adplus-dvertising
frame-decoration

Question

What is a limitation of the trap flag approach?

a.

It only detects NuMega SoftICE

b.

It can be detected by some debuggers if the detection code is being stepped through

c.

It is not possible to incorporate assembly language code into the program

d.

It increases the risk of false positives

Posted under Reverse Engineering

Answer: (b).It can be detected by some debuggers if the detection code is being stepped through Explanation:Some debuggers will only be detected if the detection code is being stepped through, in such cases the mere presence of the debugger won’t be detected as long the code is not being traced. This means that the trap flag approach can be detected by some debuggers if the detection code is being stepped through, which is a limitation of this technique.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. What is a limitation of the trap flag approach?

Similar Questions

Discover Related MCQs

Q. What is the advantage of using code checksums as an antidebugging technique?

Q. How does the code checksum technique work as an antidebugging measure?

Q. What is the downside of using code checksums as an antidebugging technique?

Q. How can the use of code checksums be optimized to minimize the impact on program execution time?

Q. What is a potential consequence of modifying the program code to make it more difficult for reversers to understand the program flow?

Q. What is the strategy of confusing disassemblers as a means of preventing or inhibiting reversers?

Q. What is the difference between linear sweep and recursive traversal in disassembly?

Q. Which type of disassembler is more reliable and tolerant of antidisassembly tricks?

Q. Which of the following is NOT a potential effect of confusing disassemblers?

Q. What is an opaque predicate?

Q. What is the difference between linear sweep and recursive traversal disassemblers?

Q. Which disassemblers can properly disassemble code with opaque predicates?

Q. What is the purpose of the pseudorandom values in the macro?

Q. Why is the LINE macro used in the macro?

Q. What is the potential downside of using too many copies of this macro in a program?

Q. Are these techniques effective at deterring experienced and determined reversers from reversing or cracking an application?

Q. What is the recommended approach for implementing powerful antireversing techniques?

Q. What is code obfuscation?

Q. What is potency in code obfuscation?

Q. What is a deobfuscator?