Malware Development: System Calls

Поделиться
HTML-код
  • Опубликовано: 29 янв 2025

Комментарии • 135

  • @crr0ww
    @crr0ww  Год назад +15

    📌 Use code "CROW10" for 10% off your order when you checkout at Maldev Academy or use this link: maldevacademy.com/?ref=crow
    Font: Terminess Nerd Font Mono
    Colourscheme: Zero (Dark Theme)
    I sincerely hope you enjoyed watching this installment of our ongoing malware development series. I know the kernel debugging portion was a bit rushed, and for that, I apologize. I had an entire segment dedicated to kernel debugging, the intricacies of MSRs as well as the incredible CPUID instruction, and all of that planned out for this video but as you could imagine, had I included that, the video would be a month-long. So instead, I'm working on a blog post that will take you into harrowing depths of that entire process, so make sure you look out for it here: www.crow.rip/
    ERRATA:
    - I just realized after rewatching this that I was doing "CONST LPCSTR" when that's not necessary at all since LPCSTR is literally: "typedef const char* LPCSTR;" HAHAHAH LOSING MY MIND
    tysm for watching, nerds. luv u all terribly

  • @C5pider
    @C5pider 11 месяцев назад +122

    Oh mom look i made it into a crow video.

    • @mohammadalihanfi8237
      @mohammadalihanfi8237 11 месяцев назад +2

      Yeah as expected 😅

    • @crr0ww
      @crr0ww  11 месяцев назад +7

      :blushing_emoji:

    • @b3twiise853
      @b3twiise853 11 месяцев назад +1

      Ohh look it is spider

    • @Dnsx_plus
      @Dnsx_plus 11 месяцев назад

      Aren’t you one of the contributors to Maldev Academy?

  • @gato4920
    @gato4920 11 месяцев назад +18

    Have not even made it this far in the series, but I had to show support. Keep it up, we appreciate you.

    • @crr0ww
      @crr0ww  11 месяцев назад +2

      i really appreciate that! thank you so much

  • @user-ik4px2cu1l
    @user-ik4px2cu1l 11 месяцев назад +7

    I literally just finished watching your Native API video and now you upload this, - literally GOD.

  • @gamerkarir306
    @gamerkarir306 11 месяцев назад +7

    omg you gave me a hart attack with the fear and hunger sound 1:25

    • @crr0ww
      @crr0ww  11 месяцев назад

      XDD

  • @sxmourai6897
    @sxmourai6897 11 месяцев назад +5

    I'm currently making an os and it's great to see the point of view of the userland people on the other side =)
    + I've learned some stuff, it's grealty explained, continue like that !

    • @crr0ww
      @crr0ww  11 месяцев назад

      thank you so much! :)

  • @Raxis
    @Raxis 11 месяцев назад +2

    Hell yes another crow video! Still need to go back and catch up on the previous vid but it's great seeing more stuff from you!

  • @jaitjacob
    @jaitjacob 11 месяцев назад +9

    babe wake up crow just uploaded a new malware video

    • @crr0ww
      @crr0ww  11 месяцев назад +1

      WAKE BABE UP, WE HAVE MALWARE TO MAKE

  • @UnhandledErrorWasTaken
    @UnhandledErrorWasTaken 11 месяцев назад +5

    Man!!! Finally a new video :D Didn't still watched it entirely but it's obviously gonna be fantastic. Ik doing this videos takes time and commitment but please do them more often ahah!

    • @crr0ww
      @crr0ww  11 месяцев назад +2

      thank you so much!! yeah it's a ton of work but your response(s) make all of the grey hairs super worth it :)

  • @t32prod.98
    @t32prod.98 11 месяцев назад

    just came across your page by pure chance and watched your processes, handles, and threads video. headed over to your website and your statement in the faq section was very wholesome and encouraging. thank you for documenting your journey and having a positive outlook for newcomers :) deff earned my sub and a bookmark to your blog.

  • @bamboooz3201
    @bamboooz3201 11 месяцев назад +29

    I am a web developer, i don't understand anything, but i love these videos, keep it up!

    • @crr0ww
      @crr0ww  11 месяцев назад +2

      aw thank you

  • @deleted_account-u3w
    @deleted_account-u3w 11 месяцев назад +2

    Your videos are so good, my tiny brain can finally understand all this stuff. Keep it up!

  • @QnF5EPuArXEX3bP
    @QnF5EPuArXEX3bP 9 месяцев назад

    I've just discovered your channel and OMG keep it up man, you're a GEMMMM

  • @tablettablete186
    @tablettablete186 11 месяцев назад

    This is why we need syscall kernel interception like we do in Linux with SECCOMP.
    Great video by the way!

  • @Babachick3n
    @Babachick3n 4 месяца назад +1

    Literally the Dale Philip of the hacking world

  • @4sakenGol3m
    @4sakenGol3m 9 месяцев назад

    Your LOCO❤😂 4:16 Love the content; keep up the incredible work!

  • @christian_leone
    @christian_leone 11 месяцев назад +3

    Nice vid as always crow, thanks

    • @crr0ww
      @crr0ww  11 месяцев назад

      thank you so much! i'm really happy you liked it :)

  • @phantompuma228
    @phantompuma228 11 месяцев назад +3

    NEW CROW VID?? LETS GOOO

  • @VloggerMan-if9bt
    @VloggerMan-if9bt 2 месяца назад

    seeing him go from using vscode to neovim was better than watching my child grow up

  • @zombieboyxx
    @zombieboyxx 5 месяцев назад

    "If your prefrontal cortex misses a QuickTime event" 😂😂😂 you have to be the funniest cybersec youtuber

  • @vizzil1675
    @vizzil1675 11 месяцев назад

    I just finished my os class. Really love it haha

  • @azdirtnaper
    @azdirtnaper 11 месяцев назад +1

    I love watching these even though I don't understand any of the shit that is going on lmaooo

  • @rosehacksyoutube
    @rosehacksyoutube 11 месяцев назад

    Quality! Your channel is going to blow up.

  • @muha0644
    @muha0644 11 месяцев назад +4

    Man you gotta make more videos, you're the new liveoverflow but more funny and less serious.

    • @crr0ww
      @crr0ww  11 месяцев назад +1

      thank you so much for your comment; I really appreciate that! liveoverflow's the GOAT tho :')

    • @muha0644
      @muha0644 11 месяцев назад

      @@crr0ww yeah, he is!
      But ever since he started using his face on camera his videos seem too "formal" or professional. More like John Hammond, but if he was German I guess...

  • @MeharKlair
    @MeharKlair 11 месяцев назад +3

    He's finally back after his hibernation

  • @jonas-ke4qz
    @jonas-ke4qz 5 месяцев назад

    This editing is awesome

  • @dadamnmayne
    @dadamnmayne 11 месяцев назад +5

    Thank you. Prob going to watch this at least 100 times.

    • @crr0ww
      @crr0ww  11 месяцев назад +1

      i appreciate you, brother! thank you so so much

    • @dadamnmayne
      @dadamnmayne 11 месяцев назад

      @@crr0ww 19:01 that API hooking/unhooking video tho... 🙏

  • @madezra64
    @madezra64 11 месяцев назад

    What's the music at 11:50? Starts a little earlier then that but Shazam as failing me cause it's copyright free music :(

  • @nobody-m6f
    @nobody-m6f 3 месяца назад

    what is the fond and IDE that you are using?

  • @EnLopXf
    @EnLopXf 11 месяцев назад +2

    Yow the legend is back!!

  • @11superjump
    @11superjump 11 месяцев назад +2

    this video taught me a lot, love it :)

    • @crr0ww
      @crr0ww  11 месяцев назад

      ah, great!! that means i've done my job haha thank you so much for commenting

  • @gwnbw
    @gwnbw Месяц назад

    Hows your font so smooth looking though? mine looks crispy like extra sharpened

  • @faanross
    @faanross 11 месяцев назад +3

    He’s back!

    • @crr0ww
      @crr0ww  11 месяцев назад +1

      hey!! thank you so much for commenting, brother! i LOVE your videos as well, such a unique style! keep up the GREAT work, you'll get really far I can already tell

    • @faanross
      @faanross 11 месяцев назад

      @@crr0ww 🖤

  • @HelpersSoftware
    @HelpersSoftware 11 месяцев назад

    Awesome ❤ Thanks!What a theme name in visual studio bro?

  • @alec3217
    @alec3217 11 месяцев назад +3

    LESS FUCKING GOOOOOOOOO, new crow vid

    • @crr0ww
      @crr0ww  11 месяцев назад +1

    • @alec3217
      @alec3217 11 месяцев назад

      @crr0ww do you have a discord server or something similar?

  • @lime5233
    @lime5233 11 месяцев назад +2

    FINALLY A VIDEO

  • @czerwonejakmleko401
    @czerwonejakmleko401 11 месяцев назад

    does anyone know what font he uses?

  • @arnabthakuria2243
    @arnabthakuria2243 11 месяцев назад

    Great vid as always. What font is that ?

  • @HTWwpzIuqaObMt
    @HTWwpzIuqaObMt 11 месяцев назад +2

    Welcome back ❤

  • @Negalijus370
    @Negalijus370 11 месяцев назад +2

    Inspiring next generation of Greybeards ⚡⚡

  • @honestsniping1
    @honestsniping1 11 месяцев назад

    Aren't all variables saved in the .TEXT section either way? Why did he manually added that code at 29:00?

    • @nikhilt3755
      @nikhilt3755 10 месяцев назад

      variables go into .data section.
      if we specify to allocate in .text section then contents of our variable can be executed because .text section is executable by default

    • @honestsniping1
      @honestsniping1 10 месяцев назад

      Thanks for the reply. But if I define the shellcode variable inside main(), it will be located in .TEXT and not .DATA. And after your logic, it would mean that shellcodes defined in the global section of the program (not within main) cannot be executed.
      I'm probably missing something here...

  • @gwnbw
    @gwnbw Месяц назад

    27:54 lowkey flex, interesting vids!

  • @MeharKlair
    @MeharKlair 11 месяцев назад +2

    CROW SIR SIR CROW YESSSSSSSSSSSSSS

  • @noorkhara1429
    @noorkhara1429 11 месяцев назад +2

    HES BACKKKKK !!!!! 🎉🎉🎉🎉

  • @tracetv8115
    @tracetv8115 11 месяцев назад

    A video about antivirus intrusion would be nice.

  • @ferverrel5519
    @ferverrel5519 11 месяцев назад

    Used your promo for the maldev academy baby!

  • @mnesicles.
    @mnesicles. 11 месяцев назад

    Sos un capo cuervito. Excelente contenido ✨

  • @D3x7er0
    @D3x7er0 11 месяцев назад +2

    _

    • @crr0ww
      @crr0ww  11 месяцев назад +1

      HAHAHAHA LETS GOOOOO i wrote it down on some sticky notes so I don't forget it again :')

    • @D3x7er0
      @D3x7er0 11 месяцев назад

      @@crr0ww 😂♥

  • @Trikstarck
    @Trikstarck 11 месяцев назад +2

    Let’s GOOOOOO 🎉🎉🎉🎉🎉🎉

  • @korsate
    @korsate 11 месяцев назад +2

    YAYAYAYAYAYA MY GOAT UPLOADED

  • @hiddengo3232
    @hiddengo3232 9 месяцев назад

    how to modify exploit code

  • @stolfoch.
    @stolfoch. 11 месяцев назад +2

    mr crow i love you

  • @ProtogenPilled
    @ProtogenPilled 11 месяцев назад

    CROW WHERE HAVE YOU BEEN
    I MISS YOU LOVE

  • @ericytff7388
    @ericytff7388 11 месяцев назад

    MORE TUTORIALLS WE SHALL SEE

  • @gordonfreimann
    @gordonfreimann 11 месяцев назад

    whats your font in vs?

  • @Beryesa.
    @Beryesa. 11 месяцев назад +2

    Operation Tux continues 😅

  • @vesmirnyjay
    @vesmirnyjay 11 месяцев назад +2

    touching everything

    • @crr0ww
      @crr0ww  11 месяцев назад

      😭

  • @meharklair3755
    @meharklair3755 11 месяцев назад +2

    i would like to inject my malware into crow :3

    • @crr0ww
      @crr0ww  11 месяцев назад

      BAHAHAHAHAHA

  • @meharklair3755
    @meharklair3755 11 месяцев назад +2

    CROW CROW CROW

  • @dompurified
    @dompurified 11 месяцев назад

    mom, look! cr0w uploaded!

  • @PlanetComputer
    @PlanetComputer 11 месяцев назад +2

    thanks crow

    • @crr0ww
      @crr0ww  11 месяцев назад

      it's my pleasure

  • @dneial.
    @dneial. 11 месяцев назад

    Can anyone link the equivalent of this but on Mac plz 🤗

  • @nightlockhayze
    @nightlockhayze 11 месяцев назад +1

    Crow why did you just ignore us and drop this new video asdjasdhakjdadasda ily always

  • @GHOST-qx6wi
    @GHOST-qx6wi 11 месяцев назад +2

    finally

  • @mohammedzaid6634
    @mohammedzaid6634 11 месяцев назад +2

    Hey crow whats up man ✋

    • @crr0ww
      @crr0ww  11 месяцев назад

      hey!! how are you :P

  • @synrage
    @synrage 11 месяцев назад +2

    finally bro

  • @brunom12111
    @brunom12111 11 месяцев назад

    that's my goat right there

  • @DM-qm5sc
    @DM-qm5sc 11 месяцев назад

    Imagine calling pantaloons trousers LuL

  • @hell0kitje
    @hell0kitje 11 месяцев назад +2

    MOB PSYCHO 100!

    • @fodk7021
      @fodk7021 11 месяцев назад

      What do you mean ?

    • @hell0kitje
      @hell0kitje 11 месяцев назад

      @@fodk7021 its anime.

    • @fodk7021
      @fodk7021 11 месяцев назад

      @@hell0kitje yes but where is it in the video.

    • @hell0kitje
      @hell0kitje 11 месяцев назад

      @@fodk7021 its in thumbail

    • @fodk7021
      @fodk7021 11 месяцев назад

      @@hell0kitje I thought it was midoriya from my hero academia

  • @DaxSudo
    @DaxSudo 11 месяцев назад

    All of this just serves my point. The NT Kernel f***ing sucks balls.

  • @illumin8-r
    @illumin8-r 11 месяцев назад +1

    all your syscalls are belong to us

  • @4sakenGol3m
    @4sakenGol3m 9 месяцев назад

    WTF 9:56 😂😂😂😂😂😂😂😂

  • @uh3906
    @uh3906 11 месяцев назад +2

    Lmao just thought about you yesterday

  • @jacobjohnson1501
    @jacobjohnson1501 11 месяцев назад +2

    heyyo you're alive ?

    • @crr0ww
      @crr0ww  11 месяцев назад

      YESSIR!!! :)

  • @raven-vr5yz
    @raven-vr5yz 11 месяцев назад +2

    yo man nice nickname

    • @crr0ww
      @crr0ww  11 месяцев назад +1

      thank you RAVEN, nice nickname as well, RAVEN :>

  • @lumikarhu
    @lumikarhu 11 месяцев назад

    a more in-depth video on indirect syscalls would be great, im not sure everything was covered, noob here. i can only cross check with the maldevs module.
    PS. i came with the power of thousand suns, you should get exclusive rights for maldev sponsoring, why watch boring jurassic park man when crow videos exist?
    lmfao please mr. d0x do this, the world will be a better place if crow becomes THE teacher. me not knowing C and low level programming well had some difficulties understanding the material but now so much has gotten clearer it's not even funny. ILY Crow

  • @snapshot8886
    @snapshot8886 11 месяцев назад +2

    Bro!!!

  • @FictionHubZA
    @FictionHubZA 11 месяцев назад +2

    Nice

  • @SpYlE-
    @SpYlE- 11 месяцев назад

    bro.. iam from bangldesh ..plzz make more video

  • @mongru
    @mongru 11 месяцев назад +2

    ah yes here i am again

    • @crr0ww
      @crr0ww  11 месяцев назад

      and i'm so happy u are

  • @sinatra02
    @sinatra02 11 месяцев назад

    a group of crows are called a murder... are we, as your fan base... murderers?

  • @cagdasisk7640
    @cagdasisk7640 11 месяцев назад

    ur the best

  • @nordgaren2358
    @nordgaren2358 11 месяцев назад

    Lmao. Urien spotted.

  • @marcelocabral389
    @marcelocabral389 6 месяцев назад

    I'm not gonna lie, i didn't understand almost anything from the video, this "layer" of execution in assembly code and things written in hexadecimal gave me a headache, great video anyway!

  • @lavender0666
    @lavender0666 11 месяцев назад +4

    hot

  • @Mika_565
    @Mika_565 11 месяцев назад +5

    Thats cool but how do I get free robux

    • @crr0ww
      @crr0ww  11 месяцев назад +3

      YOU THINK I'M AT *THAT* LEVEL, MIKA? THAT'S TOO ADVANCED FOR ME!1:$!$:

  • @lumikarhu
    @lumikarhu 11 месяцев назад

    psst hey kid, wanna buy some skooma?

  • @theexplosionist2019
    @theexplosionist2019 11 месяцев назад

    I don't understand what you're trying to achieve. You can't do "useful" functions such as virtualalloc or openprocess to modify processes' memory without admin access.
    Inline assembly works in VS2022 just fine.
    I was thinking rax is the GetProcAddress but its a special number. That makes using syscall even more pointless.
    unsigned long long count = 9;
    __asm {
    mov rax, 31H
    lea r10, count
    xor edx,edx
    xor r8d, r8d
    xor r9d, r9d
    sub rsp,40
    syscall
    add rsp,40
    }
    std::cout

  • @meharklair3755
    @meharklair3755 11 месяцев назад +2

    crow is so sexy

  • @Sp00ky__12
    @Sp00ky__12 Месяц назад

    cool ass dude

  • @Bo_om2590
    @Bo_om2590 11 месяцев назад

    do you have a job?
    what is it?

  • @imahotdogdonteatme8722
    @imahotdogdonteatme8722 11 месяцев назад +2

    Holy shit! I thought yt assasinated him!

    • @crr0ww
      @crr0ww  11 месяцев назад

      THEY GOT REALLY *REALLY* close 😓 still have more videos to make, can't stop now :')