инструментарий крекера\реверсера

Discussion in 'Реверсинг' started by ProTeuS, 30 Sep 2006.

  1. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    Code:
    Resource Hacker FX
    [​IMG]
    res_fx

    What does the patcher change:
    Resource Hacker FX does not create tree nodes for every language. Usually only one language is used anyway, so it makes it much faster to navigate through resources.
    [​IMG]
    Resource Hacker FX uses the new open and save common dialogs instead of the old outdated ones. Also, some saving as parameters got improved: the directory of the current file is initially shown, the file name gets filled, the extension is automatically added if not specified.
    If you have a modified file open and you close Resource Hacker FX, you have a Cancel option when asked whether you would like to save the file. Also, if you choose to save it, it just gets saved instead of saving as.
    The HEX viewer shows only the first 10 KB of the binary resource by default to prevent hanging Resource Hacker FX. I could not really fix it, as it’s the Rich Edit control’s fault, it’s quite slow with large texts. Well, it’s not too smart to use Rich Edit to view a HEX dump, but that’s how it works. 10 KB should be usually enough to understand what the resource is about. If it isn’t, you can hold shift to load the whole resource.
    Some more small stuff, like e.g. minimizing/maximizing effects.

    -----
    /собсна мона грить,апдейт/
    -----
     
  2. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    2011.03.31 Syser Debugger 1.99.1900.1207 Release
    [+]Support window 7 sp1
    link
     
    2 people like this.
  3. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    dirtyJOE

    Java Overall Editor is a complex editor and viewer for compiled java binaries (.class files). Current version still has some limitations, but hopefully those will be removed within the next releases.

    download

    download (x64)
     
  4. trotil

    trotil Member

    Joined:
    10 Jan 2009
    Messages:
    60
    Likes Received:
    5
    Reputations:
    4
    IDA PRO 6.1

    Ida pro 6.1
    Ida 6.1 <----LINK_1

    ida pro 6.1 <----LINK_1

    По слухам Китайцы скардили, ставите на свой страх и риск, ключа нет!
    спасибо exelab.ru
     
    #124 trotil, 10 Jun 2011
    Last edited: 10 Jun 2011
  5. trotil

    trotil Member

    Joined:
    10 Jan 2009
    Messages:
    60
    Likes Received:
    5
    Reputations:
    4
    Раздача <====LINK

    IDA pro 6.1 all RDW

    спасибо за усилия и находку Sp0Raw
     
  6. neprovad

    neprovad Elder - Старейшина

    Joined:
    19 Oct 2007
    Messages:
    900
    Likes Received:
    274
    Reputations:
    59
    Red Gate Reflector VSPro v7.3.0.18

    Red Gate Reflector VSPro v7.3.0.18

    http://depositfiles.com/files/guzi6nwdz/Red.Gate.Reflector.VSPro.v7.3.0.18-REDT.rar
    http://www.filesonic.com/file/1465989874/Red.Gate.Reflector.VSPro.v7.3.0.18-REDT.rar
    http://wupload.com/file/59600592/Red.Gate.Reflector.VSPro.v7.3.0.18-REDT.rar
     
  7. neprovad

    neprovad Elder - Старейшина

    Joined:
    19 Oct 2007
    Messages:
    900
    Likes Received:
    274
    Reputations:
    59
    X-Ways WinHex v16.1

    hex редактор файлов, дисков, памяти процессов.

    X-Ways.WinHex.v16.1.Incl.Keymaker-ZWT
    http://www.multiupload.com/58NH29GEPN
     
  8. neprovad

    neprovad Elder - Старейшина

    Joined:
    19 Oct 2007
    Messages:
    900
    Likes Received:
    274
    Reputations:
    59
    Syser Enterprise Edition v1.99.1900.1220

    Очередная версия ring0 отладчика.
    http://depositfiles.com/files/ozoe4j2wn/Sysersoft.Syser.Kernel.Debugger.Enterprise.Edition.v1.99.1900.1220.Incl.KeyMaker-DVT.rar
     
  9. t3cHn0iD

    t3cHn0iD Banned

    Joined:
    6 Apr 2009
    Messages:
    313
    Likes Received:
    63
    Reputations:
    66
    OllyDbgV2.01d + Plugins

    Olly Debugger 2.0.1d
    9 plugins

    OllyDbg2 в темном стиле вместе с плагинами


    Информация о плагинах здесь

    PS.Распаковывать WinRAR'ом последней версии (4.01)

    UPD.От себя отмечу, что текущий билд олли дебаггера очень нестабилен, поэтому на плагинах он будет падать скорее всего.
     
    #129 t3cHn0iD, 14 Sep 2011
    Last edited: 15 Sep 2011
  10. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    Scylla Imports Reconstruction 0.4

    Scylla Imports Reconstruction

    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
    ImpREC, CHimpREC, Imports Fixer... this are all great tools to rebuild an import table, but they all have some major disadvantages, so I decided to create my own tool for this job.
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|


    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
    Scylla's key benefits are:
    x64 and x86 support
    full unicode support (probably some russian or chinese will like this :) )
    written in C/C++
    plugin support
    works great with Windows 7
    Currently there are only 2 plugins (PECompact, PESpin x64) in this release, full sourcecode for both is included.
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|

    [>]
    link
     
    #130 swt1, 3 Oct 2011
    Last edited: 3 Oct 2011
  11. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    Scylla Imports Reconstruction 0.5

    Scylla Imports Reconstruction
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
    ImpREC, CHimpREC, Imports Fixer... this are all great tools to rebuild an import table, but they all have some major disadvantages, so I decided to create my own tool for this job.
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
    Scylla's key benefits are:
    x64 and x86 support
    full unicode support (probably some russian or chinese will like this :) )
    written in C/C++
    plugin support (ImpREC plugins are supported)
    works great with Windows 7
    Currently there are only 2 plugins (PECompact, PESpin x64) in this release, full sourcecode for both is included.

    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
    What's New in Version 0.5 (See full changelog)
    - added save/load import tree feature
    - multi-select in tree view
    - fixed black icons problem in tree view
    - added keyboard shortcuts
    - dll dump + dll dump fix now working
    - added support for scattered IATs
    - pre select target path in open file dialogs
    - improved import resolving engine with api scoring
    - minor bug fixes and improvements
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|

    link
     
  12. neprovad

    neprovad Elder - Старейшина

    Joined:
    19 Oct 2007
    Messages:
    900
    Likes Received:
    274
    Reputations:
    59
    SysTracer

    SysTracer
    Небольшая компактная утилита для мониторинга изменений файлов\реестра\загрузки драйверов.
    Основной плюс по сравнению с ProcessMonitor - лаконичный вид логов.
    Оффсайт http://www.sysreveal.com/category/systracer/
    Ссылка http://www.sysreveal.com/download/SysTracer.zip
     
  13. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    I.F (1.6 PuBLiC)

    Imports Fixer (abbreviated to IF hereafter) has been specifically created to assist in the process of rebuilding and reconstructing portable executable files found in memory. IF has been designed to rebuild imports for Win32 Portable Executable and Dynamic Link Libraries (DLL's). With IF one can dump a "running" executable to disk even after cutting away unwanted sections or after including the allocated memory blocks of your choice in the dump (which is very useful when dealing with redirected API's). IF allows you to easily reconstruct a new Image Import Descriptor (IID), Import Array Table (IAT) with ASCII modules and function names. IF can rebuild section tables even in the case of cut sections or allocated memory blocks dumped as new sections. With IF you can edit the Optional Header Data and edit the sections.

    download

    support & etc

    -------------------------------------------
    старо канеш,но решил всё же запостить. |
    -------------------------------------------
     
    #133 swt1, 12 Feb 2012
    Last edited: 12 Feb 2012
  14. CatalystX

    CatalystX New Member

    Joined:
    5 Sep 2011
    Messages:
    36
    Likes Received:
    0
    Reputations:
    0
    Есть ли какая-то замена OllyDBG под x64? Windbg не предлагать.
     
  15. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    ida pro
     
  16. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
  17. tim-oleksii

    tim-oleksii Member

    Joined:
    14 Mar 2011
    Messages:
    199
    Likes Received:
    10
    Reputations:
    0
    Кто-то встречал hex rays для arm?
     
  18. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    D!E
    [​IMG]
    каг птица феникс.
     
    1 person likes this.
  19. swt1

    swt1 Elder - Старейшина

    Joined:
    16 Feb 2008
    Messages:
    306
    Likes Received:
    78
    Reputations:
    21
    DIZAHEX DISASSEMBLER ENGINE

    DIZAHEX - небольшой дизассемблерный движок, предназначенный для анализа x86/x86-64 (+ 16-разрядного)
    кода. Может использоваться как самостоятельный двигл, так и совместно с какими-либо другими движками:
    пермутатор, эмулятор, виртуальная машина итд. Варианты применения прежде всего в вирусах/червях/троянах,
    навесных защитах (пакеры, крипторы, протекторы) =). А также в других программах.
    Author: pr0mix
    [​IMG]
    url
     
    1 person likes this.
  20. chuna

    chuna New Member

    Joined:
    2 Apr 2013
    Messages:
    0
    Likes Received:
    1
    Reputations:
    0
    http://www.android-decompiler.com/download.php
    JEB decompiler.com
    http://rghost.net/54459472