-
-
eEye Binary Diffing Suite (EBDS)[下载]
-
发表于: 2007-4-24 12:33 5959
-
eEye Binary Diffing Suite (EBDS)
The eEye Binary Diffing Suite (EBDS) is a free and open source set of utilities for performing automated binary differential analysis. This becomes very useful for reverse engineering patches as well as program updates.
The first tool is BDS, the Binary Diffing Starter from Andre Derek Protas. This tool helps reverse engineers with batch-analysis of patches by dispatching IDA with its many powerful plugins against groups of binaries. This especially comes in useful for Update Rollups or Service Packs, where automation is necessary to be able to reverse engineer the updates in a reasonable amount of time. NOTE: .NET Framework 2+ is required for BDS to function.
The second tool is DarunGrim, a code-analysis tool to actually find the distinct code-changes between two binaries. In Korean, DarunGrim translates to "difference in picture". DarunGrim performs multiple matching techniques against functions in order to find function pairs and analyze the differences/similarities between the functions. This allows reverse engineers to pinpoint code changes between two binaries with a graphical interface, much more rapid than "side-by-side" disassembly instances. Much like most powerful disassembly tools, DarunGrim is also using the power of IDA Pro for analysis.
[Download v1.0.5]
http://research.eeye.com/html/Tools/download/DiffingSuiteSetup.exe
Additional Information
Last Update: November 3rd, 2006
Update Notes: Enhanced graphical view of DarunGrim diffing results. Enhanced DarunGrim Analysis on hotpatching prefix in MS binaries. Fixed access violation bug in DarunGrim Analida plugin. Added analIDA src files: AddrMap.h, Database.h, IdaIncludes.h, Database.cpp.
Comments:
二进制比较工具(主要用于Patch分析)
IDA相关
有源码
dotNet2+平台
赞赏
他的文章
看原图
赞赏
雪币:
留言: