>_0xFORUM
Sign in

Exception-handler decompiler in Ghidra 11.2 — actually better?

in Reversing14 replies3.7k views

Release notes said exception-handler decompiler is less cursed. I opened an old project and re-decompiled two functions that used to be soup.

One of them is now readable. The other still invents a write to 0. Better, not fixed. Anyone re-ran old projects through 11.2?

Refs: Ghidra

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 14 REPLIES

@block

I still keep a paper notebook for this kind of note. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release

I want the listing, not the decompiler story. The load-bearing line: Release notes said exception-handler decompiler is less cursed. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Took me 8 hours the first time.

@abdulpro

Not fully convinced yet. You wrote «Release notes said exception-handler decompiler is less cursed». That is the sentence I keep. If it is a

You skipped isolation and then asked why the box is dirty. That is on you. I tried the naive path first and wasted a morning. On «Exception-handler decompiler in Ghidra 11.2 — actually better?»: Release notes said exception-handler decompiler is less cursed. Listing first. The decompiler invented a cast last week that hid a signed compare. I reproduced it on lab build 1329.

@bashirhub

This belongs in the first-hour ritual. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release notes said ex

I am not moving this to DMs so you can yell. Stay on the class. I still keep a paper notebook for this kind of note. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release notes said exception-handler decompiler is less cursed. I leave CET ops in the listing. They document that CET is on. Took me 11 hours the first time.

Not fully convinced yet. You wrote «Release notes said exception-handler decompiler is less cursed». That is the sentence I keep. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. Took me 5 hours the first time.

@cmdx

The screenshot is the useful part of the post. The load-bearing line: Release notes said exception-handler decompiler is less cursed. Vtable

I read the patch. You read a tweet. Those are not the same source. This matches a public n-day class from last patch Tuesday. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release notes said exception-handler decompiler is less cursed. Vtable grouping without RTTI: xref clusters plus IUnknown shape. Did you snapshot before, or is this a restore-from-memory story? Version in my shot: current lab snapshot, not last year's blog.

This belongs in the first-hour ritual. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release notes said exception-handler decompiler is less cursed. Call-convention mass-correct with a script. Still too much clicking. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.

@bukunmivibe

I want the listing, not the decompiler story. The load-bearing line: Release notes said exception-handler decompiler is less cursed. If it i

That is not what the listing shows. You are arguing a vibe. If you only have the decompiler, you do not have the bug. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release notes said exception-handler decompiler is less cursed. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. I still have the snapshot named reve-21-pre.

The screenshot is the useful part of the post. The load-bearing line: Release notes said exception-handler decompiler is less cursed. Vtable grouping without RTTI: xref clusters plus IUnknown shape. I reproduced it on lab build 1151.

Also: FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie.

Agreed on the class, not on the tool. On «Exception-handler decompiler in Ghidra 11.2 — actually better?»: Release notes said exception-handler decompiler is less cursed. UPX with a skipped magic is still UPX. Restore four bytes and move on. I reproduced it on lab build 1374.

@sn0op

Agreed on the class, not on the tool. On «Exception-handler decompiler in Ghidra 11.2 — actually better?»: Release notes said exception-hand

Take the telegram pitch to the bin. Market listing or nothing. Agreed on the class, not on the tool. You wrote «Release notes said exception-handler decompiler is less cursed». That is the sentence I keep. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. If anyone DMs me a zip I will not open it. Hash in-thread.

I would have written the opposite conclusion a year ago. On «Exception-handler decompiler in Ghidra 11.2 — actually better?»: Release notes said exception-handler decompiler is less cursed. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. I will +rep a listing and −rep a vibe. That is the deal.

@threxz

I would have written the opposite conclusion a year ago. On «Exception-handler decompiler in Ghidra 11.2 — actually better?»: Release notes

Quote the bytes or sit down. If you only have the decompiler, you do not have the bug. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release notes said exception-handler decompiler is less cursed. UPX with a skipped magic is still UPX. Restore four bytes and move on. Can you quote the offset instead of the graph screenshot? I wrote a 12-line script and then threw it away. The listing was enough.

@virt

If you only have the decompiler, you do not have the bug. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Re

Please keep the hashes and drop the mystery zips. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release notes said exception-handler decompiler is less cursed. I trust FLOSS after I have seen the decoder. Before that I read the stores. Took me 10 hours the first time.

@wifi

Please keep the hashes and drop the mystery zips. «Exception-handler decompiler in Ghidra 11.2 — actually better?» — specifically Release no

You are treating a checksum as a signature again. Did this on ARM64 last week — same shape, different pain. On «Exception-handler decompiler in Ghidra 11.2 — actually better?»: Release notes said exception-handler decompiler is less cursed. UPX with a skipped magic is still UPX. Restore four bytes and move on. If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.