IDA cybersecurity software provider Hex-Rays acquired
smartfinvc.com
smartfinvc.com
I own a copy of IDA (legally). It was an absolute pain to purchase and it seems that a large portion of their margins are dedicated to piracy control. I won't detail the process...but it seems unusually personal.
If I had to guess they will expand their decompilers (the actual flagship project). It will be years before Ghidra + a community catch up to them and Binary Ninja (I also own a copy of it) may never. The disassembler is just a familiar tool. Their decompilers are way, way far ahead.
I know what you mean. I tried to purchase it and got this email:
Dear Sir/Madam,
Thank you for your order. Please could you send a copy of your passport and fill out the attached form? Our compliance policy now requires this.
Many thanks
Hex-Rays SA
I used a cracked copy after that.Can you elaborate? I would really like to see what the HexRay decompiler does better (or worse) than Ghidra, but I am too poor to buy it (and dogbolt.org is not interactive, so I cannot edit function signatures to "help" the decompiler etc.).
Is it better in general, for a specific programming language or platform (e.g. C++, Windows), or for a specific use case (e.g. obfuscated code)? I heard about their cloud-based stuff, although I don't know what they are exactly doing there. Maybe ML trained on source code? Function signatures of the latest malware?
After several hundred hours with Ghidra, I think it certainly would need some polishing, in particular:
- UI. Too many frequently-used dialogs are not optimized for keyboard usage.
- Decompiler too stubborn sometimes, ignoring user input (e.g. manually specified types).
- Decompiler needs better heuristics for the treatment of some common cases (e.g., often doesn't recognize for-loops and array accesses)
- Quite dangerous: Sometimes the decompiler gets lost, especially if a function contains handwritten assembly code with unusual control flows. Okay, can happen. But instead of displaying a warning it just shows you the part it could decompile and you have to figure out by yourself that something is missing.
But most of the above issues are fixable. Instead, I would be interested in learning about more fundamental differences between the two decompilers.One issue with Ghidra's that I keep hitting is its poor support for amd64 SIMD. There's a good example at <https://github.com/NationalSecurityAgency/ghidra/issues/249>:
0000000000000000 <intrinsics>:
0: f3 0f 1e fa endbr64
4: 0f c6 ca 1b shufps $0x1b,%xmm2,%xmm1
8: 0f 58 c1 addps %xmm1,%xmm0
b: c3 retq
IDA produces great decompilation: __m128 __fastcall intrinsics(__m128 a1, __m128 a2, __m128 a3) {
return _mm_add_ps(a1, _mm_shuffle_ps(a2, a3, 27));
}
The Ghidra output is a mishmash of CONCAT pseudo-macros.This is the thing that sticks out the most IMO. IDA decompiler is quite a bit more flexible than Ghidra's. When you assert a type, it will usually not ignore it. It may sometime get a bit lost if you give conflicting types to dependant variables, but otherwise, it's pretty good at this.
One of the annoying bits of ghidra (though it may have improved, it's been around a year since I last used it) is that there's no way to "split" a variable. Sometimes, ghidra will have some code that looks roughly like:
int x;
x = 0;
doSomething(x);
x = 1;
doSomething2(x);
(Obviously, really simplified).The problem is, sometimes, x needs to be an int for the first function, and a bitflag structure for the second. But Ghidra has no way to say, "hey, from this assignment on, treat `x` as another variable", so you have to either generate a union (ugly) or deal with sending the wrong type (also ugly).
IDA tends to be much better at this. All variables start out as "split" as it can make it (almost in static single assignment form). Then, the user can tell it "Those two variables are actually the same, please treat them as one". I find this flow works really, really well.
Also can I haz offset pointers pretty please? It's not in the last released version I tried, and the last Git version I tried had offset pointers but they didn't affect decompiler output so multiple inheritance and container_of linked lists still came out broken.
Right click -> “Split Out As New Variable”, but it seems like this doesn't work for stack reuse yet (just registers, or more generally, simple varnodes).
https://github.com/NationalSecurityAgency/ghidra/issues/2573
Due to these heuristics IDA produces real actionable code quicker. My experience with Ghidra (less than yours) is that it produces mostly garbage on a lot of different things and it requires a lot of prep work to make truly usable. This might not be noticeable on small or simple binaries but on larger binaries it actually becomes a real measurable problem. While Hex Rays isn't perfect, it's about as close as we can come to it right now and it generates very human-looking code with smart optimization removal. One thing I remember with Ghidra not long ago was a common optimization like using SSE registers for arrays would produce a page worth of non-sense for something simple. Additionally, detection of standard libraries still isn't good so you end up wasting your reversing time on re-reversing a different compilers version of strlen than actually doing the work you need to do. If you could use FLIRT signatures in Ghidra legally I'd imagine Ghidra would be vastly improved.
I'm not a reverse engineer, but I have been working on this with the assumption that it would be a good time-saver for a reverse engineer. Feel free to DM me if you'd like to discuss.
I don't have formal data, but in my narrow slice of the world that's what I'm seeing as well.
IDA's price is so high that it's easy to justify using Ghidra instead. Heck, if Ghidra does something less well, it might be cheaper to pay to improve Ghidra (and then you can use those improvements forever). I encourage organizations who are thinking of using Ghidra to contribute back to it; if those improvements get integrated back in, then those improvements will continue into the future along with other improvements.
I guess there are a lot of people that just click around in the UI but for a keyboard based workflow, Ghidra has a lot of catching up to do even to IDA 4.x.
I like Ghidra's interface better, but I'm also not a keyboard-first type of user. I work with a lot of different OSes and software. I stopped trying to remember most keyboard shortcuts 10+ years ago, because there were too many variations, and the consequences of using the wrong one can be dire.
Releasing and open-sourcing Ghidra was a truly magnificent gift by the NSA, and I can't thank them enough for it.
[1] I'd love to see a Ghidra equivalent of Lumina, for example.
Arguments of keyboard/mouse efficiency are dead to me. The limiting factor of any reverse engineering is definitely not how efficiently you can keyboard navigate a UI. People are too in love with efficiency of the wrong things and not what the real limiting factors of reversing are, which is comprehending the program. I don't love clicking around but it has never once slowed me down on a project.
I'm guessing that I'm on the same pirate blacklist that a lot of people landed. I guess I should have expensed it instead of having the Company buy it. I was the only person doing RE work, it was a single user person license and I was also the only linux user out of that 300 people org.
I think there are a lot of people that would like to pay for IDA but can't get it.
On the other hand I really don't like the Ghidra user experience.
Is there something similar to FLIRT in r2 or ghidra?
Many years ago we wanted to buy IDA Pro license and were quickly declined because we had whois privacy protection enabled on our domain.
beware that these are not the latest versions.
Just to clarify, if I wasn't concerned with budget and had to pick a product today, I'd still go with IDA, but the mindshare among new hires and interns is swinging pretty rapidly towards Ghidra. If they are able to continue adding features (with US government funding, and open source development), IDA is right to be worried about whether they will still be the best choice in 5 years.
You can create your own signature databases, although i have been unsuccessful in my brief attempts.
The algorithm is different from flirt though.
Its roughly, mask a bunch of stuff (relocations, etc), and hash whats left. There is some parent/child analysis for ambiguous calls i believe.
My recollection is flirt also masks its version of a bunch of stuff, but builds a trie of the first xx bytes with some provision for needed values past that, and some parent child analysis. They have a paper on the algorithm you can google.
Ida ships with more signatures out of the box, In my experience. Although i havent seen them listed anywhere.
I think it is safe to assume that offering cheaper products will be the last thing they are going to do.
But then again those take time to show their benefit, and they probably make piracy easier.
IDA never really accommodated to the hobbyist, so I wonder did it have any impact on the commercial side of things apart from the IDA Home release?
Hex-Rays did ultimately release IDA Home, but you have to sign up for an account to even find out what their hobbyist license costs.
I cannot underscore how much Hex Rays never wanted to have customers or sell products. Maybe this restructuring will fix that?
Now, more and more tutorials and introductions use Ghidra. Is it better than IDA? In some cases yes, in most not yet, but it’s easier to get.
If I were Hex-Rays, I’d be very concerned with a generational shift as people stop bothering to pirate IDA and those who learned on Ghidra enter the industry and don’t demand an IDA license.
When I was in the US Gov there were plenty of IDA licenses floating around despitr the existence of Ghidra. The Gov thinking was basically "better to have it and not need it instead of need it and not have it". There must be a thousand licenses that never get used year after year. I suspect IDA is safe for a while for this reason alone, but of course could be wrong and don't have the numbers-just speculation.
[0] - http://www.bitsavers.org/components/ti/TMS7000/TMS7000_Famil...
For a "new" professional/team, it makes zero sense to buy a IDA license nowadays.
And even then, IDA Home comes with some pretty serious limitations. It's not just a no-commercial-use version of IDA Pro; it's also a cut-down version with no decompiler, no batch mode, and which only disassembles code for one processor family (which you have to choose at the time of purchase, from a limited subset of what IDA Pro supports).
The total price kicks licensing costs well outside that of hobbyist use cases.
But, like you said, IDA Home is additionally limited to one architecture, which is a bit annoying.
It was all over their release announcement and Twitter, iirc. From their website: “For the price of $365 / year” https://hex-rays.com/products/idahome/
IDA Pro for ARM w/ a decompiler is the cost of a used car.
IDA has a problem where, for some shops, it really makes sense to just have one concurrent IDA user, because IDA is like 10-15% of the work hours --- but it's a critically important 10-15%. So they're super careful to charge for the ability to rotate a team of consultants through the same IDA license.
We had a client, a decade or so ago, that brought us in to do IDA-based vulnerability research work. We wrote some blog posts about the work, and it was so unusual for any of their clients to have that licensing arrangement that IDA (this is in the Pierre era, not the Hex-Rays era) publicly accused us of pirating our copy (which was annoying, because we couldn't out our client, but they absolutely did have the licensing worked out for this.)
It's all super off-putting. But IDA is in sort of a bind, because there just aren't that many users for their ultra-hyper-specialized product. You can have the very best decompiler in the world and you're still going to be a rounding error compared to companies like Figma, because (1) not that many people use disassemblers and (2) less and less software is written in C/C++ every year.
Edit: Ironically the NSA is the entity commoditizing their complement here, getting an in-house SRE tool and making it easier to hire students out of college with skills they want.
(1) could be changed by making a decent offer to hobbyists that they can't refuse, and making the buying experience for them hassle-free.
Yes, the license cost is likely marginal if you only disassemble Windows malware on Windows.
as an aside - When I was taught Ghidra the trainer said "in IDA you spend most of your time in the disassembly graph, in Ghidra I rarely leave the decompiler"
They added an undo button to IDA.
but for reeeeaaal work, that needs to be done by the deadline, it rarely gets considered.
Looks like they've actually added the "cloud-based x64 decompiler" to the free offering now, so maybe if you're not working with 32-bit code and not working with anything too sensitive that could be of use.
It's really a testament to the robustness of the software.
Also this Python detection tool that needs to be executed prior the first run didn't support python 3.10 at some point -- they've did version detection based on the filename that detected 3.10 as 3.1 (windows9-style version detection). Not sure what's the case with recent IDA versions, because I'm using Ghidra since a long time now.
But overall I agree, I would never suggest IDA when being asked about an example of a buggy software.
they cater to the hobbiest market to, with a free version that will honestly work for soooo many things. I don't understand why people use ghidra honestly. but hey, nsa has some good pr people
I really hated using Ghidra and Binja compared to IDA as I'm a bit reliant on dynamic RE for some purposes, while IDA is able to bridge the gap between static and dynamic without the need to break out x64dbg or similar.
""" With the new shareholders on board, Hex-Rays must evolve from an engineering company to a commercial company. “After the takeover, we want to structure the company, develop a commercial team and a management team and continue internationalization,” say Ingels and Luyten.
The intention is to transform the current commercial model of perpetual licenses into a recurring model. In the first model, customers pay a large amount at the start and then annually for updates and maintenance. The other includes an annual payment for the license and all associated services.
Hex-Rays' next growth phase will be led by a new CEO, who will take over from Guilfanov. He will eventually become chief technology officer (CTO) of the Liège company and chairman of the board of directors. """
I wanted to do some pic disassembly a while back and out of curiosity asked if they had a low cost personal license for non commercial use and basically got told to pound sand. They said the price for the full version was what it was, no discounts. Then they came out with their ‘home’ edition which is an insult at $365 per architecture and not all architectures are available.
I don’t care how much better it is than open source stuff, until they have a full featured personal version and lower their price, they won’t be getting a dime of my (or my companies) money. It isn’t 2008 anymore.
And today they’re offering the pro-pack. 10,000 decomp units for $1,200 bucks. Of course now they can devalue the value of a unit at will.
This does not appear to be true.
"retire" is from French retirer, to pull (something) back -- as e.g. a general might do with troops that need to stop an attack.
"tire" (verb) goes back to Old English tiorian, and its etymology before that is not known and in particular doesn't seem to come from French "tirer" or its Latin antecedents.
Is it worth doing any of those online ctf thingys? Any recommended resources or books I should check out?
Practical Malware Analysis is a really great book, even if you don’t intend to reverse malware. It has labs after every chapter, along with solutions. It teaches you about windows, how to approach reversing a program and what to focus on to not waste too much time.
Once you worked through that CTFs should be much more approachable.
Reverse Engineering: Secrets of Reverse Engineering and Practical Reverse Engineering are also often mentioned as good books, but I personally haven’t read them. Aside from that, the books from nostarch.com are great.
If you want to learn more about windows itself, there are the “windows internals” books.
It’s also a good idea to find a community with similar interests, learning together is often more fun. And when you ask for help try to properly state your problem and what approaches you already tried to solve it, along with their outcomes.
Good luck!
Yeah, too much information. Maybe I'm just not finding the precise search words to find what I want.
Your reply was very helpful so thanks for that.
>You’re additionally not very specific about your goals
I'd like to be able to do very basic audits of how programs work and precisely what they're doing, and also modify their behavior in simple ways (change hardcoded servers, change program execution flow, disable or enable certain functionality). Reverse engineering with basic modifications.
I'd also like to have a go at modifying firmware of embedded devices, eg a car head unit with a stupid splash screen on startup that I'd like to disable.
For example I have a camera with wifi functionality, and you can control it from a phone app. It would be cool if I could somehow control that from the command line, or create my own basic app for the PC to control it. On top of that it would be good if I could modify the firmware to make it automatically start up in that remote control mode.
Mostly just for adding to my box of tools and general understanding though.
The listed books should help with that! I think Practical Malware Analysis really is a good start, even for that. When looking at malware you also try to find important functionality and the book teaches you how to get there quickly.
> I'd also like to have a go at modifying firmware of embedded devices, eg a car head unit with a stupid splash screen on startup that I'd like to disable.
There are probably forums for that, where you can find some info. There's also a nostarch book on car hacking (https://nostarch.com/carhacking) and for embedded (https://nostarch.com/hardwarehacking). I haven't read either, but it might be worth to check out some reviews for it. Maybe they're good and can help you achieve your goals.
The difficulty probably depends on how new the car is. In case you need to actually find a vulnerability in the infotainment system to get proper access, something like Hacking: The Art of Exploitation (https://nostarch.com/hacking2.htm), which I heard many good things about, is probably a good read. But if it's too new it might be too time consuming (see e.g. https://www.youtube.com/watch?v=k_F4wHc4h6k)
> For example I have a camera with wifi functionality, and you can control it from a phone app. It would be cool if I could somehow control that from the command line, or create my own basic app for the PC to control it. On top of that it would be good if I could modify the firmware to make it automatically start up in that remote control mode.
I think getting at least a CLI client could be relatively easy. For that you probably don't even need to reverse a binary using IDA/Ghidra/Binary Ninja. You can try to get the .apk file of the app and decompile it using something like jadx (https://github.com/skylot/jadx/). You'll receive mostly readable Java code. It can try to deobfuscate names, if they're obfuscated. The code you're interested in is probably somewhere under "com.manufacturer...".
How easy it is to modify the firmware once again likely depends on how old or new the camera is. They could, for example, have some integrity checks that keep you from doing that. But I have absolutely zero experience here, so it might as well be really easy. I think there could be forums for this, too.
Also be warned that modifying the firmware of your car or camera can break (parts of) them if things go wrong. E.g. I accidentally (soft) bricked a device because I tried to flash it from within a VM. I don't know how big the risk in your cases is, maybe there isn't any. But it's a good idea to read lots before accidentally breaking something expensive!
Happy I could help you :)