📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Help needed with: getting the right format into IDA

Topic created on: February 4, 2010 01:41 CST by Metalskin .

I need Help!!!

1. I try to track the input streaming of data from a download via wireshark. these data is store in raw format.

2. I wishes to retrieve this format and put it into IDA for viewing its code. but i just couldn't get the right format.

Any one experience to help mi??

  RabidCicada     February 9, 2010 11:01.13 CST
You need to be MUCH more clear on what you are trying to do.

IDA Pro (Interactive DissAssembler Pro) is intended to dissect and reverse engineer software Code.  This implies that the "data" which you are putting into IDA is actually code and not just some raw data.  IDA must be able to recognize what kind of code it's analyzing and you can overide and provide hints for how IDA should look at the code.

Usually anything you catch via wireshark is simply just data...unless you are watching binary excetuable code being transferred across the network.

In either case both tools work to identify what you are looking at.  IDA will try to auto recognize the file format.
If it doesn't have a "signature" for that file format it will not auto load and analyze.  In that case you will have to manually tell it how to load the file (not trivial...get the IDA Pro Book or surf the web some more, I'm not going to explain)

Wireshark will try to identify protocols it recognizes.  But that will only work for "standard" protocols.  By standard, I mean those protocols implemented enough that someone has written a "dissector" module for it in wireshark.

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit