Want to Join Us ?

you'll be able to discuss, share and send private messages.

IDA Signsrch

Discussion in 'Plugins' started by storm shadow, Feb 7, 2013.

Share This Page

  1. storm shadow

    Techbliss Owner Admin Ida Pro Expert Developer

    Source Macromonkey

    IDA Signsrch
    IDA Pro plug-in conversion of Luigi Auriemma's signsrch signature matching tool.

    Version 1.03, January 2013
    By Sirmabus

    ----- [Description] -----------------------------------------------------------

    From Luigi's original signsrch description:
    "Tool for searching signatures inside files, extremely useful as help in
    reversing jobs like figuring or having an initial idea of what encryption/-
    compression algorithm is used for a proprietary protocol or file.
    It can recognize tons of compression, multimedia and encryption algorithms and
    many other things like known strings and anti-debugging code which can be also
    manually added since it's all based on a text signature file read at runtime
    and easy to modify."

    I've used his tool in the past to help find various bits of crypto sections
    and what not. For example the log-in sections of some online game clients.
    To use the tool in IDA I would have to run signsrch output piped to a text
    file, like this: "signsrch -b Target.exe >Temp.txt".
    And then tediously take these address of each match offset and look them up
    Plus facilitated by a plug-in I added an automatic label commenting feature.

    Not be confused with IDA FLIRT "sig" technology, these signatures are direct
    binary patterns. Currently there are about 1400 of these signatures from the
    source text database "signsrch.sig".

    Dialog: The "Arco della Pace" (Arch of Peace) in Milan, Italy.

    Example output showing 96 found matches:

    Example placed comment with the <$ignsrch> tag:

    1) Fixed bad standard/CRT mixed with custom allocator method bug.
    2) Updated and fixed custom UI elements.

    1. Minor clean up of GUI customizations.
    2. Full sources now included.

    IDA_Signsrch.plw - MD5: 33E6D1B527CA92AD7D3F2F33A2E41E44

    mexskater94, CryptX0r and Rip Cord like this.
  2. Echelo


    Possible to re-upload? The current link is broken.
  3. Nihilus

    Well-Known Member Developer

  4. storm shadow

    Techbliss Owner Admin Ida Pro Expert Developer

    prerbuild package

    Attached Files:

    LordGarfio and mexskater94 like this.
  5. LordGarfio

    New Member

    Hello storm shadow,

    Your package IDA Signsrch v1.4 plugin for IDA Pro v6.8 is compiled for Windows Vista (6.00).

    Can you compile it for Windows XP SP3 (5.01) ?

    Thank you in advanced.
    storm shadow likes this.