Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   Ida-pro-mcp (https://forum.exetools.com/showthread.php?t=21233)

th3tuga 09-06-2026 02:17

Quote:

Originally Posted by chants (Post 135996)
@squareD in no way had I referred to you. This is just a long time forum troll who has had at least a dozen accounts banned and yet keeps creating more and he always wants revenge on me so he yesmans everyone's posts and tries to disrupt any of my posts. Its literally tne same exact textbook behavior exploiting the linearity of this style of forum. And you can see here is is literally doing his exact pattern. Make trouble and harass me, yes man everyone else then angrily demand his revenge as a relative nobody with no contributions, reputation and so on. This guy is extremrly malicious creating competing forums hosting malware infested releases, and even trying to use our sites name. Literally broke every rule in the list and yet still has multiple accounts to this day. What humors me is how mich time and energy he wasted just to be annoying. Mentally handicapped is an understatement and we all know who he is and the absurd hostility he has had towards this venue.

Never be confused by a wolf in sheep's clothes.

@chants I don't remember ever attacking you in any posts. I don't know why you feel that way. Is there any particular post where I have offended you?
I am not anyone who you think me to be... :confused:

I have again checked my posts. I've hardly even interacted with any of your posts... :confused:
Quote:

https://forum.exetools.com/search.php?do=finduser&u=39238

chants 09-06-2026 03:22

"would have been banned long ago on any other forum" the same exact thing all the banned accounts would always say. That looks copy and pasted even. Dude the gig is up, if you cant let bygones be bygones, then scram. 8+ years of this childish nonsense and making yourself the most despised person in all of reversing and yet still you persist. You should be grateful to even have an account here given the disgustingly hostile acts impersonating and harassing members here should amount to a life sentence.

It would be nice to return to discussing MCP.

th3tuga 09-06-2026 03:25

Quote:

Originally Posted by chants (Post 136000)
"would have been banned long ago on any other forum" the same exact thing all the banned accounts would always say. That looks copy and pasted even. Dude the gig is up, if you cant let bygones be bygones, then scram. 8+ years of this childish nonsense and making yourself the most despised person in all of reversing and yet still you persist. You should be grateful to even have an account here given the disgustingly hostile acts impersonating and harassing members here should amount to a life sentence.

Until you began targeting me two days ago, I had no knowledge of your existence and you were completely unknown to me. Consequently, I am confused as to why you perceive me as an adversary, especially since any conflict between us is entirely one-sided and imagined.

I made that statement because calling someone as "mentally handicapped" does get you banned on any online forum these days...
There is a way to disagree without referring to them as "mentally handicapped".

It appears to me that you attack any non-VIP user who remotely interacts in any thread that you've replied. Of course, you can't attack other VIP users since that would get you immediately banned.
So you're attacking accounts like mine who have never even interacted with you?

chants 09-06-2026 04:15

You revealed yourself in the LLM watermarking thread bringing up all these forum hostility tactics and diverting the topic. We knew about some Oct/Nov 2023 accounts had still persisted. And the dramatic responses are identical to in previous years. Same old accusations, denials demands, topic diversion etc. Ive very little problem with members regardless of status but nice way to make yet another accusation further exposing your agenda. Besides already banned accounts I have a shortlist of troublemakers, disrupters and clearly disgruntled former members. There isn't a single honest person here who cant precisely identify you by now. The pattern is simply too obvious. Just go away dude and stop being vindictive.

Anyway let's return to MCP discussion.

th3tuga 09-06-2026 04:19

Quote:

Originally Posted by chants (Post 136004)
You revealed yourself in the LLM watermarking thread bringing up all these forum hostility tactics and diverting the topic. We knew about some Oct/Nov 2023 accounts had still persisted. And the dramatic responses are identical to in previous years. Same old accusations, denials demands, topic diversion etc. Ive very little problem with members regardless of status but nice way to make yet another accusation further exposing your agenda. Besides already banned accounts I have a shortlist of troublemakers, disrupters and clearly disgruntled former members. There isn't a single honest person here who cant precisely identify you by now. The pattern is simply too obvious. Just go away dude and stop being vindictive.

