Foreword |
|
xix | |
|
Acknowledgments |
|
xxi | |
Introduction |
|
xxiii | |
|
PART I INTRODUCTION TO IDA |
|
|
|
Introduction to Disassembly |
|
|
3 | (12) |
|
|
4 | (1) |
|
|
5 | (1) |
|
|
6 | (1) |
|
|
6 | (1) |
|
|
6 | (1) |
|
Software Interoperability |
|
|
7 | (1) |
|
|
7 | (1) |
|
|
7 | (1) |
|
|
7 | (7) |
|
A Basic Disassembly Algorithm |
|
|
8 | (1) |
|
|
9 | (2) |
|
Recursive Descent Disassembly |
|
|
11 | (3) |
|
|
14 | (1) |
|
Reversing and Disassembly Tools |
|
|
15 | (16) |
|
|
16 | (4) |
|
|
16 | (2) |
|
|
18 | (1) |
|
|
19 | (1) |
|
|
20 | (7) |
|
|
20 | (2) |
|
|
22 | (1) |
|
|
23 | (1) |
|
|
24 | (1) |
|
|
25 | (1) |
|
|
25 | (2) |
|
|
27 | (2) |
|
|
27 | (1) |
|
|
28 | (1) |
|
|
29 | (2) |
|
|
31 | (12) |
|
Hex-Rays' Stance on Piracy |
|
|
32 | (1) |
|
|
32 | (2) |
|
|
33 | (1) |
|
|
33 | (1) |
|
|
33 | (1) |
|
|
34 | (1) |
|
|
34 | (1) |
|
|
35 | (4) |
|
|
36 | (1) |
|
OS X and Linux Installation |
|
|
37 | (1) |
|
|
37 | (2) |
|
Thoughts on IDA's User Interface |
|
|
39 | (1) |
|
|
39 | (4) |
|
|
|
|
43 | (18) |
|
|
44 | (5) |
|
|
46 | (1) |
|
Using the Binary File Loader |
|
|
47 | (2) |
|
|
49 | (5) |
|
|
50 | (2) |
|
|
52 | (1) |
|
|
53 | (1) |
|
Introduction to the IDA Desktop |
|
|
54 | (2) |
|
Desktop Behavior During Initial Analysis |
|
|
56 | (2) |
|
IDA Desktop Tips and Tricks |
|
|
58 | (1) |
|
|
58 | (1) |
|
|
59 | (2) |
|
|
61 | (20) |
|
The Principal IDA Displays |
|
|
62 | (9) |
|
|
62 | (6) |
|
|
68 | (1) |
|
|
69 | (1) |
|
|
70 | (1) |
|
|
71 | (4) |
|
|
72 | (1) |
|
|
73 | (1) |
|
|
73 | (1) |
|
|
74 | (1) |
|
|
74 | (1) |
|
|
75 | (1) |
|
|
75 | (4) |
|
|
75 | (1) |
|
|
76 | (1) |
|
The Type Libraries Window |
|
|
77 | (1) |
|
The Function Calls Window |
|
|
77 | (1) |
|
|
78 | (1) |
|
|
79 | (2) |
|
|
81 | (22) |
|
|
82 | (3) |
|
|
82 | (2) |
|
|
84 | (1) |
|
|
84 | (1) |
|
|
85 | (15) |
|
|
87 | (4) |
|
|
91 | (1) |
|
|
91 | (4) |
|
|
95 | (5) |
|
|
100 | (2) |
|
|
101 | (1) |
|
|
101 | (1) |
|
|
102 | (1) |
|
|
103 | (26) |
|
|
104 | (4) |
|
Parameters and Local Variables |
|
|
104 | (1) |
|
|
105 | (2) |
|
|
107 | (1) |
|
|
108 | (2) |
|
|
109 | (1) |
|
|
109 | (1) |
|
Anterior and Posterior Lines |
|
|
110 | (1) |
|
|
110 | (1) |
|
Basic Code Transformations |
|
|
110 | (12) |
|
|
111 | (3) |
|
Formatting Instruction Operands |
|
|
114 | (1) |
|
|
115 | (6) |
|
Converting Data to Code (and Vice Versa) |
|
|
121 | (1) |
|
Basic Data Transformations |
|
|
122 | (6) |
|
|
123 | (1) |
|
|
124 | (2) |
|
|
126 | (2) |
|
|
128 | (1) |
|
Datatypes and Data Structures |
|
|
129 | (38) |
|
Recognizing Data Structure Use |
|
|
131 | (11) |
|
|
131 | (5) |
|
|
136 | (6) |
|
|
142 | (5) |
|
|
143 | (4) |
|
Using Structure Templates |
|
|
147 | (3) |
|
|
150 | (2) |
|
Parsing C Structure Declarations |
|
|
150 | (1) |
|
|
151 | (1) |
|
Using Standard Structures |
|
|
152 | (3) |
|
|
155 | (1) |
|
|
155 | (1) |
|
|
155 | (1) |
|
|
156 | (10) |
|
|
156 | (1) |
|
Virtual Functions and Vtables |
|
|
157 | (3) |
|
|
160 | (2) |
|
|
162 | (1) |
|
Runtime Type Identification |
|
|
163 | (1) |
|
Inheritance Relationships |
|
|
164 | (1) |
|
C++ Reverse Engineering References |
|
|
165 | (1) |
|
|
166 | (1) |
|
Cross-References and Graphing |
|
|
167 | (20) |
|
|
168 | (8) |
|
|
169 | (2) |
|
|
171 | (2) |
|
|
173 | (2) |
|
|
175 | (1) |
|
|
176 | (10) |
|
|
176 | (8) |
|
IDA's Integrated Graph View |
|
|
184 | (2) |
|
|
186 | (1) |
|
|
187 | (14) |
|
|
188 | (7) |
|
Common Features of Console Mode |
|
|
188 | (1) |
|
Windows Console Specifics |
|
|
189 | (1) |
|
|
190 | (2) |
|
|
192 | (3) |
|
|
195 | (1) |
|
GUI IDA on Non-Windows Platforms |
|
|
196 | (2) |
|
|
198 | (3) |
|
PART III ADVANCED IDA USAGE |
|
|
|
|
201 | (10) |
|
|
201 | (6) |
|
The Main Configuration File: ida.cfg |
|
|
202 | (1) |
|
The GUI Configuration File: idagui.cfg |
|
|
203 | (3) |
|
The Console Configuration File: idatui.cfg |
|
|
206 | (1) |
|
Additional IDA Configuration Options |
|
|
207 | (3) |
|
|
207 | (1) |
|
|
208 | (2) |
|
|
210 | (1) |
|
Library Recognition Using Flirt Signatures |
|
|
211 | (16) |
|
Fast Library Identification and Recognition Technology |
|
|
212 | (1) |
|
Applying FLIRT Signatures |
|
|
212 | (4) |
|
Creating FLIRT Signature Files |
|
|
216 | (9) |
|
Signature-Creation Overview |
|
|
217 | (1) |
|
Identifying and Acquiring Static Libraries |
|
|
217 | (2) |
|
|
219 | (2) |
|
|
221 | (3) |
|
|
224 | (1) |
|
|
225 | (2) |
|
Extending IDA's Knowledge |
|
|
227 | (10) |
|
Augmenting Function Information |
|
|
228 | (6) |
|
|
230 | (2) |
|
|
232 | (2) |
|
Augmenting Predefined Comments with loadint |
|
|
234 | (2) |
|
|
236 | (1) |
|
Patching Binaries and Other IDA Limitations |
|
|
237 | (12) |
|
The Infamous Patch Program Menu |
|
|
238 | (3) |
|
Changing Individual Database Bytes |
|
|
238 | (1) |
|
Changing a Word in the Database |
|
|
239 | (1) |
|
Using the Assemble Dialog |
|
|
239 | (2) |
|
IDA Output Files and Patch Generation |
|
|
241 | (4) |
|
|
242 | (1) |
|
|
242 | (1) |
|
|
243 | (1) |
|
|
243 | (1) |
|
|
243 | (1) |
|
|
244 | (1) |
|
|
245 | (1) |
|
|
245 | (4) |
|
PART IV EXTENDING IDA'S CAPABILITIES |
