12 ms·
NSA to Release Their Reverse Engineering Framework GHIDRA to Public at RSA
- MrXOR 8y agoIt was in CIA Vault 7 documents[1]: Its purty cool ---> Q: Is it a serious competitor for IDA Pro? [1] https://wikileaks.org/ciav7p1/cms/page_51183656.html https://wikileaks.org/ciav7p1/cms/page_51183656.html
- Thaxll 8y agoMost likely not. Since everyone uses IDA I don't think there is anything better. ( also NSA probably also use IDA )
- MrXOR 8y agoYes, right now I see that even CIA loves IDA[1]. ida is unique. [1] https://wikileaks.org/ciav7p1/cms/page_3375335.html https://wikileaks.org/ciav7p1/cms/page_3375335.html
- andrewflnr 8y agoThat's one of the more blatant ad populum fallacies I've seen in a long time.
- burfog 8y agoGHIDRA is good. In some ways it beats IDA Pro. People didn't choose IDA Pro just for quality. GHIDRA was highly restricted. Even the people with access to GHIDRA were hesitant, because they didn't want to learn a tool that they couldn't take to another employer. The other players in this market, binja (Binary Ninja) and Hopper Disassembler, are much newer. Inertia keeps them back. Imagine introducing a new editor, like vi or emacs, but with everything just a bit different. It could even be a slightly better editor. Uptake will be slow. People don't want to relearn or repurchase. Until recently, normal people could only choose IDA Pro. You paid, or you had to suffer with awful substitutes like Radare2 and objdump.
- gruez 8y ago>IDA Pro I think you meant hex-rays decompiler (which is a separate product).
- MrXOR 8y agoHex-Rays decompiler is an extension for IDA disassembler
- rdtsc 8y agoCIA bothered to get it from NSA it must be good for something, or has extra features not available in IDA Pro. Maybe they simply don't want to pay IDA Pro licenses $3k a pop. Getting an enterprise organization or the government to pay for stuff like that is not trivial sometimes. CIA also made this a standard part of a developer's setup: https://wikileaks.org/ciav7p1/cms/page_34308123.html https://wikileaks.org/ciav7p1/cms/page_34308123.html Install XCode, setup SSH, IRC, and install Ghidra ...
- JumpCrisscross 8y ago> Maybe they simply don't want to pay IDA Pro licenses $3k a pop What prevents three-letter agencies from using software without paying for it? Tendering a bid usually requires surrendering source code. One's odds of finding out about unauthorized use is slim. And even if you do, legal discovery can be blocked on national security grounds.
- JoeSmithson 8y agoThe law and personal morality, the same thing that stops almost all immoral actions in society.
- jancsika 8y agoWould this be useful for reverse engineering proprietary graphics driver and wifi driver blobs?
- JoshTriplett 8y agoHere's hoping it's actually Open Source, and not just a no-cost download of a binary-only tool.
- DonHopkins 8y agoWhich I'd immediately use to reverse-engineer itself to see if there were any back doors. Of course they'd be expecting that, so I wouldn't find any.
- yjftsjthsd-h 8y agoMy first 2 thoughts as well:) I suppose you'd need to RE it using a tool you trust. Might need to do that one, too. It's like a compiler trusting trust problem, but in reverse:)
- deleted 8y ago[deleted]
- MrXOR 8y agoIt is a Java-based framework and most probably OSS. Coming soon on https://code.nsa.gov https://code.nsa.gov and github
- burfog 8y agoOpen Source has been the plan for many years. It has been a long process, starting with determining which parts can be declassified. The current deal is some sort of FOUO, with government contractors able to run copies on non-networked computers but without all the extra high-security stuff. This will be some interesting competition for IDA Pro, Binary Ninja (binja), and Hopper Disassembler. People with access to GHIDRA have been avoiding it because they prefer to develop skills with software that can be used at all employers, but soon that thinking will favor GHIDRA. IDA Pro is a few thousand dollars, and the other choices are a few hundred dollars.
- domenukk 8y agoThrowing r2 Cutter in the mix..
- m00dy 8y agoFingers crossed
- Varcht 8y agoSome good resources to brush up on before it is released. https://www.eff.org/issues/coders/reverse-engineering-faq https://www.eff.org/issues/coders/reverse-engineering-faq https://en.wikibooks.org/wiki/Reverse_Engineering/Legal_Aspects https://en.wikibooks.org/wiki/Reverse_Engineering/Legal_Aspe...
- web007 8y agoUseful commentary from /u/hash_define on /r/ReverseEngineering: https://www.reddit.com/r/ReverseEngineering/comments/ace2m3/come_get_your_free_nsa_reverse_engineering_tool/ed7vbld/ https://www.reddit.com/r/ReverseEngineering/comments/ace2m3/...
- chc4 8y agoWow, having better typing support is a really big deal. A lot of data layout is just put ad hoc into IDA comments because their struct labeling is trash.
- uasm 8y ago> "Useful commentary from /u/hash_define on /r/ReverseEngineering:" I would say that a lot of the GH/IDA differences probably come down to UI and usability. Most of the tooling in the RE world today is lacking in those spaces. The software simply isn't "comfortable" or intuitive enough to work with. Be it IDA/olly/windbg/radare, they're all desperately lacking a proper, solid UI. The good news is, most of them support a plugin/extension architecture - so in theory, most of the features GH provides could've ended up as an IDA plugin - so that the researchers receive the best of both worlds.
- chaosite 8y agoUm, I'd expect IDA to have a better UI, being a paid commercial tool as opposed to an internal tool for the intelligence community. Not that I know anything about Ghidra yet.
- Sniffnoy 8y agoNote, this comment could really use the context option: https://www.reddit.com/r/ReverseEngineering/comments/ace2m3/come_get_your_free_nsa_reverse_engineering_tool/ed7vbld/?context=2 https://www.reddit.com/r/ReverseEngineering/comments/ace2m3/...
- johnhenry 8y agoPlease forgive my ignorance -- is this some sort of decomplier? Something more?
- gen3 8y agoThat's pretty much what it is. Its an interactive, disassembler. Its goal is to help you reverse engineer a compiled binary. From what I read, its similar to the commercial IDA Pro( https://www.hex-rays.com/products/ida/index.shtml https://www.hex-rays.com/products/ida/index.shtml ) There are a few photos on the site, to give you an idea of how everything is laid out.
- faitswulff 8y agoSomeone please tell me this is a Godzilla reference: https://en.wikipedia.org/wiki/King_Ghidorah https://en.wikipedia.org/wiki/King_Ghidorah
- Godel_unicode 8y agoClose, final fantasy: http://finalfantasy.wikia.com/wiki/Ghidra http://finalfantasy.wikia.com/wiki/Ghidra
- abledon 8y agoI think final fantasy ripped it from Godzilla (see the etymology section): """ Ghidra, also known as "King Ghidorah," is an enemy monster in the Godzilla series. Typically, Ghidra is Godzilla's fiercest opponent, and it usually fights against humanity. """"
- xvilka 8y agoI don't get an excitement. There is already IDA Pro and Binary Ninja, developing at a big pace and with actual support. Moreover, there is FOSS radare2[1] and Cutter[2], that also being developed at crazy speed. We have even work in progress decompiler radeco[3][4], though there is still a lot to be done. If people would contribute - there is a lot of time until March (time of GHIDRA release). [1] https://github.com/radare/radare2 https://github.com/radare/radare2 [2] https://github.com/radareorg/cutter https://github.com/radareorg/cutter [3] https://github.com/radareorg/radeco https://github.com/radareorg/radeco [4] https://github.com/radareorg/radeco-lib https://github.com/radareorg/radeco-lib
- leetbulb 8y agoI've used r2 extensively. It's an extremely valuable tool set. Thank you and everyone else for the amazing work! I am very excited for its future.
- fortenforge 8y agoSurely you can see how something that combines the best of both worlds (FOSS like r2 and feature-rich / has a working decompiler like IDA / binja) would be of interest to people right?
- xvilka 8y agoRSA talk description never said anything about open sourcing it. Only about "free". And from WikiLeaks Vault7 documents it appears to be buggy.
- openloop 8y agoWhere will this be released? Repository?
- MrXOR 8y agoRobert Joyce (NSA): The GHIDRA platform includes all the features expected in high-end commercial tools, with new and expanded functionality NSA uniquely developed
- MrXOR 8y agoCharlie Miller (Apple Mac hacker and former NSA employee): This tool was already there when I left 13 years ago!
- appleflaxen 8y agothe nsa would never release cutting edge tools that had functionality unavailable in other forms.
- MrXOR 8y agoCertainly, Maybe revealed of CIA Vault7 is the reason!
- based2 8y agoWill it benefit to Radare2 and Frida? https://github.com/dukebarman/awesome-radare2 https://github.com/dukebarman/awesome-radare2 https://github.com/dweinstein/awesome-frida https://github.com/dweinstein/awesome-frida
- burfog 8y agoNo. It will make Radare2 completely obsolete.
- djmips 8y agoWhat is their motivation for releasing this now?
- linkregister 8y agoIt's been in the works for at least 5 years.
- sgc 8y agoWhat is their motivation to release this? It's not like SELinux where improving general security can be seen as a national security objective.
- FakeComments 8y agoHaving a more robust reverse engineering community seems like it would be a national security objective, in a broad sense. This tool lowers the bar for security researchers to analyze malware, and seems to be part of a broader effort by the NSA to share their tools and foster public-private partnerships.