AutoDiff Online

Marco Ramilli
Date
19 January 2011
Read
Share
Hi Folks,
today (jetlagged and sick to travel 🙂 I want to share the AutoDiff online service available here.
AutoDiff is a project which performs automated binary differential analysis between two executable files. This is especially useful for reverse engineering vulnerability patches and spotting other additional code updates. AutoDiff allows to find executable code similarities and differences among two executable files. Additionally it also includes some heuristics methods for matching variables (objects) between two executable files. AutoDiff is ultra fast, standalone tool. It was especially designed to diff Portable Executable files released by Microsoft every time in the security bulletin.
Lets focalize the output page:

From AutoDiff webpage you may see what files has been modified (in the above picture: Windows 7 dxgkrnl.sys, in date 6 January 2011), what blocks has been updated and the whole detailed page regarding every changed function (see image below).

This post was about remembering the existence of this tool for every time I need to find out the "modified function" during any patch-to-exploit procedure.
Marco Ramilli
Date
19 January 2011
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier