<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0">
	<channel>
		<title>iDefense Labs Software Releases</title>
		<link>http://labs.idefense.com/software/</link>
		<description>Latest software releases from labs.idefense.com</description>
		<copyright>Copyright 2009 iDefense Labs</copyright>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
		<language>en-US</language>
		<pubDate>Wed, 07 Jan 2009 01:18:11 UTC</pubDate>
		<lastBuildDate>Wed, 07 Jan 2009 01:18:11 UTC</lastBuildDate>
		<item>
			<title>SysAnalyzer</title>
			<link>http://labs.idefense.com/software/?show=15</link>
			<description>Author: David Zimmer &lt;br&gt;Size: 1.9mb&lt;br&gt;MD5:   B75F17199AB6EB781595758C51413EF3&lt;br&gt;&lt;br&gt;SysAnalyzer is an automated malcode run time analysis application that
      monitors various aspects of system and process states.
      &lt;br&gt;&lt;br&gt; 
      SysAnalyzer was designed to enable analysts to quickly build a
      comprehensive report as to the actions a binary takes on a system.
      &lt;br&gt;&lt;br&gt;
	Updated 1/19/07: added known file db
      &lt;br&gt;&lt;br&gt;
      SysAnalyzer can automatically monitor and compare:
      &lt;ul&gt;

      &lt;li&gt; Running Processes
      &lt;/li&gt;&lt;li&gt; Open Ports
      &lt;/li&gt;&lt;li&gt; Loaded Drivers
      &lt;/li&gt;&lt;li&gt; Injected Libraries
      &lt;/li&gt;&lt;li&gt; Key Registry Changes
      &lt;/li&gt;&lt;li&gt; APIs called by a target process
      &lt;/li&gt;&lt;li&gt; File Modifications
      &lt;/li&gt;&lt;li&gt; HTTP, IRC, and DNS traffic
      &lt;/li&gt;&lt;/ul&gt; 
      SysAnalyzer also comes with a ProcessAnalyzer tool which
      can perform the following tasks:
      &lt;ul&gt;

      &lt;li&gt; Create a memory dump of target process
      &lt;/li&gt;&lt;li&gt; parse memory dump for strings
      &lt;/li&gt;&lt;li&gt; parse strings output for exe, reg, and url references
      &lt;/li&gt;&lt;li&gt; scan memory dump for known exploit signatures
      &lt;/li&gt;&lt;/ul&gt;
      Full GPL source for SysAnalyzer is included in the installation package:&lt;br&gt;

&lt;a href=&quot;/files/labs/releases/previews/SysAnalyzer/&quot; target=&quot;DLWIN&quot;&gt;Overview&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
&lt;a href=&quot;/software/download/?downloadID=19&quot; target=&quot;DLWIN&quot;&gt;Video Tour&lt;/a&gt;</description>
			<pubDate>Fri, 19 Jan 2007 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>FileFuzz</title>
			<link>http://labs.idefense.com/software/?show=3</link>
			<description>Author: Michael Sutton&lt;br&gt;
Size: ~469k&lt;br&gt;
MD5: ac44339e856f04e116dde59389583ba9&lt;br&gt;
&lt;br&gt;
Updated 11/15/06: Recompiled under Microsoft .NET 2.0&lt;BR&gt;
&lt;BR&gt;
FileFuzz is a graphical Windows based file format fuzzing tool. FileFuzz was designed to automate the launching of applications and detection of exceptions caused by fuzzed file formats.</description>
			<pubDate>Wed, 15 Nov 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Malcode Analysis Pack</title>
			<link>http://labs.idefense.com/software/?show=8</link>
			<description>Author: David Zimmer &lt;br&gt;Size: ~2mb&lt;br&gt;MD5:  20B5A8F02EC56DDBC230CC1FFEF67D88&lt;br&gt;Update Summary: &lt;BR&gt;
Fixed md5 bug, added jsDecode&lt;br&gt;
Added GdiProcs.exe, mailpot added RSET command, fixed sniffing restart bug&lt;br&gt;&lt;br&gt;The Malcode Analyst Pack contains a series of utilities that were found to be necessary tools while doing rapid malcode analysis.
     &lt;br&gt;&lt;br&gt;

     Included in this package are: 
     &lt;br&gt;&lt;br&gt;
     &lt;table class=&quot;labDesc&quot; border=&quot;0&quot; width=&quot;450&quot;&gt;
     &lt;tbody&gt;&lt;tr&gt;&lt;td width=&quot;100&quot;&gt;&amp;bull; ShellExt&lt;/td&gt;&lt;td width=&quot;350&quot;&gt;- 4 explorer shell extensions&lt;/td&gt;&lt;/tr&gt;
     &lt;tr&gt;&lt;td&gt;&amp;bull; socketTool&lt;/td&gt;&lt;td&gt;- manual TCP Client for probing functionality.&lt;/td&gt;&lt;/tr&gt;  
     &lt;tr&gt;&lt;td&gt;&amp;bull; MailPot&lt;/td&gt;&lt;td&gt;- mail server capture pot&lt;/td&gt;&lt;/tr&gt;
     &lt;tr&gt;&lt;td&gt;&amp;bull; fakeDNS&lt;/td&gt;&lt;td&gt;- spoofs dns responses to controlled ip's&lt;/td&gt;&lt;/tr&gt;

     &lt;tr&gt;&lt;td&gt;&amp;bull; sniff_hit&lt;/td&gt;&lt;td&gt;- HTTP, IRC, and DNS sniffer&lt;/td&gt;&lt;/tr&gt;                 
       &lt;tr&gt;&lt;td&gt;&amp;bull; sclog&lt;/td&gt;&lt;td&gt;- Shellcode research and analysis application&lt;/td&gt;&lt;/tr&gt;
     &lt;tr&gt;&lt;td&gt;&amp;bull; IDCDumpFix&lt;/td&gt;&lt;td&gt;- aids in quick RE of packed applications&lt;/td&gt;&lt;/tr&gt;    
     &lt;tr&gt;&lt;td&gt;&amp;bull; Shellcode2Exe&lt;/td&gt;&lt;td&gt;- embeds multiple shellcode formats in exe husk&lt;/td&gt;&lt;/tr&gt;  
     &lt;tr&gt;&lt;td&gt;&amp;bull; GdiProcs&lt;/td&gt;&lt;td&gt;- detect hidden processes&lt;/td&gt;&lt;/tr&gt;    
     &lt;/tbody&gt;&lt;/table&gt;

     &lt;br&gt;
     For screen shots and tool descriptions please refer to the MAP overview document below:&lt;br&gt;
      &lt;a href=&quot;/files/labs/releases/sclog_trainer.wmv&quot; target=&quot;_blank&quot;&gt;Sclog Trainer&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
      &lt;a href=&quot;/files/labs/releases/previews/map/&quot; target=&quot;DLWIN&quot;&gt;MAP Overview&lt;/a&gt;</description>
			<pubDate>Mon, 13 Nov 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>iDbg</title>
			<link>http://labs.idefense.com/software/?show=27</link>
			<description>Author: David Zimmer&lt;br&gt;
Size: ~900k&lt;br&gt;
MD5: F8D603E836FEFF8771BE6B9BADEEDCBC&lt;br&gt;
&lt;br&gt;
iDBG is a Debugger Library packaged as an ActiveX Control which can be easily used from any COM aware language. Designed for the quick development of testing applications that require built in debugging or tracing functionality. iDbg is Open source and released under GPL license.&lt;br&gt;
&lt;br&gt;
Sample code provided for VB6, PHP5, and C#.</description>
			<pubDate>Tue, 12 Sep 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>OllyDbg Heap Vis</title>
			<link>http://labs.idefense.com/software/?show=12</link>
			<description>Author: Pedram Amini&lt;br&gt;
Size: ~323k&lt;br&gt;
MD5: 03ACBB54380246CABA057841E8268840&lt;br&gt;
Update Summary: Fixed bug that was causing the plug-in to hang&lt;br&gt;
&lt;br&gt;
You may have noticed the ghosted &quot;Heap&quot; option under the &quot;View&quot; menu in OllyDBG. The feature is available only under Windows 95 based OSes and is supposed to display a list of allocated memory blocks. The Olly Heap Vis plug-in was written to provide this functionality and more on all modern Windows OSes such as Windows 2000, XP and 2003. The OllyDbg Heap Vis plug-in exposes the following functionality:&lt;br&gt;
&lt;ul&gt;
  &lt;li&gt;View Heaps&lt;/li&gt;
  &lt;li&gt;Search Heaps&lt;/li&gt;
  &lt;li&gt;Jump to Heap Chunk&lt;/li&gt;
  &lt;li&gt;Create Heap Visualization&lt;/li&gt;
&lt;/ul&gt;

More information, screenshots and source code are available in the bundled archive:&lt;br&gt;
Screenshots: &lt;a href=&quot;/graphics/software/ohv_skylined_ie_heap_fill.gif&quot; target=&quot;DLWIN&quot;&gt;List&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
&lt;a href=&quot;/graphics/software/ohv_iexplore_start_state.png&quot; target=&quot;DLWIN&quot;&gt;Visualize&lt;/a&gt;</description>
			<pubDate>Fri, 11 Aug 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Comraider</title>
			<link>http://labs.idefense.com/software/?show=23</link>
			<description>Author: David Zimmer &lt;br&gt;Size: 2.2mb&lt;br&gt;MD5:   DB7D4E560B07F9CB2A3E5E9A98CBADCB&lt;br&gt;&lt;br&gt;
        COMRaider is a tool designed to fuzz COM Object Interfaces.
        &lt;br&gt;&lt;br&gt;
        COMRaider includes:
        &lt;ul&gt;
        &lt;li&gt;capability to easily enumerate safe for scripting objects
        &lt;/li&gt;&lt;li&gt;ability to scan for COM objects by path, filename, or guid
        &lt;/li&gt;&lt;li&gt;integrated type library viewer
        &lt;/li&gt;&lt;li&gt;integrated debugger to monitor exceptions, close windows,log api
        &lt;/li&gt;&lt;li&gt;external vbs script allows you to easily edit fuzzer permutations
        &lt;/li&gt;&lt;li&gt;built in webserver to test exploits on the fly 
        &lt;/li&gt;&lt;li&gt;Enumerate and view controls with killbit set
        &lt;/li&gt;&lt;li&gt;distributed auditing mode to allow entire teams to work together
        &lt;/li&gt;&lt;li&gt;ability to upload crash files to central server for group analysis
        &lt;/li&gt;&lt;li&gt;automation tools allowing you to easily fuzz multiple libraries, individual classes, or specific functions.
        &lt;/li&gt;&lt;/ul&gt;
      &lt;br&gt;
&lt;a href=&quot;/files/labs/releases/previews/COMRaider/&quot; target=&quot;DLWIN&quot;&gt;Help File&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
&lt;a href=&quot;/software/download/?downloadID=24&quot; target=&quot;DLWIN&quot;&gt;Video Tour&lt;/a&gt;</description>
			<pubDate>Fri, 11 Aug 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>PunkUI</title>
			<link>http://labs.idefense.com/software/?show=25</link>
			<description>Author: Greg MacManus, Mike Sutton&lt;br&gt;
Size: 900k&lt;br&gt;
MD5: 7C44967D47F3EA66DFCC2C4092E83AB6&lt;br&gt;
&lt;br&gt;
PUNKui is a simple utility designed to automate the theory behind Punk Ode. Specifically, it is a Windows GUI which will take common image formats (JPG, PNG &amp; BMP) and convert them into PNG files comprised entirely of a NOP sled and embedded shellcode.</description>
			<pubDate>Wed, 02 Aug 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>JPExPoc</title>
			<link>http://labs.idefense.com/software/?show=26</link>
			<description>Author: Greg MacManus&lt;br&gt;
Size: 12k&lt;br&gt;
MD5: D52AF543C05C4DBEC7A98A2DB0D8CD4D&lt;br&gt;
&lt;br&gt;
JPExPoC demonstrates embedding shellcode in JPEG image files, exploiting degenerate cases of DCT encoding to prevent information loss in the process. It consists of a few small C programs and a shellscript to bind them together. This package was tested and developed under the Cygwin environment.</description>
			<pubDate>Wed, 02 Aug 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>IDA Function Analyzer</title>
			<link>http://labs.idefense.com/software/?show=4</link>
			<description>Author: Pedram Amini&lt;br&gt;
Size: ~22k&lt;br&gt;
MD5: a0b40085fca1c9f3d2d1c12c14725c71&lt;br&gt;
Update Summary: Added gml_export() routine for generating GML graphs.&lt;br&gt;
&lt;br&gt;
Written as a C.. class, Function Analyzer was originally developed to provide an abstracted layer over &quot;chunked&quot; functions frequently found in Microsoft optimize compiled binaries. As of IDA v4.7 this functionality is built into the SDK. However, Function Analyzer can be used to construct plug-ins compatible across older versions and provides abstracted next_ea()/prev_ea() routines for stepping through an internal &quot;unchunked&quot; instruction list. The abstraction layer also exposes the following function-level information: basic block enumeration (nodes, edges), call count, MD5 hash, CRC, customizable GDL (Wingraph) and GML graph generation.</description>
			<pubDate>Thu, 06 Jul 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>HookExplorer</title>
			<link>http://labs.idefense.com/software/?show=22</link>
			<description>Author: David Zimmer &lt;br&gt;Size: 245kb&lt;br&gt;MD5: 2BB04344700CAF643472255F3C4DAFBF&lt;br&gt;&lt;br&gt;HookExplorer is a small utility designed to scan a target
        process and identify any user land hooks that may be installed
        by unknown code.
        &lt;br&gt;&lt;br&gt;

        Detects IAT and detours style hooks, and allows the user to define
        an 'ignore list' to help cut through results.&lt;br&gt;
                 
      &lt;a href=&quot;/files/labs/releases/previews/HookExplorer/&quot; target=&quot;DLWIN&quot;&gt;Help File&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
        &lt;a href=&quot;/files/labs/releases/previews/HookExplorer/HookExplorer.png&quot; target=&quot;DLWIN&quot;&gt;Screenshot&lt;/a&gt;</description>
			<pubDate>Thu, 16 Mar 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>IDAStruct</title>
			<link>http://labs.idefense.com/software/?show=21</link>
			<description>Author: Richard Johnson&lt;br&gt;
Size: 209 KB&lt;BR&gt;
MD5: F2112F6ED4309AEEC1AE80F394B55325&lt;br&gt;&lt;br&gt;
idastruct - ida structure recognition plugin&lt;br&gt;&lt;br&gt;
idastruct is an ida plugin which aims to assist reverse engineers in identifying high-level objects and structures in binary code.&lt;br&gt;&lt;br&gt;
idastruct utilizes the excellent x86 emulator plugin 'ida-x86emu' by Chris Eagle and Jermey Cooper as a basis for evaluating operand values and determining references within tracked boundaries. &lt;br&gt;&lt;br&gt;
This results in automated creation of IDA structures, enumeration or member references, and renaming of disassembly offsets to symbolic names corresponding to the newly created structures and members in the IDA database.</description>
			<pubDate>Wed, 11 Jan 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Codis</title>
			<link>http://labs.idefense.com/software/?show=16</link>
			<description>Author: Richard Johnson&lt;br&gt;
Size: 80kb&lt;br&gt;
MD5: A7C9DFB633CCBFB0EC1536700EF169BB&lt;br&gt;
&lt;br&gt;
Codis is a console-based disassembler written for the purpose of demonstrating the basic logic of a disassembler engine.&lt;br&gt;
&lt;br&gt;
This software was released as example code accompanying the information provided in the Toorcon 7 presentation titled 'Disassembler Internals'.&lt;br&gt;
&lt;br&gt;
Codis is written in C and will compile for Linux or Win32 Cygwin environments.&lt;br&gt;
&lt;br&gt;&lt;a href='/files/labs/releases/previews/codis/codis.png' target='DLWIN'&gt;Screenshot&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
&lt;a href='/files/labs/releases/previews/codis/README.txt' target='DLWIN'&gt;Readme&lt;/a&gt;</description>
			<pubDate>Wed, 11 Jan 2006 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>IDACompare</title>
			<link>http://labs.idefense.com/software/?show=17</link>
			<description>Author: David Zimmer David Zimmer&lt;br&gt;
Size: 1.2Mb&lt;br&gt;
MD5: 552C2888770D5E489139DDFD6C8B064E&lt;br&gt;
&lt;br&gt;
IDACompare is a plugin designed to compare and match up equivalent functions across two IDA databases. IDACompare was primarily designed for analyzing changes across malcode variants, it should also find good use when conducting patch analysis.&lt;br&gt;
&lt;br&gt;
Once function matches have been made, names can be ported across disassemblies, or sequentially renamed in both.&lt;br&gt;
&lt;br&gt;
Project also implements a signature scanner, letting you build your own listing of known functions.&lt;br&gt;
&lt;br&gt;&lt;a href='/files/labs/releases/previews/IDACompare/' target='DLWIN'&gt;Overview&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
&lt;a href='/software/download/?downloadID=18' target='_Blank'&gt;Video Tour&lt;/a&gt;</description>
			<pubDate>Fri, 16 Dec 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Multipot</title>
			<link>http://labs.idefense.com/software/?show=9</link>
			<description>Author: David Zimmer &lt;br&gt;Size: ~1.7mb&lt;br&gt;MD5:    275282740BD58E9658848B1FBDF0FD71&lt;br&gt;Update Summary: Added 2 PNP Shellcode Handlers&lt;br&gt;&lt;br&gt;Multipot is a emulation based honeypot designed to capture malicious code  which spreads through various exploits across the net. Design specifications for this project mandated that the captures be done in such a way so that the host machine  would require only minimal supervision and would not itself risk getting infected. Multipot was designed to emulate exploitable services to safely collect malicious code. &lt;br&gt;&lt;br&gt;Who would use MultiPot and why?&lt;br&gt;&lt;br&gt;&amp;bull; ISP's to monitor their networks.&lt;br&gt;&amp;bull; Corporate security personnel to be warned of infections.&lt;br&gt; &amp;bull; Security researchers to build statistics of Internet health.&lt;br&gt;&amp;bull; Virus researchers to collect new samples of malware in the wild.&lt;br&gt; &amp;bull; Hobbyists and students to learn more about Internet security. &lt;br&gt;&lt;br&gt;More information and source code is available in the bundled install file:&lt;br&gt;

&lt;a href=&quot;/files/labs/releases/previews/multipot/index.html&quot; target=&quot;DLWIN&quot;&gt;Online Help file&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
&lt;a href=&quot;/graphics/software/honeypot.gif&quot; target=&quot;DLWIN&quot;&gt;Screenshot&lt;/a&gt;</description>
			<pubDate>Wed, 17 Aug 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>notSPIKEfile</title>
			<link>http://labs.idefense.com/software/?show=10</link>
			<description>Author: Adam Greene &lt;br&gt;
Size: ~79k&lt;br&gt;
MD5: 8198bd8a3d5b18b5aa36335ab8cd3ec2&lt;br&gt;
&lt;br&gt;
notSPIKEfile is a linux based file format fuzzing tool. It was designed to automate the executing the launching of applications and detection of exceptions caused by fuzzed file formats.</description>
			<pubDate>Thu, 28 Jul 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>SPIKEfile</title>
			<link>http://labs.idefense.com/software/?show=14</link>
			<description>Author: Adam Greene&lt;br&gt;
Size: ~104k&lt;br&gt;
MD5: c57a794dbfb7c950abb0047b13bb8b5e&lt;br&gt;
&lt;br&gt;
SPIKEfile is a Linux based file format fuzzing tool, based on SPIKE 2.9. It was designed to automate the executing the launching of applications and detection of exceptions caused by fuzzed file formats.</description>
			<pubDate>Thu, 28 Jul 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>OllyDbg Breakpoint Manager</title>
			<link>http://labs.idefense.com/software/?show=11</link>
			<description>Author: Pedram Amini&lt;br&gt;
Size: ~160k&lt;br&gt;
MD5: 94cb360d064b6ca76f5e06c0a7149b20&lt;br&gt;
Update Summary: Bug fix in automatic breakpoint list loading.&lt;br&gt;
&lt;br&gt;
OllyDBG has excellent breakpoint manipulation capabilities and can store breakpoint information across debugging sessions for the main module being debugged. However, there are some limitations to the available functionality which this plug-in attempts to address. The OllyDbg Breakpoint (BP) Manager plug-in was written to provide three main functions- breakpoint exporting, breakpoint importing and automatic breakpoint loading. Offsets are used in place of absolute addresses to support setting and restoring breakpoints on modules that move around in memory. More information, examples and source code are available in the bundled archive.&lt;br&gt;
&lt;br&gt;
We encourage users to submit useful breakpoint sets they have created with OllyDbg Breakpoint Manager to us for credit and inclusion in future releases and on the release web site.</description>
			<pubDate>Wed, 13 Jul 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Process Stalker</title>
			<link>http://labs.idefense.com/software/?show=13</link>
			<description>Author: Pedram Amini  &lt;br&gt;Size: ~960k&lt;br&gt;MD5: 0621cfa79dc899eabbe671b924844cb1&lt;br&gt; Update Summary: Couple of bug fixes, see CHANGELOG.txt for details.&lt;br&gt;&lt;br&gt; Process Stalking is a term coined to describe the combined process of run-time profiling, state mapping and tracing. Consisting of a series of tools and scripts the goal of a successful stalk is to provide the reverse engineer with an intuitive visual interface to filtered, meaningful, run-time block-level trace data.&lt;br&gt;&lt;br&gt;The Process Stalker suite is broken into three main components; an IDA Pro plug-in, a stand alone tracing tool and a series of Python scripts for instrumenting intermediary  and GML graph files. The generated GML graph definitions were designed for usage with a freely available interactive graph visualization tool. &lt;br&gt;&lt;br&gt;Data instrumentation is accomplished through a series of Python utilities built on top of a fully documented custom API. Binaries, source code and in-depth documentation  are available in the bundled archive. Relevant slideshows from Process Stalker presentations are available on the &lt;a href=&quot;/presentations/&quot;&gt;speaking engagements&lt;/a&gt;  page. Binaries, source code and in-depth documentation are available in the bundled archive. The &lt;a href=&quot;/files/labs/releases/ps_docs/&quot; target=&quot;DLWIN&quot;&gt;usage manual&lt;/a&gt; and &lt;a href=&quot;/files/labs/releases/ps_docs/ps_api_docs/&quot; target=&quot;DLWIN&quot;&gt;Python API&lt;/a&gt; docs are also available online.&lt;br&gt;
&lt;br&gt;Screenshots: &lt;a href=&quot;/graphics/software/ps_close.gif&quot; target=&quot;DLWIN&quot;&gt;Trace Graph Close-up&lt;/a&gt;</description>
			<pubDate>Wed, 13 Jul 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>dltrace</title>
			<link>http://labs.idefense.com/software/?show=2</link>
			<description>Author: Richard Johnson&lt;br&gt;
Size: ~200k&lt;br&gt;
MD5: ceb8465b010a871ffe5685d003eabaaa&lt;br&gt;
Update Summary: Fixed missing library path (/lib/tls).&lt;br&gt;
&lt;br&gt;
dltrace is a dynamic library call tracer which attempts to remain portable to all x86 platforms that support ELF binaries and expose a debugging interface via procfs or the ptrace() system call. The shared library call tracing is done at a level which allows calls to all symbols exported by loaded libraries to be traced. In addition, dltrace does not rely on rtld symbols to retrieve library and symbol information and is capable of determing function arguments dynamically via run-time disassembly.</description>
			<pubDate>Thu, 28 Apr 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>IDA pGRAPH</title>
			<link>http://labs.idefense.com/software/?show=5</link>
			<description>Author: Pedram Amini&lt;br&gt;
Size: ~70k&lt;br&gt;
MD5: e4086cfbe1b501f4ca0bd2473d272c07&lt;br&gt;
Update Summary: Ported to IDA 4.8&lt;br&gt;
&lt;br&gt;
Built on top of the IDA Function Analyzer, pGRAPH (Pedram's Grapher), provides an interface to generate more detailed and user defined control-flow graphs using the bundled Wingraph package. Extended features include: support for &quot;chunked&quot; functions, instruction level coloring, edge customization (manhattan vs splines), layout algorithm and more.&lt;br&gt;
&lt;br&gt;
Screenshots: &lt;a href=&quot;/graphics/software/pgraph_options.gif&quot; target=&quot;DLWIN&quot;&gt;Options&lt;/a&gt;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;
&lt;a href=&quot;/graphics/software/pgraph_sample.gif&quot; target=&quot;DLWIN&quot;&gt;Sample&lt;/a&gt;</description>
			<pubDate>Tue, 05 Apr 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>IDA Sync</title>
			<link>http://labs.idefense.com/software/?show=7</link>
			<description>Author: Pedram Amini&lt;br&gt;
Size: ~225k&lt;br&gt;
MD5: 19ddfa0ab42939e1aa83f81688c7a261&lt;br&gt;
Update Summary: Ported to IDA 4.8&lt;br&gt;
&lt;br&gt;
IDA Sync was written to allow multiple analysts to synchronize their reverse engineering efforts with IDA Pro in real time. Users connect to a central server through the ida_sync plugin. Once connected, all comments and name changes made with the registered hot keys are immediately transmitted to all other users working on the same project. The central server stores a copy of all changes as well, allowing new analysts to jump on the project and immediately receive up to date information.&lt;br&gt;
&lt;br&gt;
Included in the source release is a C.. class providing IDA Pro plugin developers with an abstracted asynchronous IPC interface.</description>
			<pubDate>Tue, 05 Apr 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>IDA RPC Enumerator</title>
			<link>http://labs.idefense.com/software/?show=6</link>
			<description>Author: Pedram Amini&lt;br&gt;
Size: ~8k&lt;br&gt;
MD5: 731fa609c8a61e202c76af9c737e9ef9&lt;br&gt;
&lt;br&gt;
This IDC script will scan through an IDA database locating and marking the relevant RPC server data structures. It will then enumerate the dispatch routines from the DispatchTable. The script outputs the addresses of the discovered structs / functions and was designed to automate the otherwise tedious manual process of locating RPC routines to audit.</description>
			<pubDate>Mon, 07 Mar 2005 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Attack Vector Test Platform</title>
			<link>http://labs.idefense.com/software/?show=1</link>
			<description>Author: Peter Silberman&lt;br&gt;
Author: Richard Johnson&lt;br&gt;
Size: ~15k&lt;br&gt;
MD5:fc8808cf5d7dbd1a2472f8322fa4c59f&lt;br&gt;
&lt;br&gt;
The Attack Vector Test Platform was written over the course of research for the paper and presentation titled &quot;A Comparison Buffer Overflow Prevention Implementations &amp; Weaknesses&quot; which was presented at the 2004 Black Hat and Defcon computer security conferences. The test platform allows for assessing the effectiveness of combinations of attack buffer placement and execution control vectors against various buffer overflow prevention software technologies.</description>
			<pubDate>Tue, 15 Feb 2005 05:00:00 UTC</pubDate>
		</item>
	</channel>
</rss>
