-
-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
function detection doesn't find callbacks f. eg. CreateThread, SetWindowsHookEx, etc. #5890
Comments
can you share a sample bin? |
i dont see the same disasm at that offset. i mostly find refs to data in pushes, not code |
oh right different binary. here a SetWindowsHookEx call is located in pdf @ 0x10012536, the callback thats not detected is 0x10013318:
also CreateThread is present in 0x1000f974:
hope that helps |
Use afr or aa
|
And u have to analize to get anything in the disasm
|
It's analysed |
Works, in a sense, when I issue an 'afr' command for each function where I suspect indirectly referenced code. This way I go through my binaries, get all the functions that e.g. contain a CreateThread, then 'afr' these again to have radare generate functions for the thread handler function. |
aa should run afr but the problem is that its probably analizing in different order and overlapping some functions. you can try to set e anal.hasnext=true sorry i have not much time lately to look deeper on this issue
|
😍😍😍
|
This has not received any activity in the last years. Was the issue fixed? If not, could you share a reproducer (the one listed has a password)? |
Always same password "infected". |
Function detection misses callback functions in Windows binaries, found to be true at least for CreateThread callback handlers and SetWindowsHookEx handlers.
Below, 0x1000282d should be a function address, but is handled as dword.
The text was updated successfully, but these errors were encountered: