12 ms·
NSA Ghidra software reverse engineering framework
- motohagiography 4y agoThere's a discouragment the comes in the RE community that to be useful at all you need to be able to write your own exotic packer decoders, but I use Ghidra about once a month for really basic security incident response to pull apart "driver" installer packages to see where they are phoning home to, evaluating enterprise vendor-ware packages looking for hard coded credentials and snoopy telemetry, sometimes I can pull down the second stage of a phishing attempt against one of our users and RE it just to see what the level of sophistication the attackers having a go at us are at, and I've used the cantor dust plugin to quickly find sections of compressed and encypted data in firmware images. There is no chance I will ever publish original RE research, but it's a handy go-to tool, along with cyberchef, binwalk, and some other breadth-first static analysis tools for hunting specific IoCs. I could probably teach a solid generalist who cared to get to the level of being able to dissassemble something and say, "yeah, this is dodgy" or not in an afternoon. As an exercise, next time you get a cheap peripheral like a headset or a other usb device, pop the driver installer package into ghidra and click through the call graph just to see what else it does. You may be surprised.
- boppo1 4y ago> I could probably teach a solid generalist who cared to get to the level of being able to dissassemble something and say, "yeah, this is dodgy" or not in an afternoon. Please write and post this guide.
- j-bos 4y agoI humbly second this ask.
- cancerhacker 4y agoYou can get a long way just by running /usr/bin/strings against an executable, and maybe a platform specific version of otool -L. You should have a basic idea of how your OS does linking, shared libraries, etc.
- myself248 4y agoSeriously. There's lots of "you're already a rocket scientist so let's talk details" content out there, but very little with this incredibly-useful-sounding aim. The trick is calibrating what a "solid generalist" means. I think I'd describe myself that way, but perhaps not among the HN crowd. Would be very interested in being a soundboard for such content, if that's helpful.
- motohagiography 4y agothanks! it would to take longer to write, but a basic entry point starts with what you want to know about something: who, what, when, where, why, and how. Trouble is, we tend to start with the a complete picture of How without a sense of the rest to guide us. What you want to know about a strange binary (barring obfuscation, sandbox escapes, and other nasties) is: who does it talk to (ip addresses, hostnames, sockets, etc), what does it open (files, registry entries, api's, services), when does it do these things (eg. runtime conditions, magic packets, port knocks, triggers, checking for other software), where does it write or read data (directories, filehandles, remote sites, etc), why does it do this given it's stated purpose (why does it have an encrypted section, and where is its key, is it using weird encoding to bypass filters, etc.) and then finally the How it does these all things is the effect of answering those other questions. I think the hardest part of analysis is having an organized way of knowing what you are looking for because we don't know the right questions to ask and we tend to work at the edge of limited knowledge. Should this rando binary be talking some app hosting site, and why? Why would a developer encode endpoint names in a lookup table that only constructs and returns them at runtime? Why would someone use any of these libraries or data formats on purpose? The harder it is to answer these questions, the more suspicious I get. If you start with the 5-W's, the How falls out of that a lot faster. If you can answer these questions about a binary, you're easily 50% there in determining whether it behaves as expected. Having an organized goal can take you from zero to basically useful if you answer those questions about it. The rest is just screenshots of menu items in ghidra and maybe cyberchef for purely static extraction. I feel like I should pile on caveats here about how most malware isn't obfuscated or using novel techniques, a lot of it is just spyware capabilities you clicked through to accept, or a repackaged legit binary with some downloaded RAT attached and some nested compressed libraries. I'm sure someone who is more serious about this will say, "that's misleadingly simple!" but once you have a why and a what, the how is a work problem. Dynamic debugging and stepping through is the next stage. It's also basic, but when you are goal oriented instead of being able to reproduce all usable code paths, it's more achievable. If you get the IP addresses out of random binary and what protocols it's talking, and maybe what files it accesses, it means you've set up your analysis environment and done the initial checks, and that's valuable grunt work you can pass on to someone with deeper skills. If you can go from zero to this, that's an afternoon well spent, imo. It's not trivial, as it assumes a lot of knowledge about system architecture and network protocols, but the questions above necessarily have answers, so I can guarantee you can find them with some directed effort. I don't mean to trivialize more advanced analysis, this isn't the same thing, but as an entry point, this is how I would recommend approaching it.
- youngtaff 4y agoYes please do Tried Ghidra for the first time on the weekend to look at some 8051 firmware Got stuck with disassembly as it seems to be misinterpreting some data sections as code - can see English strings in a hex editor but Ghidra is trying to convert them to asm
- HelloNurse 4y agoYou are supposed to annotate what every part of the file is and how you want to display it. It's usually easy to distinguish reasonable assembler code from nonsense instructions interspersed with undecodable islands. Disassembling all sections just in case they contain code is a common conservative policy for disassemblers: even without malicious payload hiding tricks even definitely never executed sections could contain embedded executable code.
- youngtaff 4y agoThanks, I'll try that approach It's been a while since I've looked at asm in anger so it's taking me a while to get back into it (plus this is a side project ATM)
- dataflow 4y agoHow dooyou tell something is dodgy from the call graph? Don't you have to decipher what FUN_918243 represents, or whatever?
- intelVISA 4y agoEasy: all nonfree software you have to decompile to view the 'source' is dodgy by design. Tools like Ghidra et al. merely lay bare the truth you already know.
- saagarjha 4y ago[flagged]
- dang 4y agoPlease don't do this here.
- saagarjha 4y agoWhat would you suggest is an appropriate response to that comment? I could of course ignore or downvote it, but I'm not sure this actually conveys my sentiment towards it.
- dang 4y agoYou can't just express unprocessed annoyance. You have to let the annoyance metabolize inside yourself until one of two things happens: either (1) you have something genuinely interesting to contribute; or (2) the need to respond goes away.
- saagarjha 4y agoOn the contrary, I have spent quite a while considering how to respond to comments like these and this was the best I could come up with. I'm open to suggestions on what I might do instead but I will point out that the current options you've put forward either 1. make it very asymmetric to respond to stupid comments or 2. allow them to proliferate, which drives away and buries interesting conversation.
- amatecha 4y agoWhat do you mean by "installer driver package", like literally the setup.exe that the vendor provides? Or like, extract the resources out of that and open _those_ in Ghidra?
- philsnow 4y agoI've seen some sketchy crap while pulling apart mac .pkg files to see their preinstall/postinstall scripts. In particular one video conferencing company's installer did some "growth hacky" things a few years ago (I checked a recent one just now and it seems benign).
- amatecha 4y agoAh yeah I remember those particular installer shenanigans for sure. Indeed, installers are often granted elevated permissions which is a perfect opportunity to drop in "extra" functionality :-O
- graderjs 4y agoCan you make a youtube video tutorial series on this? Would be great!
- neoncontrails 4y agoIs cantor dust available as a plugin now? I remember watching the creator's tech talk as a young dev and being incredibly inspired by it. But I've looked it up a few times over the years, didn't find any evidence that the tool described was ever released.
- motohagiography 4y agohttps://github.com/Battelle/cantordust https://github.com/Battelle/cantordust
- zeeshanmh215 4y agoWhat you do is very interesting and might be helpful for the budding RE's and also privacy focussed general public. Can you point me to a direction where i can learn that stuff?
- 0d0a 4y ago> There's a discouragment the comes in the RE community that to be useful at all you need to be able to write your own exotic packer decoders Unless you are talking about obfuscated / virtualized payloads, isn't it common to just "cheat" by running it in an emulator / debugger, then taking the unpacked code section from memory and work from there? It was the approach I took in a CTF task: https://nevesnunes.github.io/blog/2021/10/03/CTF-Writeup-TSG-CTF-2021-2-Reversing-Tasks.html#optimized https://nevesnunes.github.io/blog/2021/10/03/CTF-Writeup-TSG...
- motohagiography 4y agonon-ghidra example, but just the other week I was pulling apart a commercial phishing kit that had implemented its own version of AES in javascript, and then created a kind of conceptual virtual file system based on nested layers of b64 and a "custom" rot-20k encoding that turned everything into unicode, where one blob was the image with offsets, and then different parts of the malware would be pulled out and decoded and decrypted at runtime - rendering the static analysis that AV and WAF tools do useless. I used a REPL to manually do the steps you describe dynamically, but doing it statically means writing a decoder. You really need a proper sandbox to do dynamic analysis becase you don't know what's going to actually detonate, whereas static analysis gives you a whif of how off it seems, and that's sufficient for most security and privacy purposes. It was also common in Android apps several years ago now, not sure what the current state of the art is though. Android isn't my problem anymore. Officially, I suck at this and I defer to more skilled people because I am a much better writer than hacker, but when they aren't around, you go to war with the army you have. :)
- flangola7 4y agoHow do you feel about models like GPT-4 using tools like that to RE?
- amrb 4y agoIts like a summary, speeds up the process by having a possible context.
- DethNinja 4y agoGhidra is genuinely an awesome software, you don’t need to be a reverse engineering expert to use it. And with LLMs like GPT it will be able to do insane stuff like automatically analysing very complex malware. On the other hand I’m sure malware will evolve too, with LLMs you can actually directly edit the binary and add hooks to them. Cost of building firmware malware for NICs and UEFI will lower to zero dollars. Anyway I’m getting out of topic but this was something I really wanted to mention somewhere, it is likely there will be a massive amount of complex malware coming via LLMs that will potentially impact the entire economy.
- boppo1 4y agoWhat will the defense be?
- password4321 4y agoLLMs on defense too. Also, the filters on the commercial services attempting to prevent misuse. Anything useful that gets past the filters and is used to cause damage leaves behind the prompts and user account info to be subpoenaed, though it could take a while for law enforcement to come up to speed.
- amrb 4y agoApi has no filters
- yalogin 4y agoWhat's an LLM and GPT?
- l33t233372 4y agoAn LLM is a large language model. A GPT is a generative pre-trained transformer. This is a type of text generative AI model.
- amrb 4y ago
- amrb 4y agoFyi there was free OpenAI credit given out, so decided to try out ghidra with the G-3P0 plugin, imo has been fun looking around binary's with basic C experience.
- amrb 4y agoI'm loving this for syncing between RE tools, tho would be great if we had help on the supported ghidra features! https://github.com/binsync/binsync https://github.com/binsync/binsync
- mdaniel 4y agohttps://github.com/binsync/binsync/labels/ghidra https://github.com/binsync/binsync/labels/ghidra being empty likely doesn't help. I know there's likely no such thing as "claiming" an issue, but I'd much rather have "optimistic locking" than 8 people concurrently working on the same "global vars" support
- mahaloz 4y agoWell, uh, no one is working on it yet hehe. When I'm aware someone is working on something, I try to have them PR as soon as possible so a running Draft PR show's everyone it's locked. If you don't seen a draft PR, it means its up for grabs :). Honored to have anyone with extra time help out <3.
- Dwedit 4y agoFor me, the one spot where Ghidra is lacking is support for vtables (or COM objects). You can't simply feed it a C++ header file that defines the COM object.
- amrb 4y agoSilly question but was a plugin like this not enough to fix the vtable? Else do we just need a feature added or is it more involved? https://github.com/astrelsky/Ghidra-Cpp-Class-Analyzer https://github.com/astrelsky/Ghidra-Cpp-Class-Analyzer
- mdaniel 4y agoIs there an issue requesting that behavior? My guess is it'll be some onoz trying to ship a C++ parser but "you don't ask, you don't get" and asking on HN is not what I meant :-D Actually, having written that out: is there vtable support and just not C++ header parsing support, or both facets are missing?
- amrb 4y agoReading the issues [0] there is a 'prototype' script "RecoverClassesFromRTTIScript.java" to rebuild vtable's, testing on a project it does indeed resolve further. https://github.com/NationalSecurityAgency/ghidra/issues/516 https://github.com/NationalSecurityAgency/ghidra/issues/516
- biggieshellz 4y agoThe breadth of that tool is just incredible. I'm about to submit my first PR to them to fix a couple of bugs in their PEF parser (classic Mac OS PowerPC executables), but it's absolutely bonkers that they have that support to begin with, and that it all works as well as it does. I'm very pleased to see my tax dollars going to something like that.
- daveofdaves 4y agoSomehow this thing downloaded itself and that's enough
- daveofdaves 4y agoSomehow this thing downloaded itself so there's that
- lionkor 4y agoWhat do you mean?
- atribecalledqst 4y agoI've been working on a hobbyist project to analyze a ROM for an architecture that wasn't covered by Ghidra, and let me just say. I had a hellish time trying to work with Sleigh, the language you use to define new architectures for Ghidra to analyze. There just isn't a ton of great info out there about it, outside of the Sleigh documentation itself. I was able to find a few guides online but none were quite at the level of detail I was looking for. I ended up getting lucky and finding somebody else's project for the same CPU, that I was able to build on to make something that worked. And by doing that I was eventually able to figure out why I couldn't even get off the ground.
- mdaniel 4y ago> And by doing that I was eventually able to figure out why I couldn't even get off the ground. ... which I then wrote up in a gist or pastebin or Toot or Tweet so the next pour soul wouldn't have to suffer like I did is the rest of that, right?
- 0d0a 4y agoI'm also writing a processor module, and reading this is a bit encouraging to eventually write about it once it's finished. Getting off the ground wasn't the hardest part so far. You can just pick the skeleton module that already comes with Ghidra, then lookup some existing simpler modules like the one for z80 to figure out how instructions are put together. You also have the script `DebugSleighInstructionParse` to check how bits are being decoded, very useful when you screw up some instruction definitions. Unfortunately, you bump into a lot of jargon heavy error messages. The first time you hear about "Interior ellipsis in pattern", you sure have no idea what's that about. Now repeat that experience for several messages. Then the hardest challenge is how to even test the module outside of some quick disassemblies. There's `pcodetest` but the setup is cumbersome and it seems more about validating instruction decoding rather than semantics. I might just write my own validation using pcode emulation and compare the register state against another emulator's instruction trace...
