11 ms·
Ghidra: A software reverse engineering suite of tools developed by the NSA
- flcl42 5y agoWARN2042: The tool when compiled may have recognizable signature that raises installation of additional spyware by compromated operating systems.
- NotSwift 5y agoIt is open source software and it can reverse engineer programs from a lot of different systems. Some people may be worried about installing a piece of software on their computer that comes from the NSA. I don't think that there are real reasons to worry. One of the tasks of the NSA is defending against cyber attacks. Having more people with good tools helps the defense. Also, you can be pretty certain that some security people have been closely looking at the sources to see if it contains any suspicious features. Besides, if the NSA really wants to install some software on your computer, they can probably do it themselves without your involvement.
- raxxorrax 5y agoI don't think there is anything fishy here, although I don't think the NSA can just install anything on my computer, even if I were based in the US. There is a lot of bluffing when it comes to cyber security. Still it might be quite a useful tool.
- NotSwift 5y agoThere has been a lot of cyber crime in recent years, e.g. see the recent wave of ransomware attacks. These criminals are mostly amateurs that know some exploits and use them. The NSA is a huge organization that employs many professional experts. Spying is one of their main objectives so you can be pretty certain that they are pretty good at it. Computer systems contain a lot of vulnerabilities and you can be pretty certain that they know a lot of them. The computers of most people are vulnerable even to normal cyber criminals, the NSA is a lot more powerful.
- inlikealamb 5y agoMost of their work probably doesn't even need to be technical. How many high-profile attacks have been based on social engineering?
- killjoywashere 5y agoMost people hear "social engineering" and think of someone playing journalist to get access to places. The NSA's idea of social engineering is having the CIA work with the BND to buy Crypto AG.
- inlikealamb 5y agohow many "former" government employees work at Google?
- NotSwift 5y agoSocial engineering can be highly effective. However, from what we know about the NSA, especially from the Snowden leaks, it appears to be mainly a technical agency. It seems likely that the NSA does not use social engineering on a large scale itself but hands it off to other agencies like the CIA or the FBI.
- nix23 5y ago>although I don't think the NSA can just install anything on my computer If it's not connected to a network you are probably right....otherwise 100% wrong, if your a enough valuable target. And just lets say for fun your OS is 100% bulletproof, your +30 firmware's are not.
- raxxorrax 5y agoI doubt it. From operations that went public the attack vectors are known and you can extrapolate something about their capabilities. Of course they could get access if I were a valuable target, but that might just as well be with a large wrench. But they cannot just take control of any device. And I think many companies might even have better capabilities. Or defense, since intelligence work is very often about industrial espionage.
- nix23 5y ago>From operations that went public Are you talking about Snowden's powerpoint slides or the Shadow Brokers arsenal?
- atatatat 5y agoWisen up.
- killjoywashere 5y agoYou don't even exist to them. The NSA wants to infiltrate nations. They do stuff like hire a friendly foreign nation to quietly buy a security company their target depends on and then exploit that vulnerability from a host in a fourth nation.
- NotSwift 5y agoThe NSA is an agency with a yearly budget of approximately 10 billion dollars. There are not many companies that can match that.
- nextlevelwizard 5y agoWhat’s with the doomer mentality. NSA isn’t some magical unicorn that can just walk through everything
- o8r3oFTZPE 5y ago"There is a lot of bluffing when it comes to cyber security." I wish this topic received more discussion.
- nix23 5y agoYes we can talk about that, let's start with the FSB an why they are always so stupid ;) to left the compilation time with the working-hours of moscow and the cyrillic keyboard in the compiled binary.
- imwillofficial 5y agoIt’s almost as if it’s not the FSB… but somebody making it look like it was… (See the Vault7 leak attribution masking)
- ragona 5y agoI’m quite sure they could, but mostly just because they could simply walk into your house and tamper with the hardware. You don’t need a fancy zero day when you’re the government.
- klyrs 5y agoFunny thing about lockdown/wfh4l... they're really gonna wait a while to get in
- rytis 5y agoTurn up with a bunch of fire engines, and a gas company van. Knock on your door, and 3-4 neighbors on each side, for good measure. Tell there's been a report of a gas leak, and you need everyone to leave their houses/apartments immediately for the inspection. 15-20 mins later - you can come back in, all's safe. Thank you for your cooperation.
- user3939382 5y agoIf they could install a virus on Iran's air-gapped uranium centrifuge industrial control systems, I'm pretty sure they could get one on your computer.
- bitsculpt 5y agoyeah but I just finished doing a security update /s
- nextlevelwizard 5y agoBribing people in generally corrupt and poor countries to smuggle a USB stick is kind a different than just breaking into random persons home in a country with relatively low corruption. Latter might actually be more difficult. Obviously depends on what your end goal is
- ozfive 5y agoEver heard of a bump key? It's easy to break into a home in a country with relatively low corruption. One might even say easier. It just comes down to whether you have one person corrupt enough to use it. A locked door is nothing more than a social contract. Door is locked means do not come in. Tell that to the person with a bump key.
- arthurcolle 5y agoPassing an infected USB stick to operators in poorer countries (as you say) is hardly the most impressive part of the deployment procedure.
- nextlevelwizard 5y agobut literally the most important when you need to attack air gapped machine
- arthurcolle 5y agoNo, it's not the most important. The most important was clearly obtaining the PLC zero days to infect the physical machines. It's unclear to me why you choose to be so explicitly obtuse but in any case, for your own personal edification, feel free to read some details on how it went down - [0] https://www.wikiwand.com/en/Stuxnet https://www.wikiwand.com/en/Stuxnet [1] https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/ https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/ [1] https://www.hsdl.org/?view&did=792239 https://www.hsdl.org/?view&did=792239
- px43 5y agoI guarantee that whatever browser you use, they have 0day for it. Whatever ISP you use, they can inject traffic into it, and they have a much easier time about it if you aren't in the US. If you're someone who uses the Internet, the NSA can take over whatever you use to browse with and have their way with it. If you don't, well that's what their interdiction program is for. The thing is though, the economics of 0day indicate that the more you use it, the more likely it is that it'll get burnt, and supply is limited. They can certainly hack anyone, but it doesn't scale, so they can't simply hack everyone. They can maybe use these techniques on a handful of targets per year, so they make it count, but most of their intelligence comes from the data we all give away for free every day.
- zarzavat 5y agoIndeed the best protection against getting 0day'd is probably to be into computer security. I feel confident that the NSA is not throwing 0days at computer security professionals; whereas they could use them on the average person with little risk of detection.
- dhx 5y agoI think a lot of people underestimate how hard it would be to build something like Ghidra not from a technical perspective, but from an avoiding big organisation bureaucracy perspective. Unlike a typical bureaucracy however, and amongst other problems[1], the barrier for entry for hiring is extremely high, everything happens within an echo chamber (closed community with little external influence) and paranoia and overbearing security process has a freezing effect on morale and the use of modern workplace practices and technology. Whilst other companies and organisations hire staff quickly who can more freely experiment with the latest technology from a hip coffee shop or their home, someone at an organisation like the NSA after waiting a year to start the job and after having hiked 8km from their car to a windowless and soulless building in the middle of nowhere instead has to fill out dozens of forms and seek dozens of approvals just to consider the idea of experimenting with some new technology. I am amazed something as useful as Ghidra could actually be built within such a large bureaucracy in modern times, and then even more amazed that someone managed to get it released as open source software to ensure it continues to be maintained and useful long after the next internal reorganisation and exodus of developers. [1] https://news.ycombinator.com/item?id=16057449 https://news.ycombinator.com/item?id=16057449
- deleted 5y ago[deleted]
- karteum 5y agoThe Google Service Framework (which is installed on 99.999% of Android phones) gives a root access to Google on your device, and Google has the power to silently install/uninstall apps...
- tracedddd 5y agoI was quite suspicious of it when it was first announced, but an open source RE tool is probably the stupidest place to put a backdoor. Author considerations aside, it’s a great tool, and does pretty well with decompiling.
- thedracle 5y agoI'm amazed at how often it does better than hexrays decompiler wise. It's pretty spectacular. Radare2 has a plugin for using ghidra's decompiler too https://github.com/radareorg/r2ghidra https://github.com/radareorg/r2ghidra So you can get all of the terminal level unix like goodness of radare2, yet still get really great ghidra quality decompiler output.
- userbinator 5y agoHow well does it decompile itself? I've always considered that a great test, much like a self-compiling compiler is a notable milestone. (I believe IDA has a check to stop you from doing this. Cracking that was one of the "rite of passage" exercises back in the day.)
- rjzzleep 5y agoIsn't it written in Java? Why would it need to do that? IDA has had watermarks and all sorts of other fancy stuff. The real challenge with IDA was extending the demo to allow it to save databases before they started publishing a working older free version. I like IDA a lot more than I like all the other tools, especially since I consider the user experience and hotkeys far superior, but the other day I did look at something where the disassembly and decompilation was great compared to other tools(one of the r2+ghidra UIs). I think because flirt signatures were missing and I can't get Hexrays to sell me a new license.
- NotSwift 5y agoEven better, the NSA provides the sources which you can compile yourself: https://github.com/NationalSecurityAgency/ghidra/releases https://github.com/NationalSecurityAgency/ghidra/releases
- ShepherdKing 5y agoI would be curious to know if anyone has audited this for malicious code, or how one would go about doing that in the first place. Is that kind of software auditing a use case for Ghidra? A demo of using Ghidra to audit Ghidra would be interesting I suppose.
- pkaye 5y agoIts used to reverse engineer an unknown binary without the matching source code. Since Ghidra already is open source it be no use to audit Ghidra itself except for learning purposes. It might be useful to reverse engineer a closed source driver so you can write an open source one from scratch.
- NotSwift 5y agoA security audit is still useful when you have sources to the program. There may still be some intended or just accidental security problems with it. Having the sources makes such an audit a lot easier to do.
- ShepherdKing 5y agoIs there a standard process anywhere for vetting some software for information leakage? I would imagine that someone would deploy the software behind an MITM proxy and then look at the traffic, but it would be nice if there was some standard process or framework for this somewhere.
- aj3 5y agoIt's a huge code base, of course there are security issues. Same way IDA and radare have security issues. People who reverse malware take that into account.
- barkingcat 5y agoI would expect there to be self-mutating code such that when the open source code is compiled with a particular compiler it activates a different code path (written into the compiler itself) such that the final resulting binary does not correspond to the source code if it were compiled with another compiler. And if this resulting binary is distributed, audits of the source code wouldn't catch these modifications.
- ozfive 5y agoThese are all true statements. Greetings from Seattle, Washington, USA! No need to cc them on this post. No one should kid themselves with what NSA is working on. No one should also kid themselves with what they aren't capable of.
- bitsculpt 5y agoafter 10 years~ of lurking, your comment was the one that encouraged me to finally sign up. I agree with you completely. Let's not joke at the capabilities of a trillion dollar organization focused on "cyber". If you are fortunate enough to be a United States citizen who gets up and contributes to society on a daily basis -- you will never have anything to worry about. The NSA won't care anything about your dealings on the internet. Everyone can safely get back to their weird browsing habits and making lame comments on youtube -- no one is watching, because no one cares :)
- ozfive 5y agoWow, I'm flattered that you would sign up because of my comment! I haven't been here that long and hardly ever comment but have always kept an account for times like you describe.
- rapjr9 5y agoI can think of one concern about downloading and installing it, the NSA might be interested in who uses it. No need for anything malicious in the code, they just watch to see who downloads it.
- aj3 5y agoBut it's hosted on Github. And some distros have ghidra in official repos.
- pelasaco 5y agoprobably makes sense. I see in the government level a lot of open positions for reverse engineers.. having its own tool, helps, at least, to save money in licensing (assuming they are using or planning to use Ghidra to do that)
- cies 5y ago> Besides, if the NSA really wants to install some software on your computer, they can probably do it themselves without your involvement. Running Linux with very few binblobs, I expect they will not be able to. Running any OS published by $tax_evading_big_corp, I expect they can.
- imwillofficial 5y agoHave you seen the crazy stuff the NSA does?
- cies 5y agoLink please? I know they collect data, and have Windows backdoors.
- imwillofficial 5y ago> Documents obtained by Der Spiegel reveal a fantastical collection of surveillance tools dating back to 2007 and 2008 that gave the NSA the power to collect all sorts of data over long periods of time without detection. The tools, ranging from back doors installed in computer network firmware and software to passively powered bugs installed within equipment, give the NSA a persistent ability to monitor some targets with little risk of detection. While the systems targeted by some of the “products” listed in the documents are over five years old and are likely to have been replaced in some cases, the methods and technologies used by all the exploit products could easily still be in use in some form in ongoing NSA surveillance operations. https://arstechnica.com/information-technology/2013/12/inside-the-nsas-leaked-catalog-of-surveillance-magic/ https://arstechnica.com/information-technology/2013/12/insid... Reading their processes is so fascinating.
- kaba0 5y agoRunning linux* that has basically no security at all, good luck! A rouge extension/bash script can install whatever backdoor it wants without problem. * under linux I mean mainstream distro here. Unless you use qubes os, it will not have good sandbox, everything runs as your user and can easily modify eg. .bashrc and start up a key logger to get sudo password.
- robthebrew 5y agoI'm not sure why this is news. It is an amazing bit of kit, and cross platform. I've been using g it for many months now and highly recommend it.
- beefcafe 5y agoProbably because a new version was just released. Details here* but big news is debugger support. Looking forward to taking it for a spin. https://htmlpreview.github.io/?https://github.com/NationalSecurityAgency/ghidra/blob/Ghidra_10.0_build/Ghidra/Configurations/Public_Release/src/global/docs/WhatsNew.html https://htmlpreview.github.io/?https://github.com/NationalSe...
- e12e 5y agoThese are great release notes - I think quite a few Foss projects could draw some inspiration here.
- NotSwift 5y agoFor you it is obviously not news, but for other people it probably is. For me, HN is about learning something new, not just for learning about something that happened in the last 24 hours.
- prophesi 5y agoPotentially news to those who recently got into coding/hacking. Ghidra was leaked in '17 and made headline news. Then officially released by the NSA in '19.
- mkishi 5y agoBecause you know everything that made the headlines up to 2017? There might or might not be discussion potential on any submission, so I understand arguing about their value, but that "news if you're a beginner" was very condescending. Why not be happy about today's lucky 10,000?
- rejectedandsad 5y agoFew years in with debugger support, how does Ghidra compare to IDA?
- chc4 5y agoI like Ghidra more than IDA. Having "proper" type support is nice - IDA's struct and type annotation support always felt very hacked together and hard to use. Ghidra's typing and decompiler is good enough that I don't even have to look at the disassembly listing for most functions, and struct autogenerating is wonderful. Unfortunately, Ghidra handles vtables and OOP very poorly still. You have to do a lot of by-hand annotations for virtual calls, even with 3rd party analysis scripts, while IDA's C++ usually Just Works. This is the main pain point, imo. The other main thing is that IDA has been used by the reverse engineering community for so long that there's a massive body of tutorials and StackOverflow answers for it, and a much larger corpus of 3rd party plugins. It's not a big deal for me, personally, but if you already have a good workflow for IDA it's probably not worth it to switch. For beginners I'd recommend Ghidra instead, though, because a free and open source tool with good official documentation and UX is worth its weight in gold (although I've heard BinaryNinja is extremely good nowadays).
- bri3d 5y agoGhidra: * Affordable for sane people (aka, free)... This of course pushed Hex-Rays to finally make a cheaper version of IDA, but it's massively hobbled and useless for uncommon architectures. * Almost as good architecture coverage. Missing a few big ones for automotive RE still - SuperH is still hit and miss, and no real C167. But the user-contributed Tricore is really quite impressive. * Decompiler works across all architectures. * Debugger is still sketchy, but has progressed extremely quickly. * Preferable UI (IMO), and better struct handling. * Decent plugin interfaces but fewer available plugins. IDA: * Still slightly better decompilation and disassembly for x86-64. Doesn't get as "lost" in vtables and big switches. * Much better C++ construct support. * More plugins and scripts available off the shelf. * Still a few architectures which Ghidra doesn't have yet. * Debugger is more stable and works a bit better. For most architectures I would not start using IDA today as a hobbyist, but if I had a good IDA workflow or was joining a company where it were the gold standard, I wouldn't feel compelled to move over.
- bovermyer 5y agoI love that they named it Ghidra and use a dragon for a logo. That endears me to the people who built it.
