Analysis of large binaries and games in Ghidra-SRE
kiwidog.me
kiwidog.me
[1] https://github.com/cmu-sei/pharos/blob/master/tools/ooanalyz... [2] https://github.com/cmu-sei/pharos/blob/master/share/prolog/o...
I've also had significantly more success with OOAnalyzer but as you say, it's dog slow and just consumes an unfathomable amount of memory. I had a few binaries it just completely choked on regardless of part size.
Finally, while Ghidra is pretty cool in theory, in practice it's quite brittle and rough at the edges. I've had projects get corrupted, analysis that always hang indefinitely with no diagnostic information why. And it performs about the same on a 4-core host as a 64-core host, which deeply saddens me, as almost nothing is multithreaded.
Turns out stuff is really hard, despite Ghidra doing a bunch of work to try and get things to be super easy. Even for really small old indie windows games I think you really have to have a good idea of what kind of tools the people are using to get places. That or get really lucky in a string search :)
Trying to RE production SW without any prior development experience is brutally hard.
I remember this back when people wanted to learn cracks/keygens: If it was anything more than replacing a value with a hex editor, it was too complicated.
I am trying to RE a 16bit windows game. Ghidra gets lost a lot on the exe to system dll paths for me. For 32bit it seems fine though.
An understanding of how C/C++ memory mangement works and how things like arrays/pointers etc normally get compiled down by the compiler. Having a general idea of how indie games a typically made (a loop which reads input -> updates game state -> draws to the screne) helps as well. In the case of finding what writes to the HP, you'll end up in a function that most likely updates game state, so you can then just walk up the functions to get to the main loop.
I spent a lot of my youth reverse engineering a small indie game. It go to the point where as a community we reverse engineered most of the in game objects into C header files. Then with the help of those header files, we made custom AI possible. Used a DLL to detour the normal AI function to our function and in that function we loaded Angelscript files that had access to the original game objects so they could control the objects. Ghidra didn't exist back then, and IDA was too expensive and the Cheat Engine dissambler was bad, so we reverse engineered everything in Ollydbg.
This was of course for a tiny indie game with a custom engine. I imagine now days with everything being made in Unity/Unreal etc, it's much harder to reverse engineer. Also x86 calling conventions were nicer than x64 imo ;).
Unity games are actually incredibly pleasant to reverse engineer most of the time, since they are built on .NET/Mono. Unless they are intentionally obfuscated (don't think I had that more than once) you can pretty much just drag and drop the Data\Managed\Assembly-CSharp.dll into your .NET decompiler of choice. The byte code is pretty close to source, with pretty much the entire class structures still there. Only the inside of functions has to be restored, thus the AST might be slightly different and variable names gone.
Even more comfortable are pure .NET games... simply attached the full IDE to debug. Rider even takes care of the decompilation on the fly.
I have messed about with Terraria reverse engineering (pure .NET) and that was easy like you said.
In software development, we share massive amounts of information, and there's always a premade tool out there that does what you need and will work the first time. This isn't my experience in the reverse engineering world. Information is sparse, seems to be kept private, and there's not always a tool that does what you want. Even if there is, good luck getting it to work.
I did this with a Tetris clone, then a Minesweeper clone and then I did a multi-threaded "Shoot the ducks" clone, each duck being a thread. Probably will take you several months but at the end you'll really be able to do a lot of RE.
And there is a dub patch to apply the Japanese audio to it too, or was.
Now to find a copy...