Vulnerability fix for bTree engine

Just a quick note for all IDA users. We published a fix for potential vulnerability in IDA. Please check out It does not seem to be exploitable but we prefer to be on the safe side.

Installing PIP packages, and using them from IDA on a 64-bit machine

Recently, one of our customers came to us asking how he should proceed to be able to install python packages, using PIP, and use those from IDA. The issue he was facing is that his system is a 64-bit Ubuntu

Recon 2012: Compiler Internals

This year I again was lucky to present at Recon in Montreal. There were many great talks as usual. I combined the topic of my last year's talk on C++ reversing and my OpenRCE article on Visual C++ internals. New

The trace replayer

One of the new features that will be available in the next version of IDA is a trace re-player. This pseudo-debugger allows to re-play execution traces of programs debugged in IDA. The replayer debugger allows replaying traces recorded with any of

Recon 2011: Practical C++ Decompilation

Last month I visited the Recon conference and had a great time again. I gave a talk on C++ decompilation and how to handle it in IDA and Hex-Rays decompiler. You can get the slides here, and download the recorded

Challenging job for software developers

We should permanently and prominently publish this ad on our site We are looking for strong software engineers to join our team and participate in the development of unique software security tools. The candidates must know low-level details of modern

IDA Pro 5.5 and Hex-Rays 1.1 have been released!

IDA Pro 5.5 We are happy to announce a new version of IDA Pro! The major news is the new docking user interface. There are many other improvements: processor modules, file formats, analysis tweaks, well, the usual stuff. There is

Decompilation gets real

Analyzing binary executables can be a very boring activity, especially when you get used to the regular patterns. You see the same things again and again. A tool to automate the analysis or diminish the amount of text to browse

Stealth plugin

The last time I showed you a simple trick with conditional breakpoints. Today I will present you a plugin which automates these breakpoints – to the extent that a protected malware like the Zotob worm can be unpacked.

This is the first entry in the blog.

