/modules/content/" 
					xmlns:atom="http://www.w3.org/2005/Atom"
					xmlns:dc="http://purl.org/dc/elements/1.1/"
					xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"

				>
				<channel>
				<title>Tuts 4 You : Downloads</title>
				<link>http://tuts4you.com/</link>
				<description>A community for researchers and reverse engineers interested in the field of Reverse Code Engineering (RCE).</description>

<language>en-gb</language>
				<copyright>Copyright (C) 2003 - 2012 Tuts 4 You</copyright>
				<managingEditor>teddyrogers@nospam.com (Teddy Rogers)</managingEditor>
				<webMaster>teddyrogers@nospam.com (Teddy Rogers)</webMaster>
				<pubDate>Thu, 17 May 2012 04:47:50 -0500</pubDate>
				<lastBuildDate>Thu, 17 May 2012 04:47:50 -0500</lastBuildDate>
				<docs>http://backend.userland.com/rss</docs>
				<generator>e107 (http://e107.org)</generator>
				<sy:updatePeriod>hourly</sy:updatePeriod>
				<sy:updateFrequency>1</sy:updateFrequency>

				<ttl>60</ttl>
<atom:link href="http://tuts4you.com/tuts_plugins/rss_menu/rss.php?download.2" rel="self" type="application/rss+xml" />

					<image>
					<title>Tuts 4 You : Downloads</title>
					<url>http://tuts4you.com/tuts_images/tuts4youlogo.png</url>
					<link>http://tuts4you.com/</link>
					<width>88</width>
					<height>31</height>
					<description>A community for researchers and reverse engineers interested in the field of Reverse Code Engineering (RCE).</description>
					</image>
<item>
<title>OllySymbolServer 0.0</title>
<link>http://tuts4you.com/download.php?view.3313</link>
<description><![CDATA[Enable Microsoft symbol server download compatablilty in OllyDbg v1.10 (with no fussing around).]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>suburban_user</dc:creator>
<pubDate>Mon, 23 Apr 2012 03:43:46 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3313</guid>
</item>

<item>
<title>NameChanger 1.1</title>
<link>http://tuts4you.com/download.php?view.3312</link>
<description><![CDATA[I recently returned to an idea of an OllyDbg plug-in which would provide functionality similar like in an IDA related with inter alia :changing name of functions or setting more readable form for global variables.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Marcin &#039;Icewall&#039; Noga</dc:creator>
<pubDate>Sun, 22 Apr 2012 20:09:28 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3312</guid>
</item>

<item>
<title>CPU Initialization Patch 1.0.0.1</title>
<link>http://tuts4you.com/download.php?view.3311</link>
<description><![CDATA[This is a plugin for OllyDbg 1.10, which hot-patches Olly's code to resolve the issue of OllyDbg taking 100% CPU time as soon as the debugged process is running (i.e. after having pressed F9 inside OllyDbg).<br /><br />If nothing else, this problem causes any laptop that you might be reversing on to lose much more battery life than necessary, and also to sound like a jet plane due to constant maximum fan rotation, so this plugin will come in hand for any laptop reversers at least.<br />]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Blurcode</dc:creator>
<pubDate>Sun, 22 Apr 2012 19:34:35 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3311</guid>
</item>

<item>
<title>OllyDbg - Windows 7 (Virtualized) 0.2</title>
<link>http://tuts4you.com/download.php?view.3310</link>
<description><![CDATA[Some beloved plugins for Olly stopped working when used with Windows 7, among these are OllyAdvanced and Conditional Branch Logger just to name two of them. To overcome this issue I virtualized Olly and now the plugins are working again :)<br /><br />You can customize this Olly as usual. Note, that you have to set the Plugins- and UDD- directory when starting it for the first time. Unfortunately there is a small shortcoming - Every part of a plugin that is driver-based is NOT working. This is due to the fact, that drivers cannot be virtualized. For instance while everything else in OllyAdvanced is working, it's driver-based Anti-RTDSC is not but that does not hinder the plugin to work great. The same goes for other plugins that have drivers involved. Sorry for that, virtualization nowadays is pretty good but not perfect.<br /><br />Also, there may be an issue with non-latin charactersets which I'm unable to confirm because I haven't got a non-latin Windows.]]></description>
<category domain='http://tuts4you.com/download.php?list.4'>OllyDbg Engines / Modifications</category>
<dc:creator>DarkElf</dc:creator>
<pubDate>Sun, 22 Apr 2012 19:32:08 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3310</guid>
</item>

<item>
<title>Advanced Labels 1.2.0.0</title>
<link>http://tuts4you.com/download.php?view.3309</link>
<description><![CDATA[Advanced labels with user datatypes support.<br /><br />Compiled in Borland C++ builder 6.0 10.166 w/o addons.]]></description>
<category domain='http://tuts4you.com/download.php?list.94'>OllyDbg2 Plugins</category>
<dc:creator>Oleh Yuschuk, Icegood</dc:creator>
<pubDate>Sun, 22 Apr 2012 17:50:09 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3309</guid>
</item>

