mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,4 Tsd.
aktive Profile

#decai

0 Beiträge0 Beteiligte0 Beiträge heute
cryptax<p>Decai decompiling a malicious shellcode. <br>The instructions are not so readable, if you're not used to syscalls int 0x80. AI does it for you.</p><p><a href="https://asciinema.org/a/4PY8wn2TPg2oBdDQ0Q5bgMYjk" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">asciinema.org/a/4PY8wn2TPg2oBd</span><span class="invisible">DQ0Q5bgMYjk</span></a></p><p><a href="https://mastodon.social/tags/r2ai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2ai</span></a> <a href="https://mastodon.social/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> <a href="https://mastodon.social/tags/r2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2</span></a> <a href="https://mastodon.social/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> <a href="https://mastodon.social/tags/shellcode" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>shellcode</span></a> <a href="https://mastodon.social/tags/syscall" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>syscall</span></a> <a href="https://mastodon.social/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a></p>
cryptax<p>A blog post on r2ai / decai by <span class="h-card" translate="no"><a href="https://infosec.exchange/@pancake" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>pancake</span></a></span> which shows decompiling to Swift : </p><p><a href="https://www.nowsecure.com/blog/2025/01/29/decompiling-apps-with-ai-language-models/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">nowsecure.com/blog/2025/01/29/</span><span class="invisible">decompiling-apps-with-ai-language-models/</span></a></p><p><a href="https://mastodon.social/tags/radare2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>radare2</span></a> <a href="https://mastodon.social/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> <a href="https://mastodon.social/tags/decompile" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decompile</span></a> <a href="https://mastodon.social/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a></p>
cryptax<p>r2ai solves my CrackMe in a few seconds. It's both elegant and educational.</p><p>Read this: <a href="https://cryptax.medium.com/cracking-my-own-crackme-with-r2ai-5629bcc7d5fe" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">cryptax.medium.com/cracking-my</span><span class="invisible">-own-crackme-with-r2ai-5629bcc7d5fe</span></a></p><p>And view <span class="h-card" translate="no"><a href="https://infosec.exchange/@dnakov" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>dnakov</span></a></span> video at r2con: <a href="https://www.youtube.com/watch?v=UxE5GNUBCXo" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=UxE5GNUBCXo</span><span class="invisible"></span></a></p><p>cc: <span class="h-card" translate="no"><a href="https://infosec.exchange/@radareorg" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>radareorg</span></a></span> </p><p><a href="https://mastodon.social/tags/radare2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>radare2</span></a> <a href="https://mastodon.social/tags/r2ai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2ai</span></a> <a href="https://mastodon.social/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> <a href="https://mastodon.social/tags/crackme" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>crackme</span></a></p>
cryptax<p>I've been running decai with Claude AI on a malware named Goldoon.</p><p>Ghidra is usually quite good to decompile, but just compare the decompiled output with r2 (<span class="h-card" translate="no"><a href="https://infosec.exchange/@radareorg" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>radareorg</span></a></span>) decai/Claude and ghidra!<br>This is marvelous. So much clear and concise + Claude immediately thought this was malicious (I didn't hint anything).</p><p>NB. I will talk about this at <span class="h-card" translate="no"><a href="https://infosec.exchange/@1ns0mn1h4ck" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>1ns0mn1h4ck</span></a></span> </p><p><a href="https://mastodon.social/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a> <a href="https://mastodon.social/tags/radare2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>radare2</span></a> <a href="https://mastodon.social/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> <a href="https://mastodon.social/tags/ghidra" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ghidra</span></a></p>
cryptax<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@radareorg" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>radareorg</span></a></span> the program was implemented using Swift, which does not disassemble very nicely. So, I tried decai. Output in C wasn't nice, but output in Java is quite usable. At least, the password is very visible.</p><p><a href="https://mastodon.social/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> <a href="https://mastodon.social/tags/radare2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>radare2</span></a></p>
