Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Help needed with: getting the right format into IDA

Topic created on: February 4, 2010 01:41 CST by Metalskin .

I need Help!!!

1. I try to track the input streaming of data from a download via wireshark. these data is store in raw format.

2. I wishes to retrieve this format and put it into IDA for viewing its code. but i just couldn't get the right format.

Any one experience to help mi??

  RabidCicada     February 9, 2010 11:01.13 CST
You need to be MUCH more clear on what you are trying to do.

IDA Pro (Interactive DissAssembler Pro) is intended to dissect and reverse engineer software Code.  This implies that the "data" which you are putting into IDA is actually code and not just some raw data.  IDA must be able to recognize what kind of code it's analyzing and you can overide and provide hints for how IDA should look at the code.

Usually anything you catch via wireshark is simply just data...unless you are watching binary excetuable code being transferred across the network.

In either case both tools work to identify what you are looking at.  IDA will try to auto recognize the file format.
If it doesn't have a "signature" for that file format it will not auto load and analyze.  In that case you will have to manually tell it how to load the file (not trivial...get the IDA Pro Book or surf the web some more, I'm not going to explain)

Wireshark will try to identify protocols it recognizes.  But that will only work for "standard" protocols.  By standard, I mean those protocols implemented enough that someone has written a "dissector" module for it in wireshark.

Note: Registration is required to post to the forums.

There are 16,512 total registered users.


Recently Created Topics
wsnpoem audio.dll
Mar/09
suggestions - RE tra...
Mar/09
Requesting Suggestio...
Mar/06
Force enable debug p...
Mar/05
upgrading new image ...
Mar/03
upgrading new image ...
Mar/03
upgrading new image ...
Mar/03
Can some one give me...
Mar/02
Error in generating ...
Feb/28
Problem debuggin Dir...
Feb/28


Recent Forum Posts
suggestions - RE tra...
RolfRolles
wsnpoem audio.dll
debbie
Requesting Suggestio...
secursig
Requesting Suggestio...
phn1x
how to get executabl...
RabidCi...
how to get executabl...
RabidCi...
Force enable debug p...
Silkut
Can some one give me...
wildinto
Problem debuggin Dir...
Silkut
IDA Pro plug-in &quo...
cseagle


Recent Blog Entries
RolfRolles
Mar/08
Compiler Optimizations for ...

ReWolf
Mar/04
When memory management goes...

thesprawler
Feb/20
log1949.txt -- Wondering ho...

thesprawler
Feb/20
log1949.log -- created on C...

thesprawler
Feb/17
Trying to reverse the firmw...

More ...


Recent Blog Comments
bughoho on:
Mar/09
Compiler Optimizations for ...

cliffwolf on:
Mar/08
Compiler Optimizations for ...

Orr on:
Mar/08
When memory management goes...

GynvaelColdwind on:
Mar/07
When memory management goes...

petroleum on:
Mar/06
When memory management goes...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit