4 ms·
Ask HN: What software do you use to examine binary files?
Of course a simple hex editor or even xxd will easily show you a hex/ascii representation of a binary file. But is there any good software that understands many binary formats and can for example show me what header values a gzip file contains?
I think a terminal application that understands this for many different formats and easily allows you to add more formats would be very helpful
- alex14fr 4y agoI never used it but GNU poke http://www.jemarch.net/poke http://www.jemarch.net/poke seems like what you're looking for.
- spaintech 4y agoI did not remember that one… great suggestion!
- spaintech 4y agoHexdump, xdd, Binwalk, Binary Ninja, and Ghidra, along with a good text editor that supports hex, I use vi like this: $ xxd /bin/ls | vi - /to open file : xxd -r /to save files for gzip files, extract those, that is the best representation of what’s inside IMO, then look at those binary individually. Good luck!
- deleted 4y ago[deleted]
- jaclaz 4y agoThere are a few hex/disk editors that support "templates" (but you need most times to create those yourself). Here is a sort of "curated list" of related tools: https://github.com/dloss/binary-parsing https://github.com/dloss/binary-parsing The most complete/populated I know of is Kaitai: http://kaitai.io/ http://kaitai.io/ http://formats.kaitai.io/ http://formats.kaitai.io/ that you can use with Hiew with Kiewtai https://github.com/taviso/kiewtai https://github.com/taviso/kiewtai If the question is slightly different, i.e. which bytes are used to identify a given file format, there is Trid: https://mark0.net/soft-trid-e.html https://mark0.net/soft-trid-e.html Which has also a database of known headers/patterns.
- cookiengineer 4y agoLately I've been using ImHex a lot [1], it's a modular hex editor that has schema files for different file formats which comes in handy when you work a lot on reverse engineering memdumps from firmware flash files. It also has fuzzy finding features of known file format headers, so it can also be used to recover things from dd images, though it can be laggy sometimes when walking through a couple GBs of data. [1] https://github.com/WerWolv/ImHex https://github.com/WerWolv/ImHex
- commandersaki 4y agobinwalk
- wojciii 4y agohexdump -v and less. I recently had some issues with objdump generated files and would love to have an utility which would make it easy to understand where the different sections from an elf file are in the binary (.bin file used for embedded system). I guess that I should write a script for this if it's not already present.