<item>
<title>Enigma Protector 1.x - 3.x Vol.1 (Unpacking)</title>
<link>http://tuts4you.com/download.php?view.3308</link>
<description><![CDATA[Today I release - finally - the series of unpacking tutorials about manually unpacking The Enigma Protector. I will discuss all protections of Enigma which are fully detailed as possible.<br /><br />I have to say thanks to LCF-AT, she helped me alot with this.]]></description>
<category domain='http://tuts4you.com/download.php?list.11'>Unpacking Tutorials</category>
<dc:creator>Silence</dc:creator>
<pubDate>Sun, 22 Apr 2012 17:46:39 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3308</guid>
</item>

<item>
<title>VMSweeper 1.5 Beta 0</title>
<link>http://tuts4you.com/download.php?view.3059</link>
<description><![CDATA[VMSweeper helps you to decompile VM code.<br /><br />* VMSweeper decompiles functions, virtualized in: <br /><br /> - Code Virtualizer (Oreans Technology) <br /> - VMProtect (VMProtect Software) <br /><br />* Recovers import <br />* Finds different types of VM, including not supported for decompiling by itself.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Vam</dc:creator>
<pubDate>Sun, 15 Apr 2012 16:50:34 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3059</guid>
</item>

<item>
<title>Win32api and x86 Opcodes</title>
<link>http://tuts4you.com/download.php?view.3307</link>
<description><![CDATA[The Win32.hlp file for OllyDbg "Help on symbolic name" containing information on some Win32 API's. Archive includes OpCodes.hlp for a list of some x86 hex opcodes and mnemonics with descriptions.]]></description>
<category domain='http://tuts4you.com/download.php?list.8'>OllyDbg Extra Tools &amp; Utilities</category>
<dc:creator>Microsoft</dc:creator>
<pubDate>Sun, 15 Apr 2012 08:07:42 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3307</guid>
</item>

<item>
<title>Enigma Protector 2.x - 3.x (HWID + Inline Patching)</title>
<link>http://tuts4you.com/download.php?view.3306</link>
<description><![CDATA[Video tutorials on bypassing the HWID and inline patching of Enigma Protector protected files from version 2.x to 3.x.]]></description>
<category domain='http://tuts4you.com/download.php?list.12'>Inline Patching</category>
<dc:creator>Pertic@n</dc:creator>
<pubDate>Sun, 15 Apr 2012 07:35:43 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3306</guid>
</item>

<item>
<title>Keygenning Encrypto's KeygenMe #5</title>
<link>http://tuts4you.com/download.php?view.3305</link>
<description><![CDATA[A tutorial on how to reverse a challenge from an old pal Encrypto that I have found lately and I have never reversed until now. The ultimate goal of the challenge is to code a standalone keygen and this is what I have done. The tutorial is a little bit long since it is provided with details so anyone can watch and give it a try.<br /><br />If you get any kind of problems will be happy to help!]]></description>
<category domain='http://tuts4you.com/download.php?list.26'>Keygenning / Serial Fishing</category>
<dc:creator>NewHitman</dc:creator>
<pubDate>Sun, 15 Apr 2012 07:30:49 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3305</guid>
</item>

<item>
<title>Keygenning pDriLl CrackMe #2</title>
<link>http://tuts4you.com/download.php?view.3304</link>
<description><![CDATA[Here is my tutorial for pDriLl's KeygenMe#2. It is using RSA, I hope it will be useful for you and of course this tutorial is not for complete newbies.]]></description>
<category domain='http://tuts4you.com/download.php?list.26'>Keygenning / Serial Fishing</category>
<dc:creator>hepL3r</dc:creator>
<pubDate>Sun, 15 Apr 2012 07:28:10 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3304</guid>
</item>

<item>
<title>OllyMSDN 1.0</title>
<link>http://tuts4you.com/download.php?view.3303</link>
<description><![CDATA[This plugin will replace WIN32.HLP with online help from the MSDN website.<br /><br />To install:<br />    1) Copy OllyMSDN.dll to OllyDbg's or ImmDbg's plugin directory.<br />    2) Start the debugger.<br />    3) If you haven't done so already, go to Help -> Select API help file<br />       and select WIN32.HLP as usual. It doesn't need to be the real file,<br />       just one named like that.<br /><br />To use:<br />    *) When you click on Help -> Open API help file, the MSDN online website<br />       will be opened instead.<br />    *) To get help on individual API calls, right-click on the CALL instruction<br />       in the CPU pane and click on "Help on symbolic name".]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Mario Vilas</dc:creator>
<pubDate>Sun, 15 Apr 2012 07:25:37 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3303</guid>
</item>

<item>
<title>OllyWow64 0.1</title>
<link>http://tuts4you.com/download.php?view.3302</link>
<description><![CDATA[Here is an OllyDbg v1.10 plugin to remove the annoying single-step break while debugging in Windows 7, Wow64.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Sun, 15 Apr 2012 07:24:23 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3302</guid>
</item>

<item>
<title>Virtual Section Dumper 2.0</title>
<link>http://tuts4you.com/download.php?view.3291</link>
<description><![CDATA[VSD (Virtual Section Dumper) is intented to be a tool to visualize and dump the memory regions of a running 32 bits or a 64 bits process in many ways. For example, you can dump the entire process and fix the PE Header, dump a given range of memory or even list and dump every virtual section present in the process.]]></description>
<category domain='http://tuts4you.com/download.php?list.41'>Process Explorers / Monitors</category>
<dc:creator>+NCR/CRC!</dc:creator>
<pubDate>Sun, 15 Apr 2012 07:24:13 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3291</guid>
</item>

<item>
<title>SyserExt 0.95</title>
<link>http://tuts4you.com/download.php?view.3301</link>
<description><![CDATA[SyserExt is a plugin for Syser debugger. The intention is similar to IceExt and it has mainly the following features:<br /><br />- Advanced hide engine<br />- Conditional branch logger]]></description>
<category domain='http://tuts4you.com/download.php?list.39'>Miscellaneous Tools</category>
<dc:creator>Ferrit</dc:creator>
<pubDate>Tue, 20 Mar 2012 08:19:15 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3301</guid>
</item>

<item>
<title>RISC Machine Documentation</title>
<link>http://tuts4you.com/download.php?view.3300</link>
<description><![CDATA[I present this time a documentation about RISC machines. The content about this document is detailed enough to give an overview of RISC machines, how they are constructed, how they deal with virtual opcodes, and how they virtualize them.]]></description>
<category domain='http://tuts4you.com/download.php?list.32'>Virtualization / Virtual Machines</category>
<dc:creator>Deathway</dc:creator>
<pubDate>Mon, 12 Mar 2012 02:02:40 -0500</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3300</guid>
</item>

<item>
<title>Reverse Engineering Techniques - Part 1</title>
<link>http://tuts4you.com/download.php?view.3299</link>
<description><![CDATA[The whole tutorial is about playing with a target and implementing new things into it. The tutorial is not for newbies, you must know how the tools given in this tutorial works. The entire article is based on exploring the calibre of a reverse engineer. Reverse engineering is an art; how to analyse and play with the target and find out other possibilities which you can implement. Sometimes targets are so challenging you can't even imagine. The target I am going to use in this tutorial is a simple crackme by Nemo.]]></description>
<category domain='http://tuts4you.com/download.php?list.25'>Reverse Code Engineering</category>
<dc:creator>Kingstaa</dc:creator>
<pubDate>Sat, 10 Mar 2012 21:21:12 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3299</guid>
</item>

<item>
<title>Oreans UnVirtualizer 1.5</title>
<link>http://tuts4you.com/download.php?view.3108</link>
<description><![CDATA[This tool will help conversion VirtualOpcodes -> Assembly Instruction. Restoring the original code of your virtualized application, the basic engine was from CodeUnvirtualizer, my other tool.<br /><br />[Features]<br /><br />- Supports WinLicense/Themida/CodeVirtualizer Cisc/Risc Machines<br />- Supports almost all common opcodes<br />- Supports CHECK_MACRO_PROTECTION on CISC machines<br />- Supppots MultiBranch Tech<br /><br />[Use]<br /><br />- Right-click on the jump leading to the Virtual Machine Area and press Unvirtualize (If machine isn't found you have to click again, after checking that the full machine was correctly deofuscated)]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Deathway</dc:creator>
<pubDate>Sat, 10 Mar 2012 21:16:26 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3108</guid>
</item>

<item>
<title>Keygenning pDriLl CrackMe #1</title>
<link>http://tuts4you.com/download.php?view.3298</link>
<description><![CDATA[In this tutorial I will show you how we can keygen this easy keygenme from pDriLl.]]></description>
<category domain='http://tuts4you.com/download.php?list.26'>Keygenning / Serial Fishing</category>
<dc:creator>hepL3r</dc:creator>
<pubDate>Thu, 08 Mar 2012 05:06:45 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3298</guid>
</item>

<item>
<title>TLSCatch 0.2</title>
<link>http://tuts4you.com/download.php?view.3014</link>
<description><![CDATA[This plugin simply intercepts any new module loaded into the current process address space, searches it for TLS callbacks and sets a one-shot breakpoint on every callback found. It lets the malware analyst catch any TLS callback in OllyDbg.<br /><br />1) Uses permanent breakpoints instead of one-shot breakpoints.<br />2) Handles executables which manipulate their PE header at runtime.<br /><br />Just copy the plugin DLL into Olly's plugin directory then start OllyDbg.<br /><br />Tested on OllyDbg v1.10 on Windows XP and Windows Vista.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Thu, 08 Mar 2012 05:06:32 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3014</guid>
</item>

<item>
<title>Reversing a Keygenme Challenge</title>
<link>http://tuts4you.com/download.php?view.3297</link>
<description><![CDATA[This tutorial is intended for beginners in RCE but it might contain something for more advanced ones. Those of you which are more advanced you can start from Part 2 as this tutorial is split into two parts.<br /><br />The target and objective for both parts of the tutorial will be a keygenme coded by Flux.]]></description>
<category domain='http://tuts4you.com/download.php?list.26'>Keygenning / Serial Fishing</category>
<dc:creator>lfozia0</dc:creator>
<pubDate>Tue, 06 Mar 2012 07:38:58 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3297</guid>
</item>

<item>
<title>BIOS Disassembly Ninjutsu Uncovered</title>
<link>http://tuts4you.com/download.php?view.3296</link>
<description><![CDATA[For many years, there has been a myth among computer enthusiasts and practitioners that PC BIOS (Basic Input Output System) modification is a kind of black art and only a handful of people can do it or only the motherboard vendor can carry out such a task.  On the contrary, this book will prove that with the right tools and approach, anyone can understand and modify the BIOS to suit their needs without the existence of its source code. It can be achieved by using a systematic approach to BIOS reverse engineering and modification. An advanced level of this modification technique is injecting a custom code to the BIOS binary. <br /><br />There are many reasons to carry out BIOS reverse engineering and modification, from the fun of doing it to achieve higher clock speed in overclocking scenario, patching certain bug, injecting a custom security code into the BIOS, up to commercial interest in the embedded x86 BIOS market.  The emergence of embedded x86 platform as consumer electronic products such as TV set-top boxes, telecom-related appliances and embedded x86 kiosks have raised the interest in BIOS reverse engineering and modification. In the coming years, these techniques will become even more important as the state of the art bus protocols have delegate a lot of their initialization task to the firmware, i.e. the BIOS. Thus, by understanding the techniques, one can dig the relevant firmware codes and understand the implementation of those protocols within the BIOS binary. <br /><br />The main purpose of the BIOS is to initialize the system into execution environment suitable for the operating system. This task is getting more complex over the years, since x86 hardware evolves quite significantly. It’s one of the most dynamic computing platform on earth. Introduction of new chipsets happens once in 3 or at least 6 month. This event introduces a new code base for the silicon support routine within the BIOS. Nevertheless, the overall architecture of the BIOS is changing very slowly and the basic principle of the code inside the BIOS is preserved over generations of its code. However, there has been a quite significant change in the BIOS scene in the last few years, with the introduction of EFI (extensible Firmware Interface) by several major hardware vendors and with the growth in OpenBIOS project. With these advances in BIOS technology, it’s even getting more important to know systematically what lays within the BIOS. <br /><br />In this book, the term BIOS has a much broader meaning than only motherboard BIOS, which is familiar to most of the reader. It also means the expansion ROM. The latter term is the official term used to refer to the firmware in the expansion cards within the PC, be it ISA, PCI or PCI Express. <br />So, what can you expect after reading this book? Understanding the BIOS will open a new frontier. You will be able to grasp how exactly the PC hardware works in its lowest level. Understanding contemporary BIOS will reveal the implementation of the latest bus protocol technology, i.e. HyperTransport and PCI-Express. In the software engineering front, you will be able to appreciate the application of compression technology in the BIOS. The most important of all, you will be able to carry out reverse engineering using advanced techniques and tools. You will be able to use the powerful IDA Pro disassembler efficiently. Some reader with advanced knowledge in hardware and software might even want to “borrow” some of the algorithm within the BIOS for their own purposes.  In short, you will be on the same level as other BIOS code-diggers. <br /><br />This book also presents a generic approach to PCI expansion ROM development using the widely available GNU tools. There will be no more myth in the BIOS and everyone will be able to learn from this state-of-the-art software technology for their own benefits.]]></description>
<category domain='http://tuts4you.com/download.php?list.24'>Disassembling</category>
<dc:creator>Darmawan Salihun</dc:creator>
<pubDate>Sun, 04 Mar 2012 01:42:08 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3296</guid>
</item>

