Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #31  
Old 09-06-2026, 02:17
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 51
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 9
Thanks Rcvd at 22 Times in 14 Posts
th3tuga Reputation: 0
Quote:
Originally Posted by chants View Post
@squareD in no way had I referred to you. This is just a long time forum troll who has had at least a dozen accounts banned and yet keeps creating more and he always wants revenge on me so he yesmans everyone's posts and tries to disrupt any of my posts. Its literally tne same exact textbook behavior exploiting the linearity of this style of forum. And you can see here is is literally doing his exact pattern. Make trouble and harass me, yes man everyone else then angrily demand his revenge as a relative nobody with no contributions, reputation and so on. This guy is extremrly malicious creating competing forums hosting malware infested releases, and even trying to use our sites name. Literally broke every rule in the list and yet still has multiple accounts to this day. What humors me is how mich time and energy he wasted just to be annoying. Mentally handicapped is an understatement and we all know who he is and the absurd hostility he has had towards this venue.

Never be confused by a wolf in sheep's clothes.
@chants I don't remember ever attacking you in any posts. I don't know why you feel that way. Is there any particular post where I have offended you?
I am not anyone who you think me to be...

I have again checked my posts. I've hardly even interacted with any of your posts...
Quote:
https://forum.exetools.com/search.php?do=finduser&u=39238
Reply With Quote
  #32  
Old 09-06-2026, 03:22
chants chants is online now
VIP
 
Join Date: Jul 2016
Posts: 870
Rept. Given: 48
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 751
Thanks Rcvd at 1,171 Times in 542 Posts
chants Reputation: 53
"would have been banned long ago on any other forum" the same exact thing all the banned accounts would always say. That looks copy and pasted even. Dude the gig is up, if you cant let bygones be bygones, then scram. 8+ years of this childish nonsense and making yourself the most despised person in all of reversing and yet still you persist. You should be grateful to even have an account here given the disgustingly hostile acts impersonating and harassing members here should amount to a life sentence.

It would be nice to return to discussing MCP.
Reply With Quote
  #33  
Old 09-06-2026, 03:25
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 51
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 9
Thanks Rcvd at 22 Times in 14 Posts
th3tuga Reputation: 0
Quote:
Originally Posted by chants View Post
"would have been banned long ago on any other forum" the same exact thing all the banned accounts would always say. That looks copy and pasted even. Dude the gig is up, if you cant let bygones be bygones, then scram. 8+ years of this childish nonsense and making yourself the most despised person in all of reversing and yet still you persist. You should be grateful to even have an account here given the disgustingly hostile acts impersonating and harassing members here should amount to a life sentence.
Until you began targeting me two days ago, I had no knowledge of your existence and you were completely unknown to me. Consequently, I am confused as to why you perceive me as an adversary, especially since any conflict between us is entirely one-sided and imagined.

I made that statement because calling someone as "mentally handicapped" does get you banned on any online forum these days...
There is a way to disagree without referring to them as "mentally handicapped".

It appears to me that you attack any non-VIP user who remotely interacts in any thread that you've replied. Of course, you can't attack other VIP users since that would get you immediately banned.
So you're attacking accounts like mine who have never even interacted with you?
Reply With Quote
  #34  
Old 09-06-2026, 04:15
chants chants is online now
VIP
 
Join Date: Jul 2016
Posts: 870
Rept. Given: 48
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 751
Thanks Rcvd at 1,171 Times in 542 Posts
chants Reputation: 53
You revealed yourself in the LLM watermarking thread bringing up all these forum hostility tactics and diverting the topic. We knew about some Oct/Nov 2023 accounts had still persisted. And the dramatic responses are identical to in previous years. Same old accusations, denials demands, topic diversion etc. Ive very little problem with members regardless of status but nice way to make yet another accusation further exposing your agenda. Besides already banned accounts I have a shortlist of troublemakers, disrupters and clearly disgruntled former members. There isn't a single honest person here who cant precisely identify you by now. The pattern is simply too obvious. Just go away dude and stop being vindictive.

Anyway let's return to MCP discussion.
Reply With Quote
  #35  
Old 09-06-2026, 04:19
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 51
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 9
Thanks Rcvd at 22 Times in 14 Posts
th3tuga Reputation: 0
Quote:
Originally Posted by chants View Post
You revealed yourself in the LLM watermarking thread bringing up all these forum hostility tactics and diverting the topic. We knew about some Oct/Nov 2023 accounts had still persisted. And the dramatic responses are identical to in previous years. Same old accusations, denials demands, topic diversion etc. Ive very little problem with members regardless of status but nice way to make yet another accusation further exposing your agenda. Besides already banned accounts I have a shortlist of troublemakers, disrupters and clearly disgruntled former members. There isn't a single honest person here who cant precisely identify you by now. The pattern is simply too obvious. Just go away dude and stop being vindictive.
Anything more specific? Apart from vague accusations?
Every post of mine was about the MCP here until you started to attack me out of thin air calling me "mentally handicapped".
Reply With Quote
  #36  
Old 09-06-2026, 04:28
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 51
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 9
Thanks Rcvd at 22 Times in 14 Posts
th3tuga Reputation: 0
Anyway returning to the mcp discussion...

The refusals from Claude have become very bad recently.
See this:
Quote:
https://simonwillison.net/2026/Sep/2/claudes-new-system-prompt/
This is the reason that I'd mentioned "practical experience" yesterday in one of my posts.
It used to be fairly easy to jailbreak, but that’s no longer really the case.
It might still work in some situations, depending on the specific case, but it isn’t dependable or reproducible.
Because of that, using local models is the better option. Many of the newer local models released recently have improved a lot and are now very capable.
Reply With Quote
The Following User Says Thank You to th3tuga For This Useful Post:
niculaita (09-06-2026)
  #37  
Old 09-06-2026, 04:48
Fyyre's Avatar
Fyyre Fyyre is offline
Fyyre
 
Join Date: Dec 2009
Location: 0°N 0°E / 0°N 0°E / 0; 0
Posts: 306
Rept. Given: 107
Rept. Rcvd 97 Times in 46 Posts
Thanks Given: 214
Thanks Rcvd at 429 Times in 139 Posts
Fyyre Reputation: 97
This is my personal setup at the moment. I certainly do not claim it to be better or worse than another solution.

I use Grok Build, with Grok as the backend .. which is connected to the "Super Grok" account which I pay for monthly.

One advantage to this is it's quota is tied into the weekly overall Grok token quota (regardless whether one uses the chatbot, image/video generation, grok build, etc..). Using Grok Build is cheaper token wise than simply talking to the chatbot.

If I want Grok to assist with reversing, I'm going to start grok build in a directory where I've placed tools (radare2, Ghidra headless, etc..) for it, along with the target. I clearly explain the objective as well.
__________________
Pax in vultu, bellum in corde.

--

https://github.com/Fyyre
Reply With Quote
The Following 2 Users Say Thank You to Fyyre For This Useful Post:
niculaita (09-06-2026), th3tuga (09-07-2026)
  #38  
Old 09-06-2026, 05:20
chants chants is online now
VIP
 
Join Date: Jul 2016
Posts: 870
Rept. Given: 48
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 751
Thanks Rcvd at 1,171 Times in 542 Posts
chants Reputation: 53
Ive had great success with these tools the first is for a semantic graph and interface for asking questions or renaming functions and variables and such with LLMs:
https://github.com/symgraph/GhidrAssist
https://github.com/symgraph/GhidrAssistMCP

I noticed the author fully support Binary Ninja and IDA Pro as well:
https://github.com/symgraph/BinAssist
https://github.com/symgraph/BinAssistMCP
https://github.com/symgraph/IDAssist
https://github.com/symgraph/IDAssistMCP

Im not sure why ive had little trouble reversing, though i was fixing bugs in binaries so maybe that is considered an okay use case. Ive no idea what sets off the flags on the big providers and I would imagine each provider is different. I have had it refuse in cases that were low levrl programming with huge output files likely as it somehow mistook it for distillation.
Reply With Quote
The Following User Says Thank You to chants For This Useful Post:
niculaita (09-06-2026)
  #39  
Old 09-06-2026, 23:01
squareD's Avatar
squareD squareD is offline
VIP
 