|
|
|
|
249 | (30) |
|
|
250 | (1) |
|
|
251 | (7) |
|
|
251 | (1) |
|
|
252 | (1) |
|
|
252 | (1) |
|
|
253 | (1) |
|
|
254 | (1) |
|
|
255 | (1) |
|
Persistent Data Storage in IDC |
|
|
256 | (2) |
|
Associating IDC Scripts with Hotkeys |
|
|
258 | (1) |
|
|
258 | (9) |
|
Functions for Reading and Modifying Data |
|
|
259 | (1) |
|
User Interaction Functions |
|
|
260 | (1) |
|
String-Manipulation Functions |
|
|
261 | (1) |
|
File Input/Output Functions |
|
|
261 | (1) |
|
Manipulating Database Names |
|
|
262 | (1) |
|
Functions Dealing with Functions |
|
|
263 | (1) |
|
Code Cross-Reference Functions |
|
|
264 | (1) |
|
Data Cross-Reference Functions |
|
|
265 | (1) |
|
Database Manipulation Functions |
|
|
265 | (1) |
|
Database Search Functions |
|
|
266 | (1) |
|
Disassembly Line Components |
|
|
267 | (1) |
|
|
267 | (10) |
|
|
268 | (1) |
|
|
268 | (1) |
|
Enumerating Cross-References |
|
|
269 | (3) |
|
Enumerating Exported Functions |
|
|
272 | (1) |
|
Finding and Labeling Function Arguments |
|
|
272 | (2) |
|
Emulating Assembly Language Behavior |
|
|
274 | (3) |
|
|
277 | (2) |
|
The IDA Software Development Kit |
|
|
279 | (30) |
|
|
280 | (4) |
|
|
281 | (1) |
|
|
281 | (2) |
|
Configuring a Build Environment |
|
|
283 | (1) |
|
The IDA Application Programming Interface |
|
|
284 | (24) |
|
|
284 | (4) |
|
|
288 | (8) |
|
|
296 | (2) |
|
Commonly Used SDK Functions |
|
|
298 | (6) |
|
Iteration Techniques Using the IDA API |
|
|
304 | (4) |
|
|
308 | (1) |
|
The IDA Plug-In Architecture |
|
|
309 | (28) |
|
|
310 | (8) |
|
|
312 | (1) |
|
|
313 | (2) |
|
|
315 | (1) |
|
|
316 | (2) |
|
|
318 | (4) |
|
|
322 | (1) |
|
|
323 | (1) |
|
|
324 | (3) |
|
Plug-in User Interface Options |
|
|
327 | (9) |
|
Building Interface Elements with the SDK |
|
|
327 | (9) |
|
|
336 | (1) |
|
Binary Files and IDA Loader Modules |
|
|
337 | (26) |
|
|
338 | (1) |
|
Manually Loading a Windows PE File |
|
|
339 | (8) |
|
|
347 | (1) |
|
|
348 | (13) |
|
|
350 | (5) |
|
Building an IDA Loader Module |
|
|
355 | (1) |
|
|
355 | (6) |
|
Alternative Loader Strategies |
|
|
361 | (1) |
|
|
362 | (1) |
|
|
363 | (36) |
|
|
364 | (1) |
|
|
365 | (1) |
|
Writing a Processor Module |
|
|
366 | (23) |
|
|
366 | (1) |
|
Basic Initialization of the LPH Structure |
|
|
367 | (4) |
|
|
371 | (5) |
|
|
376 | (4) |
|
|
380 | (5) |
|
|
385 | (1) |
|
Other processor_t Members |
|
|
386 | (3) |
|
Building Processor Modules |
|
|
389 | (4) |
|
Customizing Existing Processors |
|
|
393 | (2) |
|
Processor Module Architecture |
|
|
395 | (1) |
|
|
396 | (3) |
|
PART V REAL-WORLD APPLICATIONS |
|
|
|
|
399 | (18) |
|
Jump Tables and Switch Statements |
|
|
400 | (4) |
|
|
404 | (1) |
|
|
405 | (7) |
|
Debug vs. Release Binaries |
|
|
412 | (2) |
|
Alternative Calling Conventions |
|
|
414 | (1) |
|
|
415 | (2) |
|
|
417 | (40) |
|
Anti-Static Analysis Techniques |
|
|
418 | (15) |
|
Disassembly Desynchronization |
|
|
418 | (3) |
|
Dynamically Computed Target Addresses |
|
|
421 | (7) |
|
Imprted Function Obfuscation |
|
|
428 | (4) |
|
Targeted Attacks on Analysis Tools |
|
|
432 | (1) |
|
Anti-Dynamic Analysis Techniques |
|
|
433 | (5) |
|
|
433 | (2) |
|
Detecting Instrumentation |
|
|
435 | (1) |
|
|
435 | (1) |
|
|
436 | (2) |
|
Static De-obfuscation of Binaries Using IDA |
|
|
438 | (17) |
|
Script-Oriented De-obfuscation |
|
|
438 | (5) |
|
Emulation-Oriented De-obfuscation |
|
|
443 | (12) |
|
|
455 | (2) |
|
|
457 | (22) |
|
Discovering New Vulnerabilities with IDA |
|
|
458 | (7) |
|
After-the-Fact Vulnerability Discovery with IDA |
|
|
465 | (4) |
|
IDA and the Exploit-Development Process |
|
|
469 | (6) |
|
|
470 | (2) |
|
Locating Instruction Sequences |
|
|
472 | (1) |
|
Finding Useful Virtual Addresses |
|
|
473 | (2) |
|
|
475 | (2) |
|
|
477 | (2) |
|
|
479 | (18) |
|
|
480 | (1) |
|
|
481 | (3) |
|
|
484 | (1) |
|
|
485 | (3) |
|
|
488 | (4) |
|
|
492 | (1) |
|
|
492 | (2) |
|
|
494 | (3) |
|
|
|
|
497 | (24) |
|
|
498 | (3) |
|
|
501 | (3) |
|
|
504 | (8) |
|
|
505 | (3) |
|
|
508 | (3) |
|
|
511 | (1) |
|
|
511 | (1) |
|
Automating Debugger Tasks |
|
|
512 | (8) |
|
Scripting Debugger Actions with IDC |
|
|
512 | (5) |
|
Automating Debugger Actions with IDA Plug-ins |
|
|
517 | (3) |
|
|
520 | (1) |
|
Disassembler/Debugger Integration |
|
|
521 | (24) |
|
|
522 | (1) |
|
IDA Databases and the IDA Debugger |
|
|
523 | (2) |
|
Debugging Obfuscated Code |
|
|
525 | (19) |
|
Simple Decryption and Decompression Loops |
|
|
526 | (4) |
|
Import Table Reconstruction |
|
|
530 | (3) |
|
|
533 | (5) |
|
|
538 | (6) |
|
|
544 | (1) |
|
Linux, OS X, And Remote Debugging with IDA |
|
|
545 | (6) |
|
|
545 | (2) |
|
Remote Debugging with IDA |
|
|
547 | (3) |
|
Exception Handling During Remote Debugging |
|
|
550 | (1) |
|
Using Scripts and Plug-ins During Remote Debugging |
|
|
550 | (1) |
|
|
550 | (1) |
|
|
551 | (4) |
|
Restrictions on IDA Freeware |
|
|
552 | (1) |
|
|
553 | (2) |
|
|
555 | (18) |
|
|
573 | (4) |
|
|
574 | (1) |
|
|
574 | (1) |
|
|
574 | (1) |
|
New API/SDK Functionality |
|
|
574 | (1) |
|
|
575 | (2) |
Index |
|
577 | |