<item>
<title>Deobfuscation of Packed and Virtulazation-Obfuscated Protected Binaries</title>
<link>http://tuts4you.com/download.php?view.3295</link>
<description><![CDATA[Code obfuscation techniques are increasingly being used in software for such reasons as protecting trade secret algorithms from competitors and deterring license tampering by those wishing to use the software for free. However, these techniques have also grown in popularity in less legitimate areas, such as protecting malware from detection and reverse engineering. This work examines two such techniques – packing and virtualization-obfuscation –and presents new behavioral approaches to analysis that may be relevant to security analysts whose job it is to defend against malicious code. These approaches are robust against variations in obfuscation algo­rithms, such as changing encryption keys or virtual instruction byte code. <br /><br />Packing refers to the process of encrypting or compressing an executable file. This process “scrambles” the bytes of the executable so that byte-signature matching algorithms commonly used by anti-virus programs are ineffective. Standard static analysis techniques are similarly ineffective since the actual byte code of the program is hidden until after the program is executed. Dynamic analysis approaches exist, but are vulnerable to dynamic defenses. We detail a static analysis technique that starts by identifying the code used to “unpack” the executable, then uses this unpacker to generate the unpacked code in a form suitable for static analysis. Results show we are able to correctly unpack several encrypted and compressed malware, while still handling several dynamic defenses. <br /><br />Virtualization-obfuscation is a technique that translates the original program into virtual instructions, then builds a customized virtual machine for these instructions. As with packing, the byte-signature of the original program is destroyed. Furthermore, static analysis of the obfuscated program reveals only the structure of the virtual machine, and dynamic analysis produces a dynamic trace where orig­inal program instructions are intermixed, and often indistinguishable from, virtual machine instructions. We present a dynamic analysis approach whereby all instructions that affect the external behavior of the program are identified, thus building an approximation of the original program that is observationally equivalent. We achieve good results at both identifying instructions from the original program, as well as eliminating instructions known to be part of the virtual machine.]]></description>
<category domain='http://tuts4you.com/download.php?list.86'>Obfuscation / Deobfuscation</category>
<dc:creator>Kevin Patrick Coogan</dc:creator>
<pubDate>Sun, 04 Mar 2012 01:40:17 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3295</guid>
</item>

<item>
<title>ImmSoftice 0.1</title>
<link>http://tuts4you.com/download.php?view.3294</link>
<description><![CDATA[Who has ever used SoftICE will, and probably still finds OllyDbg and ImmunityDebugger key mapping confusing. Guess what, I'm one of them. For Olly we have Crudd[RET] modification which has SoftICE keys, and I'm using this Olly version for a long long loooooong time with some custom patches. Recently, at CodeGate 2012 we had to use ImmunityDebugger for a some challange, and I found it very very veeeeeeery annoying to use default keys there, so I wrote this plugin which will map SoftICE keys to ImmunityDebugger so this debugger can be used by users which are used to SoftICE keys (and also WinDbg keys).<br /><br />Hope SoftICE and WinDbg users will find it useful...]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Deroko</dc:creator>
<pubDate>Sun, 04 Mar 2012 01:37:33 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3294</guid>
</item>

<item>
<title>Kao’s “Toy Project” and Algebraic Cryptanalysis</title>
<link>http://tuts4you.com/download.php?view.3293</link>
<description><![CDATA[In “Toy Project” Kao presents us with a tiny, yet perverse, piece of code to reverse. Given two 32-byte strings A and B, and the 32-bit integers x and y that were used to produce B from A with the following function: <br /><br /><div class='code_highlight code-box' style='unicode-bidi: embed; direction: ltr'><code><span style="color: #000000">void&nbsp;expand(u8&nbsp;B&#091;32],&nbsp;const&nbsp;u8&nbsp;A&#091;32],&nbsp;u32&nbsp;x,&nbsp;u32&nbsp;y)&nbsp;<br />{&nbsp;<br />&nbsp;&nbsp;u32&nbsp;i;&nbsp;<br />&nbsp;&nbsp;for(i=0;&nbsp;i&nbsp;&lt;&nbsp;32;&nbsp;++i)&nbsp;<br />&nbsp;&nbsp;{&nbsp;<br /><br />&nbsp;&nbsp;&nbsp;&nbsp;out&#091;i]&nbsp;=&nbsp;(in&#091;i]&nbsp;-x)&nbsp;^&nbsp;y;&nbsp;<br />&nbsp;&nbsp;&nbsp;&nbsp;x&nbsp;=&nbsp;ROL(x,&nbsp;1);&nbsp;<br />&nbsp;&nbsp;&nbsp;&nbsp;y&nbsp;=&nbsp;ROL(y,&nbsp;1);&nbsp;<br />&nbsp;&nbsp;}&nbsp;<br />}&nbsp;</span></code></div><br /><br />Simple enough. How do we solve it?]]></description>
<category domain='http://tuts4you.com/download.php?list.26'>Keygenning / Serial Fishing</category>
<dc:creator>Dcoder</dc:creator>
<pubDate>Sun, 04 Mar 2012 01:32:34 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3293</guid>
</item>

<item>
<title>RemoveCriticality 0.2</title>
<link>http://tuts4you.com/download.php?view.3292</link>
<description><![CDATA[An OllyDbg plugin that allows malware analysts to safely debug processes that call the "RtlSetProcessIsCritical" function.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Sun, 04 Mar 2012 01:30:51 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3292</guid>
</item>

<item>
<title>Calculator 0.1</title>
<link>http://tuts4you.com/download.php?view.3290</link>
<description><![CDATA[Fast access to Windows Calculator from OllyDbg, just press Alt+F11.<br /><br />Tested with OllyDbg v1.10 on XP SP2 and Windows 7.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Wed, 22 Feb 2012 08:03:48 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3290</guid>
</item>

<item>
<title>AttachTo 0.1</title>
<link>http://tuts4you.com/download.php?view.3289</link>
<description><![CDATA[Processes with manipulated PEB.LoaderData don't show in the OllyDbg "Select process to attach" dialogue box.<br /><br />The plugin first checks for the integrity of the target process's _PEB_LDR_DATA structure. If a manipulated structure is detected, the plugin tries to create a new typical one.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Wed, 22 Feb 2012 07:57:16 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3289</guid>
</item>

<item>
<title>ICanAttach 0.2</title>
<link>http://tuts4you.com/download.php?view.3253</link>
<description><![CDATA[This plugin enables you to bypass anti-attach techniques e.g. Hooked DbgUiRemoteBreakin, DbgBreakPoint, and NtContinue functions.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Wed, 22 Feb 2012 07:57:11 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3253</guid>
</item>

<item>
<title>MarkAllAsSystem 0.1</title>
<link>http://tuts4you.com/download.php?view.3288</link>
<description><![CDATA[This tiny OllyDbg plugin marks all loaded DLLs as system. <br /><br />This is very useful only when tracing over system DLLs in an application with large number of loaded non-system DLLs.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Wed, 22 Feb 2012 07:55:34 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3288</guid>
</item>

<item>
<title>OllyVB 0.1</title>
<link>http://tuts4you.com/download.php?view.3287</link>
<description><![CDATA[A tiny plugin that resolves the "DllFunctionCall" function calls.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Wed, 22 Feb 2012 07:54:20 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3287</guid>
</item>

<item>
<title>StrongOD 0.4.6.816</title>
<link>http://tuts4you.com/download.php?view.2028</link>
<description><![CDATA[Make your OllyDbg Strong!<br /><br />This plug-in provides three kinds of ways to initiate the process:<br /><br />1, Normal - And the same manner as the original start, the STARTUPINFO inside unclean data <br />2, CreateAsUser - User with a mandate to initiate the process of the user, so that the process running under the purview of the User, unable to establish the process Admin operation.<br /><br />Running is such a need in the local security strategy - the user rights assignment inside your users will join the two powers: <br /><br />1, the replacement process-level marks (SeAssignPrimaryTokenPrivilege)<br />2, the operating system mode operations (SeTcbPrivilege)<br /><br />If the home version of the windows, unable to set up, then you can try to use SuperMode and reopen the OD to upgrade the competence and strongly does not recommend the use of this option<br /><br />3, CreateAsRestrict - The second option the user with User authority to initiate the process more restricted areas, and increase the third function to a explicit Admin users to initiate proceedings.<br /><br />The procedure is initiated Admin user, but power users only some of the default User authority, all authority to delete some risk (including SeDebugPrivilege, SeLoadDriverPrivilege, etc.), this procedure will not run OD cause great harm. In this way the proposed commencement of the proceedings.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>海风月影</dc:creator>
<pubDate>Tue, 14 Feb 2012 06:12:32 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.2028</guid>
</item>

<item>
<title>PC Guard 5.07 (Unpacking)</title>
<link>http://tuts4you.com/download.php?view.3286</link>
<description><![CDATA[A video tutorial showing a method of unpacking PC Guard 5.07 on Windows XP.]]></description>
<category domain='http://tuts4you.com/download.php?list.11'>Unpacking Tutorials</category>
<dc:creator>PassingThrough</dc:creator>
<pubDate>Tue, 14 Feb 2012 06:05:02 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3286</guid>
</item>

<item>
<title>VirusTotal v0.1</title>
<link>http://tuts4you.com/download.php?view.3285</link>
<description><![CDATA[A VirusTotal reporting and file submission plugin for IDA Pro. The plugin will allow you to get reports from VirusTotal based on the input file MD5 or a file of your choice. The plugin will offer to upload the file if the file was not analyzed before.]]></description>
<category domain='http://tuts4you.com/download.php?list.77'>IDA Plugins</category>
<dc:creator>Elias Bachaalany</dc:creator>
<pubDate>Tue, 14 Feb 2012 05:52:06 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3285</guid>
</item>

<item>
<title>DetachMe 0.1</title>
<link>http://tuts4you.com/download.php?view.3284</link>
<description><![CDATA[One of the new interesting features of OllyDbg v2.0 is the "Detach" functionality, which enables you to detach debuggees from OllyDbg at anytime and let them run freely outside control of OllyDbg.<br /><br />Unfortunately, OllyDbg v1.10, the widely used version, lacks this features. Pedram Amini has created a nice plugin to fill this gap, but it does not satisfy my needs, though.<br /><br />Pedram's plugin only works on debuggees in the running mode. It does not work on debuggees in the suspended mode. In addition, debugees will crash if software breakpoints are left.<br /><br />This pushed me to create a new OllyDbg v1.10 plugin, in which i tried to create a similar functionality to the one in version 2.0.<br /><br />Features introduced in my plugin:<br /><br /> 1) Disabling user's software and hardware breakpoints without affecting the corresponding .udd files.<br /> 2) Detaching debuggees in the suspended mode.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Waliedassar</dc:creator>
<pubDate>Wed, 08 Feb 2012 06:44:47 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3284</guid>
</item>

<item>
<title>Ariadne Optimizer 0.1  (OllyDbg)</title>
<link>http://tuts4you.com/download.php?view.3283</link>
<description><![CDATA[The Ariadne framework makes it possible for anyone who is involved in reverse engineering to save a time when reversing a code or creating new products. Using Ariadne, you can read and modify executable files, disassemble them, and even decompile a part of the code into the intermediate representation (Ariadne IR). Of course, with Ariadne you can not only read disassembled or decompiled instructions, but also modify them. Moreover, modifications can be saved into the source executable file without using any additional tools. But that's not all! Ariadne has a series of original code trace optimization strategies built-in, which can make your life a lot easier when working with obfuscated code. The Ariadne framework was initially developed for easy use in your own programs. The range of Ariadne applications is broad – from software analysis with complex obfuscation to programs that provide obfuscation and software protection.<br /><br />Ariadne key features:<br /><br />* PE parser <br />  - Makes it possible PE format analyzing and modifying<br />  - Supports modifications saving into PE-file<br /><br />* Ariadne Intelligent Disassembler (AID). Based on open-source Mediana disassembler <br />  - GP, FPU, MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, SSE4a, VMX, SMX support<br />  - Provides good code coverage of the PE-file without debugging information (the technology is based on heuristics rather than on signatures)<br />  - Supports MAP-files<br />  - Recognizes switch tables and other entry points including Borland initialization and other tables during smart analysis<br />  - Splits code into basic blocks<br />  - Allows database saving/loading<br />  - Supports modifications saving into PE-file<br /><br />* Ariadne Intermediate Representation (AIR) language <br />  - Supports assembler instructions translation into IR<br />  - Allows IR instructions modifying<br />  - Optimized to create obfuscation and deobfuscation strategies<br />  - Contains code tracing mechanisms<br />  - Contains built-in trace deobfuscation: (AIR Wave Deobfuscation Technology)<br />  - Supports IR instructions emulation<br />  - Supports IR-project (AIR database) saving and loading<br />  - Supports translation from IR into binary code<br /><br />Most of the products which disassemble and analyze PE-files require a lot of RAM. In some cases they crash due to lack of memory. In Ariadne, this problem is solved thanks to its own memory manager. When RAM becomes insufficient, the framework creates its own swap file on the computer's hard disk.]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Group-IB</dc:creator>
<pubDate>Tue, 07 Feb 2012 08:47:15 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3283</guid>
</item>

<item>
<title>Ariadne Optimizer 0.1 (IDA)</title>
<link>http://tuts4you.com/download.php?view.3282</link>
<description><![CDATA[The Ariadne framework makes it possible for anyone who is involved in reverse engineering to save a time when reversing a code or creating new products. Using Ariadne, you can read and modify executable files, disassemble them, and even decompile a part of the code into the intermediate representation (Ariadne IR). Of course, with Ariadne you can not only read disassembled or decompiled instructions, but also modify them. Moreover, modifications can be saved into the source executable file without using any additional tools. But that's not all! Ariadne has a series of original code trace optimization strategies built-in, which can make your life a lot easier when working with obfuscated code. The Ariadne framework was initially developed for easy use in your own programs. The range of Ariadne applications is broad – from software analysis with complex obfuscation to programs that provide obfuscation and software protection.<br /><br />Ariadne key features:<br /><br />* PE parser <br />  - Makes it possible PE format analyzing and modifying<br />  - Supports modifications saving into PE-file<br /><br />* Ariadne Intelligent Disassembler (AID). Based on open-source Mediana disassembler <br />  - GP, FPU, MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, SSE4a, VMX, SMX support<br />  - Provides good code coverage of the PE-file without debugging information (the technology is based on heuristics rather than on signatures)<br />  - Supports MAP-files<br />  - Recognizes switch tables and other entry points including Borland initialization and other tables during smart analysis<br />  - Splits code into basic blocks<br />  - Allows database saving/loading<br />  - Supports modifications saving into PE-file<br /><br />* Ariadne Intermediate Representation (AIR) language <br />  - Supports assembler instructions translation into IR<br />  - Allows IR instructions modifying<br />  - Optimized to create obfuscation and deobfuscation strategies<br />  - Contains code tracing mechanisms<br />  - Contains built-in trace deobfuscation: (AIR Wave Deobfuscation Technology)<br />  - Supports IR instructions emulation<br />  - Supports IR-project (AIR database) saving and loading<br />  - Supports translation from IR into binary code<br /><br />Most of the products which disassemble and analyze PE-files require a lot of RAM. In some cases they crash due to lack of memory. In Ariadne, this problem is solved thanks to its own memory manager. When RAM becomes insufficient, the framework creates its own swap file on the computer's hard disk.]]></description>
<category domain='http://tuts4you.com/download.php?list.77'>IDA Plugins</category>
<dc:creator>Group-IB</dc:creator>
<pubDate>Tue, 07 Feb 2012 08:45:07 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3282</guid>
</item>

