RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2

Ghidra (the tool for the analysis of the software code)

Product
Developers: National Security Agency (NSA) of the USA
Branches: Information technologies
Technology: Development tools of applications

Content

2019

In the declassified platform of the NSA for search of vulnerabilities found own "hole"

The expert in information security detected critical vulnerability in the platform of the U.S. National Security Agency (NSA) Ghidra. Vulnerability allows to start in it any code far off.

Ghidra represents the cross-platform framework written on Java intended for the return engineering (research) of the ready software and search of vulnerabilities. Existence of this system for the first time became known in 2017 when the resource of WikiLeaks within the campaign Vault 7 merged the large volume of non-public data on hacker tools of CIA and methods of its use. Among these documents also Ghidra is mentioned.

In March, 2019 the NSA published the source code Ghidra, having made thus once confidential platform public property.

Disclosure of source codes

At the beginning of January, 2019 the U.S. National Security Agency announced that it is going to open source codes of the tool for the analysis of the code of the software.

The solution under the name GHIDRA includes an interactive disassembler with support of decompiling in the code in language C and means for the analysis of executable files. Thanks to GHIDRA software developers and normal users can reveal malware and another suspicious software.

GHIDRA is written in language Java, has the graphical interface and is compatible to operating systems Linux, Mac and Windows. Using GHIDRA it is also possible to analyze binary files of all main OS, including mobile platforms, such Android as well as iOS. Thanks to modular architecture of the tool users can add new features to the existing platforms.

The NSA opens source codes of the tool for the analysis of the software code

Officially this tool was never considered as confidential, but the NSA held back its existence till March, 2017 though it several times appeared in the documents received as a result of date leak from the closed NSA network and placed on WikiLeaks. According to these documents, the project was started at the beginning of the 2000th years and was used by several government agencies.

Users of Hacker News, Reddit and Twitter compare GHIDRA to the commercial instrument of the return engineering under the name IDA. The majority agree that IDA is stabler and reliable platform, but note that it is software very expensively and to inaccessibly normal user. The analyst of Constellation Research company notes that the NSA for certain hopes for the help of users in error correction of GHIDRA that will help to make it much more competitive tool.

The NSA is going to open source codes of GHIDRA at the beginning of March, 2019 at the RSA Security Conference 2019 conference.[1]

See Also





Notes