Penetration Testing mailing list archives

Re: [PEN-TEST] Suspect .EXE Trojan


From: Pierre Vandevenne <pierre () datarescue com>
Date: Fri, 15 Dec 2000 19:52:31 +0100

Hello,

About "suspect" EXE analysis : I've just made a new FREEWARE version of
our IDA Pro disassembler available. It is basically last year's 3.85B
commercial release, which means that it even supports FLIRT (Fasy
Library Identification and Recognition Technology). There is no catch :
it is free, supports the DOS / WIN 80x86 file formats we supported at
that time and a couiple of other things as well, no size limit, no time
limit and is even somewhat supported (we'll fix reported bugs if
practical).

We are releasing it for tree reasons

- we are a bit tired of seeing poorly cracked versions going around.
- we have made real progress with our new versions.
- we realize there is a need for a non pro to investigate potentially
hostile code on an amateur basis and that the budget for the full
version shouldn't be an obstacle.

file can be found on our ftp

ftp://ftp.datarescue.be/pub/ida/idafree.zip

Our ftp is a bit overloaded is now, redistribution of the file is ok,
provided it is not altered.

Have fun.
Pierre





---
Pierre Vandevenne - DataRescue sa/nv
Home of the IDA Pro Disassembler  -  Version 4.15 now available !
http://www.datarescue.com/idabase/ida.htm


Current thread: