4 ms·
Ghidra is genuinely an awesome software, you don’t need to be a reverse engineering expert to use it. And with LLMs like GPT it will be able to do insane stuff
by DethNinja 4y ago
Ghidra is genuinely an awesome software, you don’t need to be a reverse engineering expert to use it.
And with LLMs like GPT it will be able to do insane stuff like automatically analysing very complex malware.
On the other hand I’m sure malware will evolve too, with LLMs you can actually directly edit the binary and add hooks to them. Cost of building firmware malware for NICs and UEFI will lower to zero dollars.
Anyway I’m getting out of topic but this was something I really wanted to mention somewhere, it is likely there will be a massive amount of complex malware coming via LLMs that will potentially impact the entire economy.
- boppo1 4y agoWhat will the defense be?
- password4321 4y agoLLMs on defense too. Also, the filters on the commercial services attempting to prevent misuse. Anything useful that gets past the filters and is used to cause damage leaves behind the prompts and user account info to be subpoenaed, though it could take a while for law enforcement to come up to speed.
- amrb 4y agoApi has no filters
- yalogin 4y agoWhat's an LLM and GPT?
- l33t233372 4y agoAn LLM is a large language model. A GPT is a generative pre-trained transformer. This is a type of text generative AI model.
- amrb 4y agoI wrote code for the headless analysis to dump all functions, till I managed to oom my laptop decompiling a tricky sse2 function, it was fun experience so gonna open a PR see if that can be solved for others.
- landr0id 4y agoSort of a tangent but I used Ghidra last week to help a coworker figure out where some function was called by looking at the callee tree to it. He was investigating a crash reported by a user that seemed impossible to hit as the function was never called. After about 10m we figured out that the code had been recently refactored and the build I had locally was enough out of date to still have the buggy function call.
- l33t233372 4y ago> with LLMs you can actually directly edit the binary and add hooks to them I’m so confused what LLMs have to do with adding hooks. Edit: I’m confused because this can be done without LLMs, and I don’t see why they’re particularly helpful here, unless the use case is instructing the LLM to “hook malloc to use my_malicious_malloc”
- DethNinja 4y agoIt is not that easy to reverse engineer closed source firmware and edit the right places on the binary to prevent runtime investigation/detection and reflashing. If you don’t care about almost undetectable persistence, then yeah you won’t need to bother with LLMs to find the perfect hook point.
- saagarjha 4y agoHow does the LLM help here?
- DethNinja 4y agoI don’t have particular experience with firmware hacking but how would you achieve persistence with just a simple malloc/bad malloc replacement? What if user decides to reflash the ROM during runtime? I imagine persistence would require emulating the entire firmware update process. In order to emulate the firmware update process, you would need to reverse engineer a large portion of the binary, right? This is where LLMs would be helpful.
- l33t233372 4y ago> how would you achieve persistence with just a simple malloc/bad malloc replacement How would you achieve it with the LLM? I’m totally confused what persistent malware had to do with LLMs, unless you’re just saying “LLMs are smart and are a way to automatically do hard things”
- 4y ago
- splonk 4y agoPrevious thread about using GPT3 with Ghidra: https://news.ycombinator.com/item?id=34250872 https://news.ycombinator.com/item?id=34250872