- TheBrokenRail 5y agoI haven't used Ghidra that extensively, but it worked well when I was using it to assist in modding Minecraft Pi. The big point in its favor for me is that its free and supports ARM32, while IDA's free version only supports x86.
- motohagiography 5y agoI used this again just the other day with the cantor.dust plugin. My rev.eng skills are dull and were never great to begin with, but for anything below a real APT with obfuscation, runtime decoding and unpacking, Ghidra is an equalizer. Between this and Chef from gchq, someone with devops skills can probably skill up to an entry level threat analyst level in a few weeks or months. The tooling available today is really good. If people are worried about running systems backdoored by NSA, they probably shouldn't use things like electricity either. It's a threat actor you can't really do anything about.
- ackbar03 5y agoYou mean my electricity has been backdoored? Now that's paranoia on a different level, how does that work
- shadilay 5y agoPowerline ethernet?
- Datagenerator 5y agoSome people like me, can hear data movement on PCB's. The electrical circuit has noise signatures which change if other data is injected by Ethernet over powerline equipment. The distance from which this works is quite large, up to a few houses with consumer hardware. Fear equipment with built-in LoFi.. that's reachable without cooperation of LAN equipment..
- rembicilious 5y agoWhen you say you can “hear data movement on PCBs”, do you mean you have some kind of superhuman ability, or that you know how to use some combination of instrumentation and analysis to “hear” the data?
- shadilay 5y ago
- anonymousiam 5y agoFirst heard about this in closed channels and tried really hard to get a copy, but failed. Was pleased to discover a few years later that they had open sourced it. They're up to v10 now and it's so much better than IDA Pro/HexRays that it's probably going to put them out of business.
- gnunez 5y agoGhidra was released 2 years ago. Am I missing something?
- asddubs 5y agoversion 10 recently came out, now featuring a debugger
- xvilka 5y agoIf you want to harness the power of Ghidra decompiler but without the need of installing Java - Rizin[1][2] and Cutter[3][4] (Rizin's Qt GUI) integrate Ghidra's decompiler part that is written in C++ (libdecomp) as plugin - rz-ghidra[5]. We work currently on improving the integration and the quality of output. [1] https://rizin.re https://rizin.re [2] https://github.com/rizinorg/rizin https://github.com/rizinorg/rizin [3] https://cutter.re https://cutter.re [4] https://github.com/rizinorg/cutter https://github.com/rizinorg/cutter [5] https://github.com/rizinorg/rz-ghidra https://github.com/rizinorg/rz-ghidra
- vesche 5y agoFor anyone confused (as I was) rizin is a fork of radare2. I don't have anything constructive to say other than I'm confused why the project was forked.
- xvilka 5y agoThe reasons behind the fork are described in our FAQ[1]. TLDR: we removed everything irrelevant, not working, rewrote some pieces completely, focus on maintainability, cleaner code, easier onboarding of new contributors, better code documentation (Doxygen), better API and testing. [1] https://rizin.re/posts/faq/ https://rizin.re/posts/faq/
- orra 5y agoCreating a welcoming, and not a hostile, environment was on its own a good enough reason to fork. But also. Cutter is the first time that either Rizin or Radare has been simple enough for me, an entry level RE enthusiast, to use. So thanks.
- ktpsns 5y agoThese two tools have so much better websites as Ghidra. Thanks for putting the links!
- lnyng 5y agoThis strange looking name remind me of Ghoti: https://en.m.wikipedia.org/wiki/Ghoti https://en.m.wikipedia.org/wiki/Ghoti
- dominicjj 5y agoGhidra is a very cool utility. I used it to disassemble StarGlider for DOS - a very old fav - to figure out how the game worked. Together with the DosBox debugger I managed to create my own hack so I could play the game without being killed the whole time.
- justshowpost 5y agoI'm curious about diffs between Ghidra_PUBLIC and Ghidra_LEAKED, that's all.
- biscotte_ 5y agoCyberCHEF is another great tool coming from a “spying” agency. I dont see how GCHQ could really benefit from it as there is even a local version for those who would want to keep their data from going over the wire.
- comandillos 5y agoI used Ghidra for the first time to hack my robot vacuum. Some months later I used it to reverse engineer the on-board software of a satellite running on a SPARCv8 CPU. It worked great in both cases, can recommend.
- one_shadow 5y agoSave