Imhex: A hex editor for reverse engineers
github.com
github.com
1. File templates mean that it auto highlights sections of known file types.
2. It shows how selected bytes may be interpreted as pretty much every common data type that I would want and does so simultaneously.
3. It’s significantly faster than other editors for me when I use large files
On the downside, the imgui ui gets buggy sometimes but it’s replaced my use of other viewers like HexFiend, hexa etc…
Oooh that looks slick, thanks for the tip!
4. Unlike 010 Editor, it does not take you $150 and is FOSS so you can easily patch it to do whatever you need.
https://github.com/WerWolv/ImHex-Patterns/tree/master/encodi...
I also tried ImHex briefly. I have a ton of respect for the project, but found for my needs it was like using a cannon to kill a housefly.
Hex Fiend for instance is my hex editor on macOS, but why does it insist on reflowing the lines when I expand the window? I might just want to work with it maximized to avoid visual distractions, but I still only want lines to be 16 or 32 bytes long, and definitely not some weird size that will make things not line up.
I've tried a lot of lesser hex editors that get cooked the moment you try to open a 4GB file. I don't know if the field I'm in skews this, but most of the time if I'm looking at a file in a hex editor, it's relatively large and I need to find a tiny amount of information in it.
Why does a hex editor require OpenGL? (and therefore a GPU?)
Is there a good reason why it needs OpenGL or is it just for l33t-ness?
Though, a couple nits:
1. An OpenGL requirement doesn’t necessitate a GPU. There are software implementations of OpenGL but they tend to be rather mediocre at best for performance.
2. Many platforms now assume some kind of GPU. It’s fairly rare to need a GUI tool without also having a GPU available. Of course there are niches for it, but those aren’t also likely to be running a hex editor and tooling locally.
OpenGL calls for basic desktop rendering can be reliably handled by the integrated graphics in the CPU. In which case OpenGL can almost be viewed as a parallel instruction set / DSL.
This is because OpenGL is made so that you need to run a program to calculate color of every pixel, even if all you want is to copy a glyph. Obviously it will be slow unless you have hundreds of core running in parallel. Software implementations should either learn to convert shaders to non-parallel optimized loops, or something other than OpenGL should be chosen as a basis for rendering GUI.
I believe even tools like NVIDIA’s Omniverse are based upon Imgui
Any editor, to be fluid and quick at today's screen resolution, needs hardware rendering. The days of drawing things pixelwise, especially any complex formatting, are noticeably slow.
See this [1] for example
[1] https://www.sublimetext.com/blog/articles/hardware-accelerat...
busybox hexedit is an editor. It's fast for viewing and editing in hex. No GPU required. No need for ncurses either. toybox hexedit adds optional colors.
And you are comparing apples with oranges. busybox hexedit is not a GUI app.
Yes, if you ignore what I wrote and cut the conditions short, you can change the conclusions. Yet I still don't think you're understanding how even console hardware tends to work.
Busybox hexedit is not drawing pixels. What do you think is drawing those glyphs on the screen? Very few font renderers are pixel based software, even for tiny systems, since that's slow (and font blitters are soooo cheap to embed).
Another way to see it - where in the hexedit code is the font drawing? In busybox? Oh, it relies on something else to do it, and even most of those are hardware accelerated. Here's the hexedit code [1]. Start there, walk back through how it prints, how that is implemented in busybox, how busybox defers that to hardware, back into various supported platforms, look at the chip sets, and voila... Hardware accelerated in most cases (I don't see one offhand that does pixel writes any more).
Pretty much all console hardware now is hardware accelerated. If you log into a device and run SSH from a larger machine, those glyphs are hardware accelerated.
So which combinations do you claim have no hardware acceleration (and if possible, meet other conditions I actually listed, like modern screen resolutions)?
[1] https://github.com/mirror/busybox/blob/2d4a3d9e6c1493a9520b9...
1. Pixels, not glyphs
All laptops use a GPU since the very first PCs used BIOS routines to access the graphics card, which, surprise surprise, accelerate textmode to make it usable. You're proving my point.
Same goes for pretty much any MIPS router that connects to a screen. List your make and model, and I'll find the docs showing you how the GPU in it is used to draw characters in text mode.
Even the term "text mode" is a holdover from those 1970s era cards: they had dedicated graphics modes where you draw pixels, and hardware accelerated modes called textmode where ASCII bytes get drawn, by hardware acceleration, as characters.
I am not playing video games. I am not interested in "AI".
I do not need a GPU to use a hex editor. That would be a waste of electricity.
The earliest IBM PCs and compatibles used hardware acceleration for textmode, and those ancient BIOS interfaces and successors are still used to draw characters, not pixel by pixel, but with hardware acceleration.
So whether or not you like it, whether or not you understand how your laptop actually works, you're almost certainly using a GPU to render textmode.
> In case you don't have a GPU available, there are software rendered releases available for Windows and macOS
It has a built-in DSL that looks like Rust (without memory management, though – so it's very lightweight), and with that, it's possible to visualize and extract structural data from binary streams. That's really fun and cool.
It also has a visual editor to make simple calculations with no code. It didn't feel polished at the time I tried it. Strangely, writing code in DSL was more intuitive and easier for me.
The thing that's complicated of course, is that while it is a good idea and the basic idea is incredibly similar across implementations, there are just enough different concerns to make it hard to have one universal standard that can cover all of the use cases. It's hard enough to have a single parsing framework that handles both text parsing and binary format parsing well, but you also would need to consider the ability to incrementally parse/stream, read/write support, support arbitrary transformations, some formats need pointers, offsets, indices, and of course to what degree such a descriptor should be declarative versus imperative (declarative is better, but it gets increasingly hard to capture all details entirely in a purely declarative manner.)
I too have been working in this space for a while. Then I found out about kaitai stuct, lost some steam but regrouped. I do have some novel ideas and my dsl is less verbose than theirs :)
I have a DSL in go with cli tooling at https://github.com/martinlindhe/feng/
ImHex – A Hex Editor - https://news.ycombinator.com/item?id=32287902 - July 2022 (70 comments)
ImHex – A Hex Editor - https://news.ycombinator.com/item?id=25353965 - Dec 2020 (78 comments)
Commenter asks:
> also, question: Why is it called linux_keylogger?
(but also, carrying sensibly sized knife is illegal where I live)
Publish under a pseudonym with no links to your real identity, use dedicated communities that disregard DMCA takedowns. As long as you don't want to earn money this way, the worst that will happen is that your target notices your work and deploys vmprotect on their releases.
I reverse engineer things for a living and I have many peers worldwide who do the same. My main field of work is malware analysis.
For recreation, in my country it's explicitly legal to reverse engineer things you own, with a purpose of making it work on your system (think: fixing a windows XP game so it works on windows 10). This is a very broad loophole, and let's you reverse engineer things in most cases when they "feel" like they should be legal.
There wasn't anything illegal about that. I'm sure the vendor would've preferred we pay them to make reports for us but nothing legally prevented it.
Ghidra is, for the most part, not a hex editor. It’s meant for reverse engineering - mainly decompilation, but it’s useful for patching as well. The debugger is new and takes some getting used to (I’m still using GDB + Ghidra), but the disassembler and decompiler are top-notch.
If HexFiend/xxd are at one end of the spectrum, ghidra at the other, I imagine ImHex and tools like Kaitai are in the middle
Personally, for file format parsing I like to use Hachoir (specifically Hachoir-wx for GUI file structure browsing), which is a somewhat obscure bit of software that I’ve made some contributions to.
You just need a well lit room to use light mode.
No one complains that reading something on paper burns out your retinas. A light mode shouldn't either.
I always assumed that ImHex only supported dark mode, but it turns out that it does support light mode too!
The problem is that modern monitors are optimised for max brightness, not minimum. On my monitor I work on 0% brightness during the day. More is too bright already. During the night I turn down the contrast for lack of other options. That screws up colour depth though. Dark mode helps a ton too. A monitor that could display accurate colours at low brightness would be amazing but nobody cares enough to make one.
I have a pair of LG 24UD58-B 4K 24" monitors mounted on monitor arms:
https://www.amazon.com/dp/B01LPNKFK0/
One is above my ThinkPad P1 or X1 Extreme in landscape mode, the other to the left in portrait mode. I use all three displays.
I calibrated all three displays with an X-Rite (now Calibrite) Display Pro using DisplayCAL software.
For the two external monitors, the calibrator came up with these settings:
Brightness: 27
Contrast: 70
Gamma: Gamma 1
The specific RGB settings are slightly different between the two. One is: Red: 56
Green: 43
Blue: 40
And the other: Red: 39
Green: 42
Blue: 42
This settings make light modes very comfortable on both monitors, either during the day or at night with the room lights on. They are on a dimmer so I can adjust the lighting for comfort.For photo editing or watching a video, I crank up the brightness on the landscape monitor to 85.
I do something similar on my phone, a Samsung S24 Ultra. I use light themes and turn the phone brightness way down so it matches these other displays - unless I'm out in the sun and then I turn it way up.
I also turn up the brightness near max to look at photos or watch videos. Because of this, YouTube is the one app where I use a dark theme. This works well with the increased brightness.
The problem for me is that I live in a very hot country but I don't have air conditioning. At night I leave the balcony doors wide open but I don't like to keep any lights on which attract bugs. The lights from the street are enough to move around by. Even with dark themes and the contrast and brightness set way down the LG is still a bit too bright for comfort. And when an app opens that doesn't do dark mode.. ouch
I also have an old crt terminal (a Dec VT520) and I can set that so dim I can barely read it under those circumstances without being bothered by pwm or loss of fidelity.
Ps I really lament the lack of 24" 4K models on the market these days :'( 27" is a bit too big
I wonder if you have tried some of the custom settings under Picture/Picture Mode and Picture/Color Adjust? Picture Mode has a couple of dark room settings, and Color Adjust may let you turn down the brightness farther than the normal brightness setting allows.
Agree completely on the 24" vs. 27", especially because I use one of my monitors in portrait mode. 27" would be way too tall!
And that is what I use during the day - lol. This screen really is bad at low light performance. For the price (I think I paid 220 euro for it) I can forgive that because it's pretty decent in other ways.
> You just need a well lit room to use light mode.
Who wants a well-lit room at 3 AM?
Finally, when it does load on my Windows machine (using MSI installer and after convincing Microsoft that it is safe to run and bypassing their warning) it loads up super tiny on my 4k laptop screen and is unusable. I suppose I could mess about with the compatibility and scaling settings but I kind of lost interest after all of the above.
I tell you all this because obviously a lot of work went into this tool and from the screenshots it looks beautiful and useful, but is let down by the process involved to get it to run, at least on my machine.
For now, I will keep running HxD.
> Why would I do that unless I have a strong reason to use it rather than just
> move on with my day? A link is posted on HN for some cool software, it is
> already annoying to install it due to Microsoft complaining about it, then
> when I first run it, it opens up a tiny window an is asking if it can upload
> information. I don't expect to spend time figuring out its issues. I can't be
> the only one using a 4K display on Windows.
Spoken as a true reverse engineer, you should ask for a refund.Be lucky you get binaries at all, there are many projects that don't provide any at all, and are quite hostile to anyone asking for them!
Oh, it’s this one. I tried it a couple of years ago and it did this, and was somewhat awkward to fix IIRC.
It may even blow your mind that Google searches are not in fact the same for other people, and can vary in time, location, and the individual searching for something.
So perhaps you should explicitly say what your concern is?
When I search for werwolv, I get the person's github entry, and the german entry for 'Werewolf' https://de.wikipedia.org/wiki/Werwolf
probably not a good idea to pick a username sounding closely to that stuff.
I think it’s closer to, say, “beer hall”, which isn’t inherently Nazi even though “beer hall putsch” was their thing. They can still have beer halls.
(Or, direct link to using google translate to get the gist
https://de-m-wikipedia-org.translate.goog/wiki/Werwolf?_x_tr... )
You know the Nazis had plans called blue, red, yellow, pine tree, Icarus, heron, sea lion, northern lights, typhoon, Isabella, Hercules, etc? Should all those words now be stricken from the German lexicon because stupid Americans aren't able to consider that a German-speaker would use a common German word appropriately?