吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 5785|回复: 6
收起左侧

[IDA Plugin] IDA Entropy Plugin 0.1

[复制链接]
Hmily 发表于 2010-6-30 23:33
Utility for entropy calculation of 32-bit executable and binary files released. It can be usefull for express searching of a file blocks with a high entropy - encrypted chunks, encryption keys, etc. Utility can be built as a IDA plugin and as a standalone utility.
It allow to calculate entropy of a sections of the file by utility launch, calculate entropy of any block of the file, build entropy map of a specified section.





Double-click on the row in ListView copies Address and Length to appropiate fields on the form. Calculate button shows entropy for a data block from StartAddress to StartAddress + Length. Draw button allows to build entropy map of the data block. ChunksSize specifies a length of chunks used for entropy calculation in this mode. And StepSize fileld is used as a indent between current and next chunks. Double-click on the map in IDA plugin mode allows to go to the specified location in IDA listing.





Deep Analyze button performs a lot of calculations from StartAddress to StartAddress + Length with a varing block size from 1 to ChunkSize and with StepSize indent. If calculated entropy value greater than MaxEntropy for the chunk, it will be added to result report. Double-click on the row in IDA plugin mode allows to go to the specified location in IDA listing.





Launch feature in IDA plugin mode is IDA listing selection check. I.e. utility fills StartAddress, Length and pushs to Calculate button. To start utility as IDA plugin simply copy in to ./IDA/plugins/ and press F11 (default hotkey) or choose Edit -> Plugins ->Entropy plugin.
In standalone mode utility shows GetOpenFileName dialog when started without command-line parameters. Command line format is "ida-ent.exe [-sw] filename", where switches are one of the following: --binary (-b), --pe (-p), --elf (-e). By default utility tries to determine file format (PE, ELF) by checking signature.
Sources (for MS Visual C++ 2008 EE) and precompiled standalone utulity, IDA Pro 5.5 plugin, IDA Free 4.9 plugin are available in the archive.

http://smokedchicken.org/2010/06/ida-entropy-plugin.html

IDA Entropy Plugin v0.1.7z

1.66 MB, 下载次数: 141, 下载积分: 吾爱币 -1 CB

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

Skyfly 发表于 2010-7-1 00:07
老大 这是什么啊 看不懂-_.-!
bbwtjjw 发表于 2010-7-1 00:12
reckless 发表于 2010-7-1 15:26
Alar30 发表于 2010-7-1 22:12
看看神器的新插件哈
wei123 发表于 2010-7-1 23:37
一直不会IDA..教材不多
goodyou520 发表于 2010-7-17 15:54
不错  谢谢奉享
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-5-1 20:28

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表