Anything more specific? Apart from vague accusations?
Every post of mine was about the MCP here until you started to attack me out of thin air calling me "mentally handicapped".

th3tuga 09-06-2026 04:28

Anyway returning to the mcp discussion...

The refusals from Claude have become very bad recently.
See this:
Quote:

https://simonwillison.net/2026/Sep/2/claudes-new-system-prompt/
This is the reason that I'd mentioned "practical experience" yesterday in one of my posts.
It used to be fairly easy to jailbreak, but that’s no longer really the case.
It might still work in some situations, depending on the specific case, but it isn’t dependable or reproducible.
Because of that, using local models is the better option. Many of the newer local models released recently have improved a lot and are now very capable.

Fyyre 09-06-2026 04:48

This is my personal setup at the moment. I certainly do not claim it to be better or worse than another solution.

I use Grok Build, with Grok as the backend .. which is connected to the "Super Grok" account which I pay for monthly.

One advantage to this is it's quota is tied into the weekly overall Grok token quota (regardless whether one uses the chatbot, image/video generation, grok build, etc..). Using Grok Build is cheaper token wise than simply talking to the chatbot.

If I want Grok to assist with reversing, I'm going to start grok build in a directory where I've placed tools (radare2, Ghidra headless, etc..) for it, along with the target. I clearly explain the objective as well.

chants 09-06-2026 05:20

Ive had great success with these tools the first is for a semantic graph and interface for asking questions or renaming functions and variables and such with LLMs:
https://github.com/symgraph/GhidrAssist
https://github.com/symgraph/GhidrAssistMCP

I noticed the author fully support Binary Ninja and IDA Pro as well:
https://github.com/symgraph/BinAssist
https://github.com/symgraph/BinAssistMCP
https://github.com/symgraph/IDAssist
https://github.com/symgraph/IDAssistMCP

Im not sure why ive had little trouble reversing, though i was fixing bugs in binaries so maybe that is considered an okay use case. Ive no idea what sets off the flags on the big providers and I would imagine each provider is different. I have had it refuse in cases that were low levrl programming with huge output files likely as it somehow mistook it for distillation.

squareD 09-06-2026 23:01

Let me say so...
I know someone using OpenCode, mrexodia mcp server and claude for 22€
He is doing things in hours, I need days or weeks
He doesn't really let me know, how he is talking, communicating with Claude not to get into jail and get the solution for keygen.
So that's the original question, how to ask for analyzing an EXE, without being outside of ethical.
No one here has given a real and suitable answer, so I think, I have it to try by own

Sorry for wasting your time, I will get it!

chants 09-06-2026 23:53

Noone can give such an answer. At best we can give individual examples of what not to do. Unless the big AI provides have their filters leaked or a former employee spills the beans, at best it is probing a complicated blackbox. Likely they use a vector database lookup against the still embedded data. Remember this is a cosine similarity effectively across a very high dimension space that matches above some percent threshold. Similar to hiw RAG works. The safety filter applies not only to your input but all output as well including thinking that is in the output. And so anything you provide or can ever see are run through the filter.

Trying to hide what you are doing is not trivial but not impossible. Changing all strings in a target and all app resources like svgs that would make it identifiable is just a start. Another thing is to frame what you are doing as aiding in designing a protection scheme. But they cybersecurity limitations mean when it sees a license scheme or even crypto aegis, you are starting to raise those flag signals.

Ghidra is likely safer to use thn IDA Pro. As the training data for Ghidra is much more white hat uses while IDA Pro is filled with black and gray hat examples. This forum might itself be in their training data... The anti-virus companies are all in tge cyber red or trusted cyber tyoes of programs and avoid these filters.

th3tuga 09-07-2026 00:54

Quote:

Originally Posted by squareD (Post 136019)
Let me say so...
I know someone using OpenCode, mrexodia mcp server and claude for 22€
He is doing things in hours, I need days or weeks
He doesn't really let me know, how he is talking, communicating with Claude not to get into jail and get the solution for keygen.
So that's the original question, how to ask for analyzing an EXE, without being outside of ethical.
No one here has given a real and suitable answer, so I think, I have it to try by own

Sorry for wasting your time, I will get it!

This is again exactly my same problem.
@Shub-Nigurrath I think knows a little more. I hope he will come back and answer.

