From someone who does binary reverse engineering full time, in my experience, BinaryNinja, Hopper, radare2, etc are toys compared to IDA Pro + Hex Rays Decompiler. The quality of the results and the features supported are unmatched... until now. I haven’t spent too much time with ghidra yet but it’s the real deal. The output of the decompiler looks alright (not complete garbage like I’ve seen with other tools). Even…
Out of curiosity what kind of job involves doing binary reverse engineering full time?
Ghidra, NSA's reverse-engineering tool
351–360 of 425 posts
Re: Ghidra, NSA's reverse-engineering tool
#352Why this is important (for those uninitiated): - Ghidra is basically the first real competitor to IDA Pro, the extremely expensive and often pirated state-of-the-art software for reverse engineering. Nothing else has come close to IDA Pro. - Ghidra is open-source, IDA Pro is not. - Ghidra has a lot of really cool features that IDA Pro doesn't, such as decompiling binaries to pseudo-C code. - It's also collaborative,…
Re: Ghidra, NSA's reverse-engineering tool
#353Earlier quoted context omitted.
Think BinaryNinja has been acting pretty effectively as a competitor to IDA Pro. Its much cheaper than IDA, has a good API and I have been a very happy customer.
And they didn't take my money, break my key in an update, and ghost me while I was still in the support period. So they've got that going for them.
Re: Ghidra, NSA's reverse-engineering tool
#354Pretty impressive software though. Finally one strong open-source alternative for reverse engineering.
Re: Ghidra, NSA's reverse-engineering tool
#355Earlier quoted context omitted.
Did they ever tell you why they did that? I'd like to hear the rest of this story, I was considering buying IDA Pro (though these days I'm having a lot of fun adding M68k support to Avast's Retdec)
No, they never replied at all. Their self-service site broke and they completely and utterly ignored my emails to the associated service address and to a number of other addresses posted on their site. I grew up using, ah, other methods of satisfying my need for an interactive debugger and those methods continued to be viable after giving hex-rays $1100 and getting flaked, so I wasn't materially impacted by the flake…
Just searched for your username in our chat and our email and don't see anything so I assume you've got a different email?
Re: Ghidra, NSA's reverse-engineering tool
#356Earlier quoted context omitted.
If your Red team is reversing binaries you’re doing it wrong.
Why? If your real world adversaries can reverse binaries, why would you shackle a Red team from doing so?
Re: Ghidra, NSA's reverse-engineering tool
#357Earlier quoted context omitted.
Retdec is based in part on Capstone, like Hopper.
I believe Capstone is merely a disassembly framework, and retdec's decompilation process is custom implementation which works on LLVM IR.
Re: Ghidra, NSA's reverse-engineering tool
#358Earlier quoted context omitted.
And they didn't take my money, break my key in an update, and ghost me while I was still in the support period. So they've got that going for them.
I'm sorry you had a bad experience. This is the first I've heard about it! We normally get nothing but praise during any customer support interaction. Feel free to email me directly (jordan at vector35 com) with your email address so I can try to figure out what happened. Apologies it didn't go well.
Re: Ghidra, NSA's reverse-engineering tool
#359Earlier quoted context omitted.
Think BinaryNinja has been acting pretty effectively as a competitor to IDA Pro. Its much cheaper than IDA, has a good API and I have been a very happy customer.
And they didn't take my money, break my key in an update, and ghost me while I was still in the support period. So they've got that going for them.
Re: Ghidra, NSA's reverse-engineering tool
#360Earlier quoted context omitted.
Hunting for bugs to report would be a valid, wouldn't it?
Not if you're oracle.
https://www.zdnet.com/article/oracle-to-sinner-customers-rev...