SrTools |
---|
[IDA!]
idafree.zip, 12.522.567 bytes... lotta bytes, biggest appz on my tools page... but WHAT for bytes!: IDA,
Ilfak's masterpiece,
version 3.85B, is a truly MAGICAL ITEM, kindly offered by Ilfak Guilfanov & Pierre
Vandevenne: BEST disassembler around when you really need to work... read what Pierre says about this release (end december 2000):
I've just made a new FREEWARE version of our IDA Pro disassembler available. It is basically last year's 3.85B commercial release, which means that it even supports FLIRT (Fasy Library Identification and Recognition Technology). There is no catch : it is free, supports the DOS / WIN 80x86 file formats we supported at that time and a couple of other things as well, no size limit, no time limit and is even somewhat supported (we'll fix reported bugs if practical). We are releasing it for tree reasons: - we are a bit tired of seeing poorly cracked versions going around; - we have made real progress with our new versions; - we realize there is a need for a non pro to investigate potentially hostile code on an amateur basis and that the budget for the full version shouldn't be an obstacle. The file can be found on our ftp idafree.zip @ datarescue Our ftp is a bit overloaded is now, redistribution of the file is ok, provided it is not altered.So download it [here] (@ fravia's) and enjoy! This is a truly wondrous cadeau by Pierre and Ilfak for all present and future reversers entering the third Millennium! Note that there's a dedicated messageboard for IDA-matters, see [here]. NEW!: An average of ~300 copies downloaded daily... lotta future reversers, I hope! Maybe with their help we'll even be able to win our [GNU powered] battles for free knowledge against the evil forces of commercial darkness! | Magical Item |
Wdasm (easy to find on the web) (You will have to find it ojn the web by yourself: I'm still awaiting Peter Urbanik's permission to link to it, in the mean time you'll be able to find it all over the web with banal searches). If you start to use it for real, please do register it, I have seldom seen such an useful program around. In fact I paid for my copy of wdasm. This quick disassembler still beats ida when you want to defeat an easy protections or you need to perform some simple "on the fly" code-reversing investigations (i.e. 70% of times). | Precious Item |
SOFTICE!!! Softice aka Winice aka sice aka
SI aka cutter aka (for older versions) memphis MUST HAVE TOOL FOR ANY REVERSER (easy to find on the web) search the web for it, 'trial', 'regged' and 'cracked' versions are to be find literally everywhere (everywhere software reversing activities are seriously performed, that's it), this target's names will mostly emerge like si405wi95.zip, SI405_9x.zip... that's for version 4.05... you get the idea... or try good ftp searches for subdirectories named sice or Softice or siw... and so on, if you'r serious about reversing software buy it (one of the VERY FEW pieces of software that deserves it in spades) @ Numega's (as long as they will be allowed to sell such a powerful software weapon. This is the most hated tool by those (bastards) that get the creeps seeing the [GNU/Free software] movement and ideas applied to the windoze world. Ancient History There were two older sice versions for dos: sice 2.6 (this version snaps in memory) and sice 2.8 (this version doesn't snap in memory). You'll find them 'searching the archies' and/or perusing older alleys of the web and/or once you will have found the ancient mythical "ORCpaks". |
Magical Item |
Ollydbg (Olly debug) by Oleh Yuschuk (thanks Oleh!)
v.1.09d (2005) [odbg109d.zip] : 1076224 bytes Oleh Yuschuk keeps improving his wondrous debugger. Now with SSE support, powerful run trace, improved code analysis, new search options or customizable user interface. see http://home.t-online.de/home/Ollydbg/ for details OllyDbg is a 32-bit code level debugger for Windows. Emphasis on binary code analysis makes it particularly useful in all those cases where source code is unavailable... as Oleh points out ;-) A list of discussion for OllyDbg users, moderated by TBD is at http://www.ollydbg.f2s.com; another messageboard, in spanish, is at http://ollydbg.cjb.net/. Please note that OllyDbg is free! Oleh (Ollydbg{ALT+64}t-online{POINT}de) is a great soul and has no intention to make OllyDbg commercial. The program is rated as a shareware only for copyright reasons. Moreover Oleh plans to release the source of his disassembler under GPL! | Precious Item |
Filemon: [filesrc.zip]
: 323906 bytes Mark Russinovich & Bryce Cogswell, @ [sysinternals] deserve the reversing Nobel, and more for their fabulous tools... (Process Explorer, Filemon, Regmon, and PsTools). |
Precious Item |
Resource hacker: [reshack.zip]
by Angus Johnson: 542549 bytes,
mighty wizardish power for your software fiddling and reversing wishes! Thanks fake faulty: indeed it looks like Angus decided to develop good old borland trw! Vielen Dank Angus! :-) Ahem... let's see if you understand what the following words (could) mean... "Resources can be added to an executable as long as no resource of the same type, name and language id already exists. Select Action | Add a New Resource ... from the menu". Eh? :-) And do you grasp what the following words (could) mean?... "New controls can also be added. The Control Editor supports virtually all Microsoft’s currently defined standard and common control classes. User defined custom classes can also be added to the predefined list of classes by carefully editing the “dialog.def” text file which can be found in the same folder as Resource Hacker" Eheh :-) | Precious Item |
customiz.zip ~ 653537 bytes customiz.zip [The customizer per anthonomasia, version 1.10] You'll find this even more useful than poledit when your system administrator or your software programmer has chosen to 'disable' some options... :-) See for instance how you can modify on the fly the webferret bot in this essay. See also another interesting use of the customizer (tweaking EULAs) in this [conference of mine] customiz.exe ~ 692224 bytes: this is customiz.zip version 1.10 autoextracting as exe very useful when you need to perform some quick tweakings from -say- a web-café ;-) cust115.zip ~ 272528 bytes: cust115.zip [The customizer per anthonomasia, version 1.15] A ridicolous time check protection... any kid could set all FOUR occurrences of 000007D1 (if you have installed it in 2001) to -say- 00000BB9 with the result that the program will expire in 3001. (And if that's not enough... set all four to 00000FA1 :-) Maybe the good people at wanga should learn [some better tricks] to protect this most useful appz. | Precious Items |