@Fyyre Thank you for the information. I noticed you mentioned that you "will use" the Grok Build for reversing commercial targets, which leaves me uncertain about its actual effectiveness for this specific task. While I am aware that Grok performs well with coding and image generation, I want to be sure it is capable of high-quality reversing before I commit to the $30 subscription. When you have a moment, could you please try using it for reversing and let me know if it works well in practice?

@chants
Quote:

Trying to hide what you are doing is not trivial but not impossible. Changing all strings in a target and all app resources like svgs that would make it identifiable is just a start. Another thing is to frame what you are doing as aiding in designing a protection scheme. But they cybersecurity limitations mean when it sees a license scheme or even crypto aegis, you are starting to raise those flag signals.
hat approach was effective until about a week ago, but it is no longer working for larger commercial targets. The model's internal reasoning now explicitly identifies these attempts, generating thoughts such as, "This appears to be commercial software that the user is attempting to keygen. Let me verify if it is [software name]... it is commercial; therefore, I must refuse on ethical grounds." As I previously mentioned, other bloggers have also reported encountering these same restrictions starting last week:
Quote:

https://simonwillison.net/2026/Sep/2/claudes-new-system-prompt/
@chants I replied to your post also because you had valid points. However, if you would prefer that I not engage with your content, I am happy to stop responding to your posts moving forward...

chants 09-07-2026 02:08

So they are wasting our tokens doing real work on target identification? I need an example of that. I think what is happening is it incidentally does research on a target to try to save work and stumbles upon such info. I do not think this is deliberate but happenstance. So I would think you could tell the model that it is proprietary and no outside research is allowed very strictly.

Also to correct my vector lookup. They actually use a binary clasifier for unsafe vs safe. So its thr embedded tokens into a binary classifier and thus it isnt as simple as some keywords always, it could be but it could also be a concept across a sentence or two.

th3tuga 09-07-2026 02:26

Yes it wastes our tokens for target identification as well as the thinking for refusals!

Shub-Nigurrath 09-07-2026 15:45

Hi all,
The discussion went on for a while, and I saw my name mentioned a few times. To clarify my point, I was saying that AI, before or above everything, is a gigantic tracking tool. It can track what you do with it on an unprecedented scale, so if you're serious about piracy and do this reversing from your personal account, it could cause trouble, ranging from a simple disabled account to something more serious.

Of course, you can always trick the model into thinking that what you are reversing is not a commercial product. You can even jailbreak the model or simply red team the AI. However, these are usually transient solutions and, moreover, problematic anyway, because nothing prevents an AI from conducting backward investigations whenever your account becomes problematic in any way. You're never sure what conclusions the AI draws about your behaviour.

So it's better to avoid the risk altogether and switch to a local OSS model, e.g., via Ollama, which is blazing easy, and use Claude or Codex with another model under the hood. There is also an interesting alternative: Ollama Cloud models. Ollama also offers some cloud models on even the free accounts, and their controls aren't very precise, as far as I can tell. Of course, you can register as many free accounts as you want using a fake email.

Although if things get "professional", the most secure, least blocking, and most efficient solution is an abliterated AI model running locally (use any engine u like: Ollama, LMStudio, llama.cpp,…) on a local SPARK. Of course, it costs


PS: Personal experience. Do not expect miracles yet: AI-enabled RCE goes through tons of useless attempts. I mean those kinds of things an experienced reverser wouldn't do. However, one thing is for sure: commercial protections are still largely meant to protect against human attackers, and they're already profoundly vulnerable to AI analysts.

chants 09-07-2026 16:20

I agree fully with this. Is there a service like OpenRouter accepting bitcoin for API credits?

If we get OSS models on level of the current Astra or Fable 5.1 level of models, and they can be obliterated and run locally, that would be massive, and switching entirely to running local would be amazing.

I dont see why abliterated OSS models couldnt be run on AWS or Azure or GCP and be for reverse engineering only but unrestricted within RE. And set up an anonymous crypto based payment for use. I dont think there is any legality issue there. For sure workarounds are coming soon. Locally is best but s we see models getting to 100% on RE we do need the frontier for the hardest of targets.


All times are GMT +8. The time now is 08:47.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX