Ghidra 9.2
ghidra-sre.org
ghidra-sre.org
https://maxkersten.nl/2020/09/13/a-review-of-the-ghidra-book...
It's a good introduction but does not venture far.
Part of the reason I keep saying this is, if you've done reversing work with IDA or Hopper, you can fumble your way to productivity with Ghidra without a book. So: if Ghidra is completely greek to you, start maybe with fundamentals.
First, let me say: Both are leaps and bounds above _anything_ else out there. Stuff like Hopper is basically just assembler code in a different syntax; Hex-Rays and Ghidra are real, working, useful decompilers. Hex-Rays charges four-figure sums for single licenses, and it's because the product is utterly worth it if you do this kind of thing for a living (or at least was before Ghidra came along). I would estimate it speeds up reverse-engineering by 10x. There's a wonderful interactivity where the decompiler does all the boring book-keeping for you, and you keep feeding it info and it tells you stuff in return. Decompiling is often about figuring out data structures; both will infer a lot of struct types and sometimes even names based on usage and surrounding code. This is _so incredibly useful_. When you give a field a type or a name, it propagates throughout the program and gives you new understanding.
Both products are weird and have arcane UIs. IDA/Hex-Rays feels more ergonomical to me, though (for instance, highlighting happens automatically instead of having to middle-click), perhaps because it's what I started on. Both have strange bugs that you eventually learn to work around. Both have lots of bells and whistles only advanced users will get to use.
Hex-Rays' output feels much more polished to me. It recognizes a lot of compiler idioms, and every new release recognizes more. On the other hand, Hex-Rays only supports a few select platforms (when I started, it did 32-bit x86 only; now it does x86, x86-64, arm, aarch64, ppc, ppc64, mips), and you have to pay for it separately. Ghidra supports decompilation for almost all targets it can disassemble! This either is huge, or doesn't matter to you at all.
Hex-Rays' support is amazing. You report a bug, include a specialized program database by means of a function in the GUI, and four hours later, you receive an email with the bug fixed. On the other hand, Ghidra is free and Hex-Rays is the most expensive software I've ever used, which is obviously a huge deal for anyone not doing this full-time. (The Hex-Rays license lasts for only a year, but after the license is expired, you can still use the software. You just don't get support or newer versions.) If Ghidra cost $500 (for a permanent license), I would probably consider getting it, but it happens to be $0. Fantastic value for money.
If I could choose only one, and cost didn't matter? I'd probably go with Hex-Rays.
However, I use these tools strictly on a hobbyist basis, and I'm not sure that IDA Pro's price tag is really worth it. I think I might have a copy of IDA Free kicking about before they really gimped it, but what I really want is a working IDA on Linux.
[1]: https://cutter.re
I'm not well versed in the legality of publishing those databases, as some discussions I've heard elsewhere treat them the same as the object code they annotate and thus it would be like publishing the .exe from Photoshop. I would guess it's possible to separate the annotations from the object code, similar to the way subtitle files are shared for the movies, but similar to a wrong subtitle file, it would take some doing to discover it and more doing to try and rescue the annotations if they could apply to a slightly different but still applicable binary
I know IDA has a "Lumina" database.
https://www.hex-rays.com/products/ida/lumina/
Someone has made a public "Lumina" database for IDA.
If you don't have a legit copy of IDA, you can always pirate a copy and use that public "Lumina" server.
- edb (https://github.com/eteran/edb-debugger)
- x64dbg (https://x64dbg.com)
>As @ryanmkurtz mentioned work is continuing on the debugger, it is a large job and there have been many issues that have come up, not the least of which is COVID. We would really like to give you a timeline, but I don't want to promise anything and not deliver in a timely manner. Dynamic analysis and easy integration of dynamic information is important to the Ghidra community as is evidenced in the thread.
>IMHO, I would not hesitate to learn/use any tool, as the knowledge gained can always be ported to another tool. Time spent learning other debuggers, such as gdb or windbg, will not be wasted as the new Ghidra based debugger will be integrated with existing debuggers or have considerable overlap with their command sets and functionality. That said, if another tool fits your needs, use it. There are many great things about each RE tool and reasons to use or not use each.
>Rest assured we are diligently working on the debugger and we think it will be worth the wait. We'll share information on features and release when we have solid timelines.
>Thanks for using Ghidra in whatever way fits your work. Feel free to request features/improvements you see lacking and we and the community will try to address them.
>We'll close the issue for now.
--------------------------
Also from the What's New 9.2 release notes:
>Dynamic Analysis Framework - Debugger
>The debugger is very much still in progress. You may have seen some commits, in the Ghidra GitHub master branch, to get in sync with the debugger. Stay tuned for more on the Dynamic Analysis Framework soon after the 9.2 release.
[0] https://github.com/NationalSecurityAgency/ghidra/issues/24#i...
I know there are projects from OWASP etc with a realistic site for learning web security, but I don't know any realistic installed software for teaching in the same style with multiple targets in the same package.
King Ghidorah is the 3 headed monster from the Godzilla universe.
Given that your purported translations all have four consonants in them, not three, I'm guessing you somehow pasted the wrong string? When I get "غدر" in Google Translate, I get the transliteration as ghadar and not ha-zi-bo-m.
https://translate.google.com/?sl=ar&tl=en&text=%D8%BA%D8%AF%...
Here I added a couple diacritics (just to make it sound just like "ghidra".
https://translate.google.com/?sl=ar&tl=en&text=%D8%BA%D9%90%...
"Threat: The Mossad doing Mossad things with your email account. Solution: Magical amulets? Fake your own death, move into a submarine? YOU’RE STILL GONNA BE MOSSAD’ED UPON"
-- https://www.usenix.org/system/files/1401_08-12_mickens.pdf
The NSA being accountable is also news to me. They routinely violate their own constitution, and many other laws. They also cooperate with said criminals, and similar criminal enterprises worldwide.