- mumbel 4y agoPcodetest is more about validating the implementation of the instruction, sure it has to decode, but the benefit is most a base level set of logic that can be emulated. And definitely not a fan of the setup to get it going (also only helpful if you have a semi recent C compiler)
- steponlego 4y agoOne cool thing is the infinity dragon logo, it’s a recurring motif with other NSA projects.
- tomas789 4y agoGhidra is reasonably simple to pick up at the entry level. I use it just for fun to make a keygen for commercial software from time to time. Just to flex the muscle. My take aways are: 1/ You can do RE without knowledge of assembler (which I know nothing about) 2/ C decompiler is useful and you will need to learn some patterns of how things get disassembled 3/ There are many good videos on youtube on how to get started 4/ There is a debugger to see what the program actually does but I never managed to get it running. That would be awesome feature to use.
- Grothendank 4y agoIs ghidra safe to use if you consider the NSA an adversary? Every person I've asked this question has had their noses so far up the NSA's pooper that they could not imagine considering the NSA an adversary. But suppose you were running a malware honeypot operation for the CCP. Would you still use Ghidra? Why or why not? And please don't pass the buck and say, "I probably wouldn't be allowed to use ghidra" or "I'd probably use whatever my CCP handler told me to use" or "I wouldn't be working for the CCP in the first place." That does not inform me about the security risks of using ghidra with the NSA as an adversary.
- lovetocode 4y agoCode is right there -- just look at it.
- Grothendank 4y agoI'm looking at it. It's very beautiful code. 2,049,616 lines of it. Okay. I have looked at the code. Now what? Has that made me more secure?
- lionkor 4y agoYes https://github.com/NationalSecurityAgency/ghidra https://github.com/NationalSecurityAgency/ghidra
- Grothendank 4y agoI'm not trying to be flippant here, but how many of ghidra's 2 million lines of code have you audited?
- mumbel 4y agoIt's pretty dumb this continues to come up years later. You're the NSA delivering source code to the cyber security community. The exact community that: doesn't immediately trust NSA, knows how to find bugs, would love to find any sort of bug in their code (regardless if malicious), people you want to apply for your jobs, people you partner with (academia/other govt orgs/other country cyber security groups). So your thinking is: yes, this is the crowd we'll attempt to insert backdoor java code. Okay fine you still don't trust them? Run in a VM without network connection. What security risks/threat are you even talking about? And yes people have heavily audited the source. You either trust the community catches thing or not. I'm the end of your still tin foil about it, don't use, nobody cares.
- elif 4y agoHas anyone RE'd ghidra using another decompiler to determine whether it hides NSA backdoors etc?
- lionkor 4y ago> RE'd ghidra What, like, read the source code [1] or reverse engineered a binary? Would be easy(ish) to tell if the code in the binary was different from the source, probably. [1]: https://github.com/NationalSecurityAgency/ghidra https://github.com/NationalSecurityAgency/ghidra
- elif 4y agoBeing a large open source project is an even lower standard of transparency than a formal NIST review of a very small codebase, from which the NSA was able to hide at least one backdoor. It wasn't until use in the wild for decades revealed the ECC magic number that this vulnerability was uncovered [0]. Similarly RE has a way of investigating the actual functioning of code in a way more thorough than a human tasked with hunting for an intentionally obfuscated defect (if even any human has undergone that process) [0] https://jiggerwit.wordpress.com/2013/09/25/the-nsa-back-door-to-nist/ https://jiggerwit.wordpress.com/2013/09/25/the-nsa-back-door...
- nibbleshifter 4y agoIts open source. No RE necessary.
- elif 4y agoPlenty of encryption algorithms created by the NSA were also public and contained backdoors.
- ezconnect 4y agoIs Ghidra a trojan horse?
- ezconnect 4y agoIs it not a valid question? If I want to find out hackers the best way to monitor them is to release a tool they would use.
- thund 4y agoThe best part of readme: security warnings.
- kuroguro 4y agoIt does seem ironic on first glance but it's pretty much unavoidable getting some vulns in a large project. In fact if you're reversing malware that might be actively trying to sabotage that, it's a good thing they've put warnings front and center.
- abudabi123 4y agoMaybe a better UIX in the readme says, 1) buy an NVIDIA Jetson ODIN 64GB Mini 2) press the buy and play button in the App Store 3) you are running in a AAA Studio IDE