<item>
<title>Ariadne Optimizer 0.1 (Immunity)</title>
<link>http://tuts4you.com/download.php?view.3281</link>
<description><![CDATA[The Ariadne framework makes it possible for anyone who is involved in reverse engineering to save a time when reversing a code or creating new products. Using Ariadne, you can read and modify executable files, disassemble them, and even decompile a part of the code into the intermediate representation (Ariadne IR). Of course, with Ariadne you can not only read disassembled or decompiled instructions, but also modify them. Moreover, modifications can be saved into the source executable file without using any additional tools. But that's not all! Ariadne has a series of original code trace optimization strategies built-in, which can make your life a lot easier when working with obfuscated code. The Ariadne framework was initially developed for easy use in your own programs. The range of Ariadne applications is broad – from software analysis with complex obfuscation to programs that provide obfuscation and software protection.<br /><br />Ariadne key features:<br /><br />* PE parser <br />  - Makes it possible PE format analyzing and modifying<br />  - Supports modifications saving into PE-file<br /><br />* Ariadne Intelligent Disassembler (AID). Based on open-source Mediana disassembler <br />  - GP, FPU, MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, SSE4a, VMX, SMX support<br />  - Provides good code coverage of the PE-file without debugging information (the technology is based on heuristics rather than on signatures)<br />  - Supports MAP-files<br />  - Recognizes switch tables and other entry points including Borland initialization and other tables during smart analysis<br />  - Splits code into basic blocks<br />  - Allows database saving/loading<br />  - Supports modifications saving into PE-file<br /><br />* Ariadne Intermediate Representation (AIR) language <br />  - Supports assembler instructions translation into IR<br />  - Allows IR instructions modifying<br />  - Optimized to create obfuscation and deobfuscation strategies<br />  - Contains code tracing mechanisms<br />  - Contains built-in trace deobfuscation: (AIR Wave Deobfuscation Technology)<br />  - Supports IR instructions emulation<br />  - Supports IR-project (AIR database) saving and loading<br />  - Supports translation from IR into binary code<br /><br />Most of the products which disassemble and analyze PE-files require a lot of RAM. In some cases they crash due to lack of memory. In Ariadne, this problem is solved thanks to its own memory manager. When RAM becomes insufficient, the framework creates its own swap file on the computer's hard disk.]]></description>
<category domain='http://tuts4you.com/download.php?list.74'>Immunity Plugins</category>
<dc:creator>Group-IB</dc:creator>
<pubDate>Tue, 07 Feb 2012 08:34:19 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3281</guid>
</item>

<item>
<title>ODBGPluginConv 0.1b</title>
<link>http://tuts4you.com/download.php?view.3280</link>
<description><![CDATA[A utility to convert our OllyDbg plugins to use them on any modified version thereof<br /><br />Features:<br /><br /> -Automatic plugin conversion<br /> -Supported versions: OllyDbg, Defixed, SND, RAMODBG, diablo2oo2, Shadow, ICE, CiM.<br /> -Advanced plugin conversion<br /> -Change imports and exports names manually<br /> -Integrated hexa-editor]]></description>
<category domain='http://tuts4you.com/download.php?list.9'>OllyDbg Plugins</category>
<dc:creator>Thunder</dc:creator>
<pubDate>Tue, 07 Feb 2012 08:31:10 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3280</guid>
</item>

<item>
<title>Armadillo - ECDSA Patching</title>
<link>http://tuts4you.com/download.php?view.3279</link>
<description><![CDATA[I had a lot of free time to spend and therefore I created a full tutorial about Armadillo ECDSA Public Parameter replacing. I will start from the beginning and put hardware breakpoints and stuff to show you the time-consuming process which reversing can be.<br /><br />Tutorial includes an UnPackMe, the text file so you can try stuff yourself and a few useful tools (source available on request).]]></description>
<category domain='http://tuts4you.com/download.php?list.90'>Packers / Protectors</category>
<dc:creator>Mr. eXoDia</dc:creator>
<pubDate>Sat, 04 Feb 2012 21:43:51 -0600</pubDate>
<guid isPermaLink="true">http://tuts4you.com/download.php?view.3279</guid>
</item>


				</channel>
				</rss>
