Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Help needed with: getting the right format into IDA

Topic created on: February 4, 2010 01:41 CST by Metalskin .

I need Help!!!

1. I try to track the input streaming of data from a download via wireshark. these data is store in raw format.

2. I wishes to retrieve this format and put it into IDA for viewing its code. but i just couldn't get the right format.

Any one experience to help mi??

  RabidCicada     February 9, 2010 11:01.13 CST
You need to be MUCH more clear on what you are trying to do.

IDA Pro (Interactive DissAssembler Pro) is intended to dissect and reverse engineer software Code.  This implies that the "data" which you are putting into IDA is actually code and not just some raw data.  IDA must be able to recognize what kind of code it's analyzing and you can overide and provide hints for how IDA should look at the code.

Usually anything you catch via wireshark is simply just data...unless you are watching binary excetuable code being transferred across the network.

In either case both tools work to identify what you are looking at.  IDA will try to auto recognize the file format.
If it doesn't have a "signature" for that file format it will not auto load and analyze.  In that case you will have to manually tell it how to load the file (not trivial...get the IDA Pro Book or surf the web some more, I'm not going to explain)

Wireshark will try to identify protocols it recognizes.  But that will only work for "standard" protocols.  By standard, I mean those protocols implemented enough that someone has written a "dissector" module for it in wireshark.

Note: Registration is required to post to the forums.

There are 28,212 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
Ludwig
Feb/04
chi on sale

Ludwig
Feb/04
Monster In The Vicinity Of ...

Ludwig
Feb/04
Supra footwear Online

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

More ...


Recent Blog Comments
waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

NirIzr on:
Jan/31
Yet Another Anti-Debug Trick

jackchen on:
Jan/10
nike mercurial vapor iii

waleedassar on:
Dec/27
A new Anti-Olly trick.

PeterFerrie on:
Dec/27
A new Anti-Olly trick.

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit