3 ms·
> So I was able to use the utility to discover and defeat the trial protection of itself. This is why I used to feel bad for Hex Rays / IDA Pro. When your prod
by Benjamin_Dobell 5y ago
> So I was able to use the utility to discover and defeat the trial protection of itself.
This is why I used to feel bad for Hex Rays / IDA Pro. When your product is a disassembler, there's bound to be someone in your target audience capable of cracking your software.
P.S. Don't use a cracked IDA Pro. Checkout Hopper instead. It's reasonably priced and really solid software. Been using it on and off for years.
- emidln 5y agoCracking IDA Pro used to be part of the experience.
- stevekemp 5y agoFor me it was Numega's SoftICE, which was an amazing debugger. Using it to defeat it's own protection always struck me as ironic, but I guess also to be expected. I hacked software for many years, for my personal amusement rather than profit, as it always reminded me of being a teenager hacking games for infinite lives, etc. Now and again I take a stab at commercial linux software, but there isn't so much out there with the standard "Enter License Key" kinda protection.
- takeda 5y ago> as it always reminded me of being a teenager hacking games for infinite lives, etc Now you have Cheat Engine[1] specializing just on that [1] https://cheatengine.org/ https://cheatengine.org/
- mike_d 5y agoMy Google-fu is failing me at the moment, but I remember a piece of malware actually included the copyright string of a disassembler so it would detect "itself" and not let you analyze the malware sample.
- robertlagrant 5y agoGoing to show just how rudimentary said scanning is sometimes.
- grover12 5y agoHey mike_d, I remember this as well. Using my google-fu, I found it. Google: "hopper disassembler" copyright text OR string https://alexomara.com/blog/a-silly-anti-disassembly-trick/ https://alexomara.com/blog/a-silly-anti-disassembly-trick/ backup links: https://web.archive.org/web/20210830080742/https://alexomara.com/blog/a-silly-anti-disassembly-trick/ https://web.archive.org/web/20210830080742/https://alexomara... https://archive.is/uzga3 https://archive.is/uzga3
- Benjamin_Dobell 5y agoFrom the article: > One of the limitations to at-least the demo of Hopper is that it is not able to disassemble itself. I was curious as to whether this limitation was present in the latest licensed version of Hopper (4.8.2). I can confirm that I can indeed disassemble Hopper itself. Whether there's some intentional mistakes in that disassembly I don't really have time to delve into, unfortunately.
- rurban 5y agoNope, ghidra. Better disassembler
- Namidairo 5y agoThe inbuilt vtable detection is nice, you don't have to remember to update and run Class Informer every time you want to look at a vtable...
- jonpalmisc 5y agoI'd suggest checking out Binary Ninja [1] as well. Also reasonably priced and very solid, but available on all platforms --- not to mention having a much nicer UI and API than all the other tools out there. [1] https://binary.ninja https://binary.ninja Disclosure: I'm currently an intern working on the product.