SoftICE: a kernel mode debugger for Windows
en.wikipedia.org
en.wikipedia.org
his softice essays: http://71.6.196.237/fravia/project2.htm
It's why I always laugh when people say the Internet needs ads to survive. It was doing just fine before ads became so pervasive.
There's absolutely no way quality can ever compete with thousands of underpaid click farmers. Google is steadily getting smarter, but even they can't keep up.
Even though I'd already been hacking (Spectrum) games for infinite lives from the age of around 12 or so I learned so much from him, and the various contributors.
RIP +Fravia.
https://github.com/aquynh/capstone
https://github.com/REhints/HexRaysCodeXplorer (this is CRAZY useful if you bought the Hex Rays license with IDA)
https://github.com/ynvb/DIE - makes IDA even better ("DIE is an IDA python plugin designed to enrich IDA`s static analysis with dynamic data)
https://portal.cert.org/web/mc-portal/pharos-static-analysis... - I haven't used this yet but Pharos is a static analysis tool out of Carnegie Melon that's particularly useful for C++ gen'd code. https://insights.sei.cmu.edu/sei_blog/2015/08/the-pharos-fra... Walks through some feature set. HexRays is great for somethings but when you F5 some block, you really are left wanting. This looks like it fills the gap quite nicely.
http://www.radare.org/r/cmp.html - Comparison beween IDA and Radare (admittedly unfair, even titled so, ha)
There are dozens of plugins I use which are just python scripts mapped to keyboard shortcuts so I don't even remember what they're called. Someone else is going to have to jump in because I'm not on my work machine and can't look it up.
You lost Ring0 with the demise of SoftICE, but the RE community is more active than ever. Just watch a few CCC talks if you're not convinced.
Just a note guys: I know you can pirate IDA but some companies just "do it right" and should be supported. I buy from Adafruit even though they're more expensive because I support them. IDA is one dude, who's responsive within the community, who goes out of his way to be nice and implement bug fixes and feature enhancements. I try not to get all preachy, but pirating IDA isn't stealing Visual Studio from Microsoft- you're ripping a dude who's contributed a lot to the community and even offers a free (granted less featureful) version.
Seriously? One lone guy coded up all of IDA and the Hex Rays decompiler? Whoa, hat off.
I always thought that there was a group of more-or-less shady highly experienced hackers, but not a single dude.
https://en.wikipedia.org/wiki/Ilfak_Guilfanov
I don't know if it's just perception bias or something cultural, but I seem to hear a lot more about famous/advanced Russian reverse-engineers than anywhere else.
Availability was always a big driving force behind many RE efforts, allot of the good reverse engineering examples from the west (EU/US) that you can see especially in the 80's/90's were all about reversing Japanese games and game consoles (including arcade machines), some of them took 10-20 years to break especially those with the more advanced CAPCOM DRM modules.
Basically anyone who had PC and interest in reverse engineering may do almost anything without consequences. There was a lot of people that did it all publicly without really hiding their identity or even making business off it (like well-known DRM-removal tools). If you would try to do anything like that in western would you'll end up in prison soon.
Also reverse engineering isn't some independent area, but it's usually linked with black hat security, virus making, carding, SEO, etc. There was a lot of CIS-based illegal and gray area communities and services that only may exist because lack of government control and many still exist.
So it's was as well one of ways to make a lot of (illegal) money, but at some point any person grow up, get married (and make a child) and don't want to take criminal risks. Many of them want move to EU/US where risks are higher. Here you go where huge part of experts has come from.
No, it doesn't yet. We have to wait for OllyDbg 64 (http://ollydbg.de/odbg64.html).
I worked at Numega from 1999 through 2001 in the technical support department. When I started, I provided support for another product, but over time became familiar with all of the tools and eventually managed the technical support team.
We would frequently get support requests from companies asking for ways to detect and/or prevent SoftICE, and we had some nice reply templates trying to break it gently to them how there was no practical way for software loaded after SoftICE to reliably stop a determined user from debugging and/or tampering with it.
The SoftICE tech support issues were always the tough ones. We had a small team of elites who would slog through those issues while the other team members could only wonder what they were talking about sometimes. :) Some companies even resorted to shipping hardware to the team to help reproduce and resolve tough issues.
My favorite memory though is when I was learning SoftICE and I grabbed one of the guys and asked them if they could help me figure out a weird issue with it. As we walked over, I shared with them that every time I broke into SoftICE, my CRT monitor would shut off, and it wouldn't come back on until I closed SoftICE. I asked them if it could be some sort of new countermeasure.
They looked at me with that disbelieving look one shares with a mere novice, and sat down at my computer and pressed Ctrl-D. Click! Off went the monitor. Their eyes bugged just a bit and they tentatively toggled the power switch just to make sure. Dead. With hesitation, they typed the command to close the SoftICE window and blinked as the monitor hummed back to life.
As I said though, these guys were good. After hitting Ctrl-D a few more times and watching the monitor switch off and on, this person didn't let the mystery send them down any rabbit holes. They immediately went fishing for the monitor power cable and traced it to the plug where they found a suspicious looking box it was plugged into. As they looked back at me with a glare, I guiltily held up the remote control for the power switch and fessed up.
Good times.
It was awful. The huge noisy blue box ran on floppies; it booted like molasses; it's fullspeed emulation was nowhere near fullspeed. It had an arcane debugger and an arcane file system. The cable was fragile (1-inch pins! that would crimp and break when inserting into the socket).
When Intel asked us "What do you want in the next generation of processor chips?" I knew exactly what to say. I requested special registers where I could set bus conditions and masks, that created an NMI (non-maskable interrupt) on a match. With that I could do data breakpoints, I/o traps, pretty much anything that a hardware ICE could do.
The next spec had my register(s)! It was one of the happiest days of my life. And the rest is history.
I remember that one.
I used it when hopelessly trying to RE some applications (either Aspack, Securom or Safedisk). Dat self modifying code :3
Got to learn a couple of things thanks to RE. Never became an expert, with college becoming more demanding and then lack of interest, but got to work around some shareware and crackmes. My most "notable work" was dumping an UPX packed executable and rebuilding the PE tables.
A shoutout to all the +RE and Cracking4Newbies and REA people for all the help and tutorials.
fake edit: my first introduction to crypto was from REA... Vigenère cipher comes to mind.
The remote debugging was needed as switching between the graphics mode of the game and text mode of the debugger was totally unstable - Now that I think of it, it might actually have been a "anti-debugging" measure of some games, as I vividly recall a Bards Tale cracking session on a single machine.