Reverse Engineering: Choose Your Watchlist Flavor
Description
This meme uses the popular 'Inside You There Are Two Wolves' format, which depicts a black wolf and a white wolf staring each other down in front of a full moon. The top text reads, 'INSIDE YOU THERE ARE TWO WOLVES'. Text overlaid on the black wolf says, 'ONE USES GHIDRA', while the text on the white wolf says, 'THE OTHER USES IDA PRO'. The punchline is delivered in large, white text at the bottom: 'BOTH ARE ON A GOVERMENT WATCHLIST' (with 'government' misspelled). The joke satirizes the world of software reverse engineering. Ghidra (a free tool from the NSA) and IDA Pro (the expensive industry standard) are the two premier tools for this work. The humor lies in the fact that while practitioners might argue over which tool is better, the very nature of their work - analyzing software at a deep, low level - is inherently suspicious to authorities, regardless of the tools used. It's a nod to the paranoia and occupational hazards of the cybersecurity and vulnerability research fields
Comments
25Comment deleted
The real choice isn't between Ghidra and IDA Pro, it's whether you prefer your three-letter agency backdoor to be open-source or proprietary
Whichever wolf you feed, the SOC still files the same suspicious-binary ticket - call it dual-boot paranoia
The real question is which wolf spent three weeks reversing a binary only to discover it was just a hello world program with 47 layers of obfuscation and anti-debugging tricks added by a bored intern
The real joke is that after spending 40 hours reverse engineering a binary with either tool, you realize the original developer just copy-pasted Stack Overflow code anyway - but at least now three-letter agencies know you have excellent taste in disassemblers
Choosing between Ghidra and IDA Pro just decides whether Compliance or Procurement opens the ticket; either way the SIEM thinks you're the IOC
Ghidra: free NSA love. IDA: premium polish. Both: pre-approved for Langley fan mail
Compile Ghidra or expense IDA Pro - either choice summons the SOC when EDR spots ida64.exe on your laptop
i use cheat engine Comment deleted
party van is on its way to you Comment deleted
It’s not even the same thing… Cheat engine is not a decompiler nor reverse engineering tool. Finding out which addresses values live in the runtime is not reverse engineering especially in managed runtime. See replies Comment deleted
Cheat engin is way more than just memory reader/writer. It has other features like disassembler, pointerscan, debugger and a lot more. So i would say it is reverse engineering tool. Comment deleted
Okay disassembler is new to me. Never seen that before in cheat engine. Comment deleted
This is not widely known but you should really check features list of cheat engine, it’s a huge monster tool Comment deleted
I will at some point thanks. Bth I am switching away from desktop windows it seems like. Too much shit recently and w10 is not supported for a long while if it goes as planned. Comment deleted
i used to use that on s4league a game of 100 years ago Comment deleted
cz noone buys actually ida pro ? Comment deleted
I'm just a poor boy, I use OllyDbg. Comment deleted
Why not x64dbg? Comment deleted
This Comment deleted
Uhm ... certainly those newbie questions like "I'm new to reverse engineering, how do I get ... done in IDA Pro with Hex-Rays" always make me wonder about that. I've met a guy who didn't have a clue but plenty of money and purchased Sourcer back in the day. But Sourcer seems outright cheap compared to IDA Pro with the Hex-Rays plugin, for a tool and process of which I have no clue as a newbie. Oh well ... Comment deleted
I think a guy bought it. He is the same guy who paid for WinRar. Comment deleted
I paid for WinRAR as well, but I'm definitely not the same guy. Comment deleted
Generally I try to use the tool that best suits the job. Comment deleted
Real chads use radare2 😎 Comment deleted
Btw I use all three, still learning Comment deleted