Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 07-19-2015, 04:38
schrodinger schrodinger is offline
Friend
 
Join Date: Jan 2015
Posts: 24
Rept. Given: 2
Rept. Rcvd 4 Times in 1 Post
Thanks Given: 10
Thanks Rcvd at 1 Time in 1 Post
schrodinger Reputation: 4
Exclamation How to port function names from one exe to another?

Hello,
I have two executable elf files for one program but with 2 different version.
IDA can resolve the function names in one of them while not for the other.
Bindiff is the tool of choice I think but it is not working for 64 bit.What can be done to solve this issue?
Reply With Quote
  #2  
Old 07-19-2015, 06:18
Apuromafo Apuromafo is offline
Family
 
Join Date: Nov 2010
Location: Chile
Posts: 112
Rept. Given: 30
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 217
Thanks Rcvd at 168 Times in 60 Posts
Apuromafo Reputation: 26
Use a vm example oracle vm virtualbox, put a windows xps3 or windows 7 /8 x86 and you must will done ...
Reply With Quote
  #3  
Old 07-19-2015, 07:55
Naides Naides is offline
Friend
 
Join Date: Mar 2005
Location: Planet Earth
Posts: 40
Rept. Given: 7
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 21
Thanks Rcvd at 10 Times in 7 Posts
Naides Reputation: 2
If you are analyzing 32 bit elf files you can use IDA 32 bit even in a 64 OS environment. And Bindiff should work. If the elf files are 64 bit, then trying the analysis on a x86 system will not help. Try a earlier version 3.x of Bindiff. Not all the bells and whistles, but I remember IDA x64 module did not crash.
Reply With Quote
  #4  
Old 07-19-2015, 08:32
schrodinger schrodinger is offline
Friend
 
Join Date: Jan 2015
Posts: 24
Rept. Given: 2
Rept. Rcvd 4 Times in 1 Post
Thanks Given: 10
Thanks Rcvd at 1 Time in 1 Post
schrodinger Reputation: 4
Quote:
Originally Posted by Naides View Post
If you are analyzing 32 bit elf files you can use IDA 32 bit even in a 64 OS environment. And Bindiff should work. If the elf files are 64 bit, then trying the analysis on a x86 system will not help. Try a earlier version 3.x of Bindiff. Not all the bells and whistles, but I remember IDA x64 module did not crash.
can you please upload older bindiff (I want to try 4.01 or 3x)
Do you know if 4.0 works for 64 bit ?
Reply With Quote
  #5  
Old 07-19-2015, 09:43
Naides Naides is offline
Friend
 
Join Date: Mar 2005
Location: Planet Earth
Posts: 40
Rept. Given: 7
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 21
Thanks Rcvd at 10 Times in 7 Posts
Naides Reputation: 2
Alternative solution found in a chinese Hacking place.

http://www.h4ck.org.cn/2014/08/ida64-fatal-error-before-kernel-init/

Rename the file: Zynamics_binexport_8.p64, found in IDA\plugins to something else. IDA will now work. I have not tested the functionality though.
Reply With Quote
  #6  
Old 07-19-2015, 09:53
Naides Naides is offline
Friend
 
Join Date: Mar 2005
Location: Planet Earth
Posts: 40
Rept. Given: 7
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 21
Thanks Rcvd at 10 Times in 7 Posts
Naides Reputation: 2
Files too big to upload. I have Ver 4.0
Reply With Quote
  #7  
Old 07-19-2015, 22:47
Naides Naides is offline
Friend
 
Join Date: Mar 2005
Location: Planet Earth
Posts: 40
Rept. Given: 7
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 21
Thanks Rcvd at 10 Times in 7 Posts
Naides Reputation: 2
ver 4.01 works. PM if you need a link.
Reply With Quote
The Following User Says Thank You to Naides For This Useful Post:
darsy (08-04-2015)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to shuffle names in the PE import table? Newbie_Cracker General Discussion 5 08-25-2019 03:59
IDA v4.8 Prof. Standard : To load databases created in blacklisted licensee names. ketan General Discussion 2 05-25-2005 20:26


All times are GMT +8. The time now is 09:34.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )