We got deobfuscated skype v5.5!!!
I can't belive in this. But its fucking true. Great thanks and congratulations going to Vilko.
Some words from Vilko about his skype5 research:
Skype version 5.5 is a hybrid of GUI on delphi and embedded dll with skype "kernel". This kernel is fully independent structure in binary code - code block, data block, imports. And it was built with use of VC compiler(exists VC lib signatures).
This kernel has not contain any reference to external code/data in delphi part. And only entry point block xrefs on kernel from delphi GUI. It can be saved as independent binary code with dll-header, and that kernel will work, i tested this.
You can download it here:
(DMCA takedown arrived, so check download link in comments)
Skype-open-source project still alive!
P.S. We open jabber conference for all who interested in skype reversing. Feel free to join on: skypeopensource@conference.jabber.ru
SkypeKit_sdk+runtimes_370_412.zip
ReplyDeletehttp://thepiratebay.se/torrent/7190651/
skype55_59_deobfuscated_binaries
http://thepiratebay.se/torrent/7238404/
magnet:?xt=urn:btih:2a93d303ce538a1f5894f93086255837ccc3eeff&dn=skype55_59_deobfuscated_binaries&tr=udp%3A%2F%2Ftracker.openbittorrent.com%3A80&tr=udp%3A%2F%2Ftracker.publicbt.com%3A80&tr=udp%3A%2F%2Ftracker.ccc.de%3A80
ReplyDeleteskype55_patched.exe
ReplyDeleteMD5 7381deed3e9937ef2206f6bec1023c47
SHA-1 1831e6631b95e93173d899a256769c02cc31eb06
ED2K e243c24c67faf733f39828ddfc4a50f8
skype59_patched.exe
MD5 1233d32e9cb54684cfa7ce093033e3a1
SHA-1 69d50a22019842be494f5c857dd40fa5b7f2dcdb
ED2K 16c9617a0e1c0236ecca39dd35f7f4a0
For those who need to know.
utorrent hash:
ReplyDelete2A93D303 CE538A1F 5894F930 86255837 CCC3EEFF
Упростил скрипт для сбора логов. Спасибо за тул.
ReplyDeletehttp://pastebin.com/sci0RfQq
skype user ip-address disclosure
ReplyDeletehttp://pastebin.com/LrW4NE2p
Skype user IP-address disclosure (english version)
ReplyDeletehttp://pastebin.com/rBu4jDm8
two versions of skypekit deobfuscated:
ReplyDeletemagnet:?xt=urn:btih:3da068082f6ec70be379d4046e4c77bc4578f751&dn=SkypeKit_sdk
%2Bruntimes_370_412.zip&tr=udp%3A%2F%2Ftracker.openbittorrent.com%3A80&tr=udp%3A%2F
%2Ftracker.publicbt.com%3A80&tr=udp%3A%2F%2Ftracker.ccc.de%3A80
фантастическая и плодотворная работа! я б тока посоветовал сразу вырезать проверку на новые версии в этом туле. а то сразу визжать начинает, мол старье используешь....
ReplyDeleteи еще - в парсере логов не отлавливаются(не маскируются) айпишники самого скайпа - и получается что для заданного пользователя я получаю на выходе и айпи его - и айпи скайповского сервера, с которым пользователь соединен.
к примеру:
IP: 212.187.172.66
запустил патченный skype, добавил reg файл, захожу в AppData\Roaming\Skype\user, смотреть нада chatsync?
ReplyDeleteHave you tried to fuzz the skype protocol for 0day vulns already? Do you have a mac version as well, I would be very interested in that.
ReplyDeleteWhat should I add to registry? Link isn't alive anymore.
ReplyDelete[HKEY_CURRENT_USER\Software\Skype\Phone\UI\General]
Delete"LastLanguage"="en"
"Logging"="SkypeDebug2003"
"Logging2"="on"
This one worked great for me!
ReplyDeletemagnet:?xt=urn:btih:2a93d303ce538a1f5894f93086255837ccc3eeff
https://thepiratebay.se/torrent/7238404
How did you do it.. Do you want to write a tutorial...
ReplyDeleteБыло бы круто и познавательно прочитать статью о деобфускации... Скайп давно вызывал удивления в этом плане, его успел выразить даже Крис Касперски...
ReplyDeleteЕсть ли планы по написанию хабрастатьи?
Спасибо за работу.
thanks for the good work!
ReplyDelete