From owner-freebsd-security@FreeBSD.ORG Mon Jun 5 13:33:46 2006 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 80B8D16B0CA for ; Mon, 5 Jun 2006 13:33:44 +0000 (UTC) (envelope-from lboehne@damogran.de) Received: from cthulhu.zoidberg.org (zoidberg.org [213.133.99.5]) by mx1.FreeBSD.org (Postfix) with ESMTP id E8CF543D66 for ; Mon, 5 Jun 2006 13:33:42 +0000 (GMT) (envelope-from lboehne@damogran.de) Received: from localhost (dslb-084-063-047-188.pools.arcor-ip.net [::ffff:84.63.47.188]) (AUTH: PLAIN kasperle, TLS: TLSv1/SSLv3,256bits,AES256-SHA) by cthulhu.zoidberg.org with esmtp; Mon, 05 Jun 2006 15:33:36 +0200 id 040E4152.448432B0.00005613 From: Lutz Boehne To: freebsd-security@freebsd.org Date: Mon, 5 Jun 2006 15:32:46 +0200 User-Agent: KMail/1.9.1 References: <8e96a0b90606050614l26db50f2nfcb26669d02a7ad9@mail.gmail.com> In-Reply-To: <8e96a0b90606050614l26db50f2nfcb26669d02a7ad9@mail.gmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="nextPart1390710.hGTDFCeDpH"; protocol="application/pgp-signature"; micalg=pgp-sha1 Content-Transfer-Encoding: 7bit Message-Id: <200606051532.52775.lboehne@damogran.de> Subject: Re: PE disassembler for unix X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 05 Jun 2006 13:33:52 -0000 --nextPart1390710.hGTDFCeDpH Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Hi, > Hello, I'm looking for a disassembler to examine a malicious > Win32 binary on FreeBSD. Does anybody have any favourites? editors/hte (http://hte.sourceforge.net/) is fairly nice, disassembles ELF,= PE=20 and some other binary formats. Regards, Lutz --nextPart1390710.hGTDFCeDpH Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (FreeBSD) iD8DBQBEhDKEDbEkl9DbWrYRAmfBAKCE4NSZWetpJ515vzvcYtACuvjUVACfSZBx evR3+DXrCfNA+rOerh0CmKw= =B7d/ -----END PGP SIGNATURE----- --nextPart1390710.hGTDFCeDpH--