She-geeks Forum
May 28, 2012, 01:40:26 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Don't forget our main site at she-geeks.com 'lots of goodies'.
 
   Home   Help Search Login Register  
Pages: 1   Go Down
  Print  
Author Topic: eEye Binary Diffing Suite (EBDS)  (Read 367 times)
0 Members and 2 Guests are viewing this topic.
fraggle
Honored Member
Full Member
**********

Karma: 722
Offline Offline

Posts: 205



WWW
« on: June 18, 2008, 04:02:46 PM »

Quote
The eEye Binary Diffing Suite (EBDS) is a free and open source set of utilities for performing automated binary differential analysis. This becomes very useful for reverse engineering patches as well as program updates.

The first tool is BDS, the Binary Diffing Starter from Andre Derek Protas. This tool helps reverse engineers with batch-analysis of patches by dispatching IDA with its many powerful plugins against groups of binaries. This especially comes in useful for Update Rollups or Service Packs, where automation is necessary to be able to reverse engineer the updates in a reasonable amount of time. NOTE: .NET Framework 2+ is required for BDS to function.

The second tool is DarunGrim, a code-analysis tool to actually find the distinct code-changes between two binaries. In Korean, DarunGrim translates to "difference in picture". DarunGrim performs multiple matching techniques against functions in order to find function pairs and analyze the differences/similarities between the functions. This allows reverse engineers to pinpoint code changes between two binaries with a graphical interface, much more rapid than "side-by-side" disassembly instances. Much like most powerful disassembly tools, DarunGrim is also using the power of IDA Pro for analysis.

http://research.eeye.com/html/tools/RT20060801-1.html

also video tutorials available for a better understanding how ebds works. i thought this could be interesting, because the diffing technique is also a necessary feature of the automated-patch-based-exploit-generation ( maybe someone of you heared about that, http://isc.sans.org/diary.html?storyid=4310 ).
Logged

>>All the war-propaganda, all the screaming and lies and hatred, comes invariably from people who are not fighting.<<

George Orwell
Pages: 1   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
.
Custom Search