02 Jul

QCustomPlot for IDA Pro Qt C++ plug-ins

For a Windows executable exploratory data analysis project using IDA Pro I needed to display some graphs. As is my usual planed on doing this from a Windows IDA C/C++ plug-in.
I looked at doing this several ways.  One idea was to just dump out a text file in the Graphviz DOT language and using a Graphviz viewer to see it.  Couldn’t be much simpler than that, but then looking for possible Qt options I ran into the awesome QCustomPlot.

With a little work I got it going in IDA:

Read More

20 Jan

Qt 5.4 User Interfaces for IDA Pro C/C++ plug-in development – Part 1 of 2

This is a rough and dirty update for my series “Qt 4.8.4 on Windows for IDA Pro C/C++ plug-in development”.

With the new IDA Pro 6.9 comes the newer Qt 5.4.1. Luckily upgrading from Qt 4.8.4 to the 5.4.1 environment for plug-in development turned out to be pretty easy as it’s not that much different.

Later this Hex Rays IDA 6.9: Qt 5.4.1 configure options & patch blog post came out, then this somewhat relevant one too IDAPython: migrating PySide code to PyQt5.
Read More

18 Apr

Qt 4.8.4 on Windows for IDA Pro C/C++ plug-in development – Part 3 of 3

Back in part 2 I went over how to setup a Visual Studio 2013 IDA Pro plug-in project to use the Qt 4.8.4 framework.  Now we’ll discus the basics of creating custom user interfaces.

With the Qt environment there is a build setup with it’s own tool-chain (located in your “C:\Qt\4.8.4\bin” folder).
I’ll briefly cover the key components here:

The most basic C++ object  most everything is derived from is the “QObject” class, then from there the QWidget class is the base class of all user interface objects that you’ll see a lot of it.  Another key one is QApplication but since we’re making plug-ins we’ll only need to occasionally reference IDA’s own instance of this class.

When you work with UIs with Qt you’ll want to use the Qt designer.  It’s a UI design tool similar to what’s in VS (Visual Studio) with it’s dialog and forums editors.

Qt Designer Screenshot

Read More

16 Apr

Qt 4.8.4 on Windows for IDA Pro C/C++ plug-in development – Part 2 of 3

Back in part 1 I showed you the first step in setting up Qt 4.8.4 with Visual Studio 2013 so you can add Qt to your IDA Pro plug-ins.

Unfortunately Visual Studio extensions are version specific.  The one that comes with 4.8.4 is made for VS2010  and probably without doing some major work you won’t get it to build for VS2013.

Go to the page http://www.qt.io/download-open-source/#section-2 and under “Other Downloads”, download the the latest “Visual Studio Add-in 1.xx for Qt5”.  Note just this add-in download, not the whole large Qt5 package.

Install it and now a “QT5” menu should be added to visual studio.  From there you can launch the Qt designer to build custom UIs, etc.

Visual Studio QT5 menu example
Read More

05 Mar

Qt 4.8.4 on Windows for IDA Pro C/C++ plug-in development – Part 1 of 3

(Note this an advanced article.  It assumes you know advanced C++, IDA Pro and it’s plug-in environment, etc).

Now that IDA Pro has completely moved to Qt for it’s user interface you can really expand on it to make your own custom Qt user interfaces in IDA.  You’re not locked in to using just IDA’s varied but basic UI system.

If you want to use Python for IDA there is already a featured setup using PySide but then maybe you want to use Qt from IDA’s C/C++ plug-in SDK (for speed and resource control, etc.)

The development environment for IDA Qt is version 4.8.4 and Visual Studio 2010.
You can clearly see this looking at the DLLs in the IDA Pro folder:DLL image showing Qt 4.8.4

DLL image showing Visual Studio 2010

Read More

29 Jan

IDA Plugin info

Here is a little utility I wrote to list IDA Pro plugin information.
About 30 plugins come with the default IDA install (~60 if you count the .p64 versions), then you start adding your own and with others off the web it can get a little difficult to manage.

IDA Plugin Info Example
Read More

30 Dec

New site under construction

I’m putting my site back together here after I let it all go “404” last year.
I restored my old blog, put up a new clean forum, and I’m in the process of adding some other new stuff.

My old site was mainly centered around my Macromonkey scripting system.
I plan on bringing part of that back, but the site will mainly focus on my reverse engineering, and IDA Pro plugin development stuff.

05 Mar

IDA StringMiner™

Today, I’ll show off this IDA plug-in I made over a few months last summer.
I ended up with basically an enhanced replacement for IDA Pro’s Strings window that understands many character set encodings (of the multi-byte foreign language kind, other then our ubiquitous friend ASCII), extracts ambiguous UTF-16 strings (real ones, using code pages beyond “ASCII-16″/Latin 1), with some statistical understanding of languages, and wrapped up with some automated web translation to translate the found “foreign” strings into English.

StringMiner™ screenshot:
ID StringMiner™ Example 1
Read More