online version:
- https://fastbin.io/reverse - ghidra online
installation:
https://ghidra-sre.org/InstallationGuide.html
basic usage:
https://www.youtube.com/watch?v=fTGTnrgjuGA
https://threatvector.cylance.com/en_us/home/an-introduction-to-code-analysis-with-ghidra.html
notes on interpretation:
double click on any variable or function name to go to it in the assembly
rename vars or functions when you know what they are
DAT_ ...
in the decompiler,
DAT_ indicates global variables....ghidra can't interpret them, so go to it in assembly and edit them ourselves, shows the actual characters / bytes in those addresses.
A char is a byte, so change type to char[n]
double click on DAT__00400b48 to go to that data in the assembly and see what kind of data it is...
for example:
DAT_00400b48 XREF[1]: main:004009ec(*)
00400b48 ?? 25h %
00400b49 ?? 64h d
00400b4a ?? 00h
you see its %d with a null pointer, so integer