Searching for instructions and opcodes is a basic necessity for security researchers, therefore to address this issue IDA Pro provides many search facilities, among them we list: Text search: Used to search the listing for text patterns (regular expressions are allowed). One can write a regular expression to find any assignment to the eax register (with […]
Read MoreWith IDA, one can use the command line interface (CLI) not only to type scripting related commands but also to send debugger specific commands to the current debugger plugin. Although the topic mentions device drivers, you do not have to know much about drivers to learn something new from this post.
Read MoreJust a quick post to share the joy of having more expressiveness and freedom in IDA Pro. A few days ago we implemented a JavaScript plugin. This means that there is yet one more languauge to write scripts in IDA, and a very powerful one. All usual methods of accessing the language work: you may execute […]
Read MoreHalvar and Dennis Elser recently blogged about a serious vulnerability in the ATL libraries. A few days ago, Microsoft released an emergency “out-of-band” patch. Yes, the bug was that nasty, and since it is in a library, many MS Windows components were affected. Everyone who used the library should review their code and […]
Read MoreIDA Pro already has a function call graph facility, nonetheless it employs WinGraph32.
Read MoreIDA Pro 5.5 We are happy to announce a new version of IDA Pro! The major news is the new docking user interface. There are many other improvements: processor modules, file formats, analysis tweaks, well, the usual stuff. There is a new MS Windows Crash Dump Loader and improved Bochs debugger. The complete list of new features and bug fixes […]
Read MoreAfter many months of work, IDA Pro 5.5 is now in alpha stage and this week the beta will be out for testing.
Read MoreJust a quick note for interested parties: we prepared the new demo version of IDA Pro. The new demo includes the bochs debugger. The debugger is fully functional with just one limitation: it will become inactive after a number of commands. I prefer to tell you this in advance rather than this limitation to be […]
Read MoreWe have already published short tutorial on Windows kernel debugging with IDA and VMWare on our site, but the debugging experience can still be improved. VMWare’s GDB stub is very basic, it doesn’t know anything about processes or threads (for Windows guests), so for anything high-level we’ll need to do some extra work. We will show […]
Read MoreSince the number of debugger modules in IDA surpassed the magical number seven plus or minus two, we created a small table describing what is available and what is not: http://www.hex-rays.com/idapro/debugger/index.htm Direct links to tutorials are available here: http://www.hex-rays.com/idapro/idasupport.htm I know, I know – we need to add 64-bit support for all platforms, port the Bochs […]
Read More