<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; IDA-pro</title>
	<atom:link href="http://www.darknet.org.uk/tag/ida-pro/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Turbodiff v1.01 BETA Released &#8211; Detect Differences Between Binaries</title>
		<link>http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/</link>
		<comments>http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 06:59:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[binary diff]]></category>
		<category><![CDATA[binary difference]]></category>
		<category><![CDATA[compare binaries]]></category>
		<category><![CDATA[compare binary files]]></category>
		<category><![CDATA[disassembler]]></category>
		<category><![CDATA[ida]]></category>
		<category><![CDATA[ida pro binary diff]]></category>
		<category><![CDATA[ida pro plugin]]></category>
		<category><![CDATA[IDA-pro]]></category>
		<category><![CDATA[turbo diff]]></category>
		<category><![CDATA[turbodiff]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2215</guid>
		<description><![CDATA[Turbodiff is a binary diffing tool developed as an IDA plugin. It discovers and analyzes differences between the functions of two binaries. Requirements &#8220;Turbodiff 1.01 beta release 1&#8243; works with IDA starting from v5.0. Instructions For the binaries: Download the plugin and store it at the directory &#8220;..\IDA\plugins&#8221;. If you want to compile it on [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Turbodiff is a binary diffing tool developed as an <a href="http://www.hex-rays.com/idapro/">IDA plugin</a>. It discovers and analyzes differences between the functions of two binaries.</p>
<p><strong>Requirements</strong></p>
<p>&#8220;Turbodiff 1.01 beta release 1&#8243; works with IDA starting from v5.0.</p>
<p><strong>Instructions</strong></p>
<p>For the binaries:<br />
Download the plugin and store it at the directory &#8220;..\IDA\plugins&#8221;.</p>
<p>If you want to compile it on your own: We have compiled it and tested it using Borland C. For the free version of IDA Pro (4.9) you&#8217;ll need to first:</p>
<ol>
<li>Generate the ida_free.lib library. To do this execute: &#8220;implib -c ida_free.lib ida_free.def&#8221;</li>
<li>Next, you must have the linker use this library.</li>
<li>Compile.</li>
</ol>
<p>Comparing two files:</p>
<ol>
<li>Open the first file to be compared with IDA and run /Option 1 (take info from this idb)/ from the plugin. Close.</li>
<li>Open the second file to be compared with IDA and run /Option 1 (take info from this idb)/ from the plugin.<br />
Use /Option 2 (compare with&#8230;)/ from the plugin, and when prompted to select a file, select the first file. </li>
<li>Chose if you want a log file to be genreated and run. Once finished a functions table will popup (watch Figure 1) describing results. The results are then saved for later usage.</li>
</ol>
<p>You can download Turbodiff here:</p>
<p>IDA PRO v4.9 <a href="http://corelabs.coresecurity.com/index.php?module=Wiki&#038;action=attachment&#038;type=tool&#038;page=turbodiff&#038;file=turbodiff-for-free-ida_v1.0.1b2.zip">Sources and plugin</a> (Free version)<br />
IDA starting with version v5 <a href="http://corelabs.coresecurity.com/index.php?module=Wiki&#038;action=attachment&#038;type=tool&#038;page=turbodiff&#038;file=turbodiff_v1.0.1b2.zip">Sources and plugin</a></p>
<p></p>
<p>Or read more <a href="http://corelabs.coresecurity.com/index.php?module=Wiki&#038;action=view&#038;type=tool&#038;name=turbodiff">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2215+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;t=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;title=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;title=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;title=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;title=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F11%2Fturbodiff-v1-01-beta-released-detect-differences-between-binaries%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eEye Binary Diffing Suite (EBDS)</title>
		<link>http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/</link>
		<comments>http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/#comments</comments>
		<pubDate>Wed, 02 Aug 2006 08:34:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[binary-diffing]]></category>
		<category><![CDATA[binary-diffing-suite]]></category>
		<category><![CDATA[coding]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[ebds]]></category>
		<category><![CDATA[eeye]]></category>
		<category><![CDATA[IDA-pro]]></category>
		<category><![CDATA[patch-hacking]]></category>
		<category><![CDATA[reverse-engineering]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/</guid>
		<description><![CDATA[The eEye Binary Diffing Suite (EBDS) is a free and open source set of utilities for performing automated binary differential analysis. This becomes very useful for reverse engineering patches as well as program updates. The first tool is BDS, the Binary Diffing Starter from Andre Derek Protas. This tool helps reverse engineers with batch-analysis of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>The eEye Binary Diffing Suite (EBDS) is a free and open source set of utilities for performing automated binary differential analysis. This becomes very useful for reverse engineering patches as well as program updates.</p>
<p>The first tool is BDS, the Binary Diffing Starter from Andre Derek Protas. This tool helps reverse engineers with batch-analysis of patches by dispatching IDA with its many powerful plugins against groups of binaries. This especially comes in useful for Update Rollups or Service Packs, where automation is necessary to be able to reverse engineer the updates in a reasonable amount of time.</p>
<p>The second tool is DarunGrim, a code-analysis tool to actually find the distinct code-changes between two binaries. In Korean, DarunGrim translates to &#8220;difference in picture&#8221;. DarunGrim performs multiple matching techniques against functions in order to find function pairs and analyze the differences/similarities between the functions.</p>
<p>This allows reverse engineers to pinpoint code changes between two binaries with a graphical interface, much more rapid than &#8220;side-by-side&#8221; disassembly instances. Much like most powerful disassembly tools, DarunGrim is also using the power of IDA Pro for analysis.</p>
<p>You can download it here:</p>
<p><a href="http://research.eeye.com/html/Tools/download/DiffingSuiteSetup.exe">EBDS v1.0.1</a></p>
<p></p>
<p>More info <a href="http://research.eeye.com/html/tools/RT20060801-1.html">here</a>, IDA.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=eEye+Binary+Diffing+Suite+%28EBDS%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D309+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/&amp;t=eEye+Binary+Diffing+Suite+%28EBDS%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/&amp;title=eEye+Binary+Diffing+Suite+%28EBDS%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/&amp;title=eEye+Binary+Diffing+Suite+%28EBDS%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/&amp;title=eEye+Binary+Diffing+Suite+%28EBDS%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/&amp;title=eEye+Binary+Diffing+Suite+%28EBDS%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F08%2Feeye-binary-diffing-suite-ebds%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/08/eeye-binary-diffing-suite-ebds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