:radare2: radare :verified:<p>When you find a method with a curious name and what to know what it’s doing with <a href="https://infosec.exchange/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a>.<br>(But don’t use it for cheating, you know 😜)<br><a href="https://infosec.exchange/tags/r2con2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2con2024</span></a></p>
:radare2: radare :verified:<p>Once again <a href="https://infosec.exchange/tags/r2ai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2ai</span></a>, <a href="https://infosec.exchange/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> and <a href="https://infosec.exchange/tags/r2frida" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2frida</span></a> to the rescue!<br>They were really helpful in <span class="h-card" translate="no"><a href="https://infosec.exchange/@as0ler" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>as0ler</span></a></span>’s, combining them in the process. <br><a href="https://infosec.exchange/tags/r2con2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2con2024</span></a></p>
:radare2: radare :verified:<p>Tomorrow we’ll be able to see how <a href="https://infosec.exchange/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> was really helpful to decompile the STM8 firmware. So don’t miss it!<br><a href="https://infosec.exchange/tags/r2con2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2con2024</span></a></p>
:radare2: radare :verified:<p>Some more examples of <a href="https://infosec.exchange/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> decompilation.<br>And with -Q command you can also ask if the code is vulnerable and where, and it will answer that! Isn’t it awesome?<br><a href="https://infosec.exchange/tags/r2con2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2con2024</span></a></p>
:radare2: radare :verified:<p>Decompiling with <a href="https://infosec.exchange/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> provides a really nice output, as you can see in the example below. But even with more complex binaries the results are surprising.<br><a href="https://infosec.exchange/tags/r2con2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2con2024</span></a></p>
Marc R<p>Crazy things at the <span class="h-card" translate="no"><a href="https://infosec.exchange/@radareorg" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>radareorg</span></a></span> conference!! <span class="h-card" translate="no"><a href="https://infosec.exchange/@pancake" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>pancake</span></a></span> joins to the stage to do a surprise talk about <a href="https://mastodont.cat/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> <a href="https://mastodont.cat/tags/r2con2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2con2024</span></a></p>
:radare2: radare :verified:<p>When dealing with python is a mess, you can write your own plugin in js, so that was how <a href="https://infosec.exchange/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> was born. <a href="https://infosec.exchange/tags/ia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ia</span></a><br><a href="https://infosec.exchange/tags/r2con2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2con2024</span></a></p>
:radare2: radare :verified:<p>And now… surprise talk from <span class="h-card" translate="no"><a href="https://infosec.exchange/@pancake" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>pancake</span></a></span>! He will show us some of the <a href="https://infosec.exchange/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> magic.<br><a href="https://infosec.exchange/tags/r2con2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2con2024</span></a></p>
cryptax<p>I got decai (radare2's AI-assisted decompiler) to work with a local model, and tried it over a basic Caesar implementation in C and in Dart.</p><p>To be honest, I think the conclusion is that the model I selected is not good enough ;) but <a href="https://mastodon.social/tags/r2ai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>r2ai</span></a> and <a href="https://mastodon.social/tags/decai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decai</span></a> are really great tools. Read my post to understand how to install, configure and use. Or RTFM :P</p><p><a href="https://cryptax.medium.com/using-ai-assisted-decompilation-of-radare2-e81a882863c9" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">cryptax.medium.com/using-ai-as</span><span class="invisible">sisted-decompilation-of-radare2-e81a882863c9</span></a></p><p>many thanks to <span class="h-card" translate="no"><a href="https://mastodon.social/@Pancake" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Pancake</span></a></span> for his patience! "it's not working on my laptop", "try this then" etc</p><p><a href="https://mastodon.social/tags/radare2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>radare2</span></a> <a href="https://mastodon.social/tags/decompiler" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decompiler</span></a> <a href="https://mastodon.social/tags/dart" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dart</span></a> <a href="https://mastodon.social/tags/C" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>C</span></a></p>