RetDec: An Open-Source Machine-Code Decompiler Jakub Kˇroustek Peter Matula Petr Zemek Threat Labs Botconf 2017 1 / 51 ♂ Peter Matula • main developer of the RetDec decompiler • senior developer @Avast (previously @AVG) • ♥ rock climbing and • R
[email protected] > whoarewe ♂ Jakub Kˇroustek • founder of RetDec • Threat Labs lead @Avast (previously @AVG) • reverse engineer, malware hunter, security researcher • 7 @JakubKroustek • R
[email protected] Botconf 2017 2 / 51 > whoarewe ♂ Jakub Kˇroustek • founder of RetDec • Threat Labs lead @Avast (previously @AVG) • reverse engineer, malware hunter, security researcher • 7 @JakubKroustek • R
[email protected] ♂ Peter Matula • main developer of the RetDec decompiler • senior developer @Avast (previously @AVG) • ♥ rock climbing and • R
[email protected] Botconf 2017 2 / 51 Quiz Time Botconf 2017 3 / 51 Quiz Time Botconf 2017 4 / 51 Quiz Time Botconf 2017 5 / 51 Quiz Time Botconf 2017 6 / 51 Disassembling vs. Decompilation Botconf 2017 7 / 51 Decompilation? What is it? Botconf 2017 8 / 51 è Binary recompilation (yeah, like that’s ever gonna work) • porting • bug fixing • adding new features • original sources got lost • optimizations Decompilation? What good is it? ü Binary analysis • reverse engineering • malware analysis • vulnerability detection • verification • binary comparison • ... Botconf 2017 9 / 51 Decompilation? What good is it? ü Binary analysis • reverse engineering • malware analysis • vulnerability detection • verification • binary comparison • ... è Binary recompilation (yeah, like that’s ever gonna work) • porting • bug fixing • adding new features • original sources got lost • optimizations Botconf 2017 9 / 51 • It is damn hard • compilation is not lossless • high-level constructions • data types • names • comments, macros, . • compilers are optimizing • computer science goodies • undecidable problems • complex algorithms • exponential complexities • obfuscation, packing, anti-debugging Ok, why aren’t we already using it? • Multiple existing tools: Hex-Rays, Hopper, Snowman, etc.