<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>souriz's weblog</title>
	<atom:link href="http://souriz.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://souriz.wordpress.com</link>
	<description>nezumi's den internals</description>
	<lastBuildDate>Wed, 07 Jan 2009 02:41:01 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='souriz.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/7e262a1e5e601a19d92b3cdec01f286a?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>souriz's weblog</title>
		<link>http://souriz.wordpress.com</link>
	</image>
			<item>
		<title>blog was moved</title>
		<link>http://souriz.wordpress.com/2009/01/07/blog-was-moved/</link>
		<comments>http://souriz.wordpress.com/2009/01/07/blog-was-moved/#comments</comments>
		<pubDate>Wed, 07 Jan 2009 02:41:01 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=67</guid>
		<description><![CDATA[blog was moved  to http://nezumi-lab.org
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=67&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2009/01/07/blog-was-moved/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title>RE-courses/conferences schedule</title>
		<link>http://souriz.wordpress.com/2008/09/28/current-re-coursesconferences-scheduling/</link>
		<comments>http://souriz.wordpress.com/2008/09/28/current-re-coursesconferences-scheduling/#comments</comments>
		<pubDate>Sun, 28 Sep 2008 05:18:00 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[courses-n-trainings]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=37</guid>
		<description><![CDATA[
I offer free 3/5/10 days RE-courses for organizations and individuals (examples of the syllabuses will be published soon).
The counties, listed below, are visa-free for me (or give a visa on the border), so they are preferred.

To contact me, please, leave a comment.

Barbadoes
Belize
Colombia
Congo
Costa Rica
Cuba
Dominican Republic
Ecuador
Egypt
Fiji
Indonesia
Iran, Kish Island
Israel
Jamaica
Kenya
Maldives
Malaysia
Morocco
Myanmar
Namibia
Nepal
Nicaragua
Sesel
Sri Lanka
Swaziland
Thailand
Vietnam
Yemen

       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=37&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/09/28/current-re-coursesconferences-scheduling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title>#773: bug in IDA-Pro [fails to debug zero-based PE]</title>
		<link>http://souriz.wordpress.com/2008/05/14/773-bug-in-ida-pro-fails-to-debug-zero-base-pe/</link>
		<comments>http://souriz.wordpress.com/2008/05/14/773-bug-in-ida-pro-fails-to-debug-zero-base-pe/#comments</comments>
		<pubDate>Wed, 14 May 2008 14:14:30 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[bugs]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=25</guid>
		<description><![CDATA[IDA-Pro embedded debugger doesn&#8217;t support PE files with zero image base.
the debugger says (I quote):
&#8220;IDA Pro couldn&#8217;t automatically determine if the program should be rebased in the database because the database format is too old and doesn&#8217;t contain enough information. Create a new database if you want automated rebasing to work properly. Notice you can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=25&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/05/14/773-bug-in-ida-pro-fails-to-debug-zero-base-pe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title># Syser causes BSOD</title>
		<link>http://souriz.wordpress.com/2008/05/09/syser-causes-bsod/</link>
		<comments>http://souriz.wordpress.com/2008/05/09/syser-causes-bsod/#comments</comments>
		<pubDate>Fri, 09 May 2008 06:43:15 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[bugs]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=24</guid>
		<description><![CDATA[a new bug in Syser was found. download this file, unpack it and run make-all-and-run.bat.
under XP SP2 with Syser we have BSOD:
# BugCheck 100000D1, {45b0, ff, 0, f580aa75}
# Probably caused by : Syser.sys ( Syser+aa75 )
# DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
this is _very_ strange, since the program causes crash &#8211; is a user-mode application, or, to be exactly, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=24&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/05/09/syser-causes-bsod/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title># old CD 03 bug in windows</title>
		<link>http://souriz.wordpress.com/2008/05/09/old-cd-03-bug-in-windows/</link>
		<comments>http://souriz.wordpress.com/2008/05/09/old-cd-03-bug-in-windows/#comments</comments>
		<pubDate>Fri, 09 May 2008 05:09:07 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[bugs]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=23</guid>
		<description><![CDATA[coming soon!
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=23&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/05/09/old-cd-03-bug-in-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title># turbo-import [stealth anti-api-monitors style]</title>
		<link>http://souriz.wordpress.com/2008/05/09/turbo-import-stealth-anti-api-monitors-style/</link>
		<comments>http://souriz.wordpress.com/2008/05/09/turbo-import-stealth-anti-api-monitors-style/#comments</comments>
		<pubDate>Fri, 09 May 2008 05:07:33 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[optimization]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=22</guid>
		<description><![CDATA[coming soon!
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=22&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/05/09/turbo-import-stealth-anti-api-monitors-style/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title># bug in Olly, Windows behavior and Peter Ferrie</title>
		<link>http://souriz.wordpress.com/2008/05/09/bug-in-olly-windows-behavior-and-peter-ferrie/</link>
		<comments>http://souriz.wordpress.com/2008/05/09/bug-in-olly-windows-behavior-and-peter-ferrie/#comments</comments>
		<pubDate>Fri, 09 May 2008 04:58:17 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[bugs]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=21</guid>
		<description><![CDATA[PeterFerrie strongly disagreed with me, pointed out, that this is not only the Olly bug.
https://www.openrce.org/forums/posts/775#2715:
The not a problem in OllyDbg, it&#8217;s a Windows behavior. Try it without any debuggers and you will see the same thing. I found the same while researching my new paper.
https://www.openrce.org/forums/posts/775#2720:
If you set the trap flag then cause an access exception, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=21&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/05/09/bug-in-olly-windows-behavior-and-peter-ferrie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title># eternal life, ammo, scores in games</title>
		<link>http://souriz.wordpress.com/2008/05/07/eternal-life-ammo-scores-in-games/</link>
		<comments>http://souriz.wordpress.com/2008/05/07/eternal-life-ammo-scores-in-games/#comments</comments>
		<pubDate>Wed, 07 May 2008 12:10:31 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[Soft-Ice tips-n-tricks]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=20</guid>
		<description><![CDATA[a man asked me how to find where games keep scores, eternal life or ammo. the answer is simple and I doubt is it worth to be published here or not. well, let&#8217;s try and see.

as a general rule, scores are stored &#8220;as is&#8221;, I mean: if you have 666 scores, some memory cells keep [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=20&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/05/07/eternal-life-ammo-scores-in-games/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title># thinking in IDA Pro &#8211; how to obtain a copy</title>
		<link>http://souriz.wordpress.com/2008/05/05/thinking-in-ida-pro-how-to-obtain-a-copy/</link>
		<comments>http://souriz.wordpress.com/2008/05/05/thinking-in-ida-pro-how-to-obtain-a-copy/#comments</comments>
		<pubDate>Mon, 05 May 2008 03:43:21 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[IDA-Pro tips-n-tricks]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=19</guid>
		<description><![CDATA[wow! I see some ppl ask google for &#8220;thinking in IDA Pro&#8221; and feel obligations to say: this book was written in rus and never translated to eng. the exactly name is &#8220;образ мышления &#8211; IDA&#8221; (obraz mishleniya &#8211; IDA). it&#8217;s quite obsolete now, however, if you know rus and don&#8217;t mind to download less [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=19&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/05/05/thinking-in-ida-pro-how-to-obtain-a-copy/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>
	</item>
		<item>
		<title># bug in Process Explorer (a gift for malware)</title>
		<link>http://souriz.wordpress.com/2008/05/04/bug-in-process-explorer-gift-for-malware/</link>
		<comments>http://souriz.wordpress.com/2008/05/04/bug-in-process-explorer-gift-for-malware/#comments</comments>
		<pubDate>Sun, 04 May 2008 15:34:00 +0000</pubDate>
		<dc:creator>souriz</dc:creator>
				<category><![CDATA[bugs]]></category>

		<guid isPermaLink="false">http://souriz.wordpress.com/?p=15</guid>
		<description><![CDATA[years ago I found a bug in Process Explorer tool, written by Mark Russinovich. well, not a bug, just misfeature :) Process Explorer tries to determine the start address of a thread, but does this wrong and under certain conditions gives us an incorrect result. I sent a report to Mark, but had got no [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=souriz.wordpress.com&blog=3529444&post=15&subd=souriz&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://souriz.wordpress.com/2008/05/04/bug-in-process-explorer-gift-for-malware/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/82b04f5cc4eba668c179c35a25733865?s=96&#38;d=identicon" medium="image">
			<media:title type="html">souriz</media:title>
		</media:content>

		<media:content url="http://souriz.files.wordpress.com/2008/05/procexp-bug-01.gif" medium="image" />
	</item>
	</channel>
</rss>