IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to...
9
IDA Pro Grant Uland
-
Upload
julius-morrison -
Category
Documents
-
view
215 -
download
0
description
How does it work? IDA takes a.exe and generates 4 files – Name.id0: B-tree style database – Name.id1: Flags describing program bytes – Name.nam: Index of program locations – Name.til: local type definition info
Transcript of IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to...
![Page 1: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/1.jpg)
IDA Pro
Grant Uland
![Page 2: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/2.jpg)
What is IDA Pro?
• Interactive Dissassembler– Reverse Engineering
• Used to turn .exe binary to machine code
• While Expensive, IDA Pro is considered by many to be the best availiable– Professional License = $1129– Or free… if you’re sneaky
![Page 3: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/3.jpg)
How does it work?
• IDA takes a .exe and generates 4 files– Name.id0: B-tree style database– Name.id1: Flags describing program bytes– Name.nam: Index of program locations– Name.til: local type definition info
![Page 4: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/4.jpg)
![Page 5: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/5.jpg)
What do you get?
• An incredibly complex program flow graphical interface
• Function Window• Hex view of the instructions• Imports, strings and enumerations
![Page 6: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/6.jpg)
![Page 7: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/7.jpg)
![Page 8: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/8.jpg)
![Page 9: IDA Pro Grant Uland. What is IDA Pro? Interactive Dissassembler Reverse Engineering Used to turn.exe binary to machine code While Expensive, IDA Pro.](https://reader036.fdocuments.us/reader036/viewer/2022082801/5a4d1bad7f8b9ab0599cb70c/html5/thumbnails/9.jpg)
Source
• http://resources.infosecinstitute.com/basics-of-ida-pro-2/