freeoks / SD0_reader

Program for reading Mayhem hidden filesystem
6 stars 3 forks source link

Possibly syntax issue? #1

Open viceroyx1 opened 9 years ago

viceroyx1 commented 9 years ago

First, thanks for the contribution of this tool. I'm trying to run it using this command:

./read_sd0 -f .sd0 -d test and I get the following error:

FAT_FS: Error could not load FAT details (-3)! ERROR: Media attach failed

When I checked the -h option I see that after the -f is "fat_container".

What is the script expecting there?

smx-smx commented 8 years ago

The malware can have different XTea Deltas and key step, because it's apparently distributed in different variants. On the one i came across i had a delta of 0x2F26F3C0, and a step of 0x4686C862