Join Date: Aug 2005
Location: Banana Republic
Posts: 320
Rept. Given: 32
Rept. Rcvd 35 Times in 27 Posts
Thanks Given: 45
Thanks Rcvd at 120 Times in 79 Posts
squareD Reputation: 36
Let me say so...
I know someone using OpenCode, mrexodia mcp server and claude for 22€
He is doing things in hours, I need days or weeks
He doesn't really let me know, how he is talking, communicating with Claude not to get into jail and get the solution for keygen.
So that's the original question, how to ask for analyzing an EXE, without being outside of ethical.
No one here has given a real and suitable answer, so I think, I have it to try by own

Sorry for wasting your time, I will get it!
__________________
The three worst enemies of the reversers: sun , fresh air and especially this unbearable roar of birds ...
Reply With Quote
The Following 2 Users Say Thank You to squareD For This Useful Post:
chants (09-06-2026), th3tuga (09-07-2026)
  #40  
Old 09-06-2026, 23:53
chants chants is online now
VIP
 
Join Date: Jul 2016
Posts: 870
Rept. Given: 48
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 751
Thanks Rcvd at 1,171 Times in 542 Posts
chants Reputation: 53
Noone can give such an answer. At best we can give individual examples of what not to do. Unless the big AI provides have their filters leaked or a former employee spills the beans, at best it is probing a complicated blackbox. Likely they use a vector database lookup against the still embedded data. Remember this is a cosine similarity effectively across a very high dimension space that matches above some percent threshold. Similar to hiw RAG works. The safety filter applies not only to your input but all output as well including thinking that is in the output. And so anything you provide or can ever see are run through the filter.

Trying to hide what you are doing is not trivial but not impossible. Changing all strings in a target and all app resources like svgs that would make it identifiable is just a start. Another thing is to frame what you are doing as aiding in designing a protection scheme. But they cybersecurity limitations mean when it sees a license scheme or even crypto aegis, you are starting to raise those flag signals.

Ghidra is likely safer to use thn IDA Pro. As the training data for Ghidra is much more white hat uses while IDA Pro is filled with black and gray hat examples. This forum might itself be in their training data... The anti-virus companies are all in tge cyber red or trusted cyber tyoes of programs and avoid these filters.
Reply With Quote
  #41  
Old 09-07-2026, 00:54
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 51
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 9
Thanks Rcvd at 22 Times in 14 Posts
th3tuga Reputation: 0
Quote:
Originally Posted by squareD View Post
Let me say so...
I know someone using OpenCode, mrexodia mcp server and claude for 22€
He is doing things in hours, I need days or weeks
He doesn't really let me know, how he is talking, communicating with Claude not to get into jail and get the solution for keygen.
So that's the original question, how to ask for analyzing an EXE, without being outside of ethical.
No one here has given a real and suitable answer, so I think, I have it to try by own

Sorry for wasting your time, I will get it!
This is again exactly my same problem.
@Shub-Nigurrath I think knows a little more. I hope he will come back and answer.

@Fyyre Thank you for the information. I noticed you mentioned that you "will use" the Grok Build for reversing commercial targets, which leaves me uncertain about its actual effectiveness for this specific task. While I am aware that Grok performs well with coding and image generation, I want to be sure it is capable of high-quality reversing before I commit to the $30 subscription. When you have a moment, could you please try using it for reversing and let me know if it works well in practice?

@chants
Quote:
Trying to hide what you are doing is not trivial but not impossible. Changing all strings in a target and all app resources like svgs that would make it identifiable is just a start. Another thing is to frame what you are doing as aiding in designing a protection scheme. But they cybersecurity limitations mean when it sees a license scheme or even crypto aegis, you are starting to raise those flag signals.
hat approach was effective until about a week ago, but it is no longer working for larger commercial targets. The model's internal reasoning now explicitly identifies these attempts, generating thoughts such as, "This appears to be commercial software that the user is attempting to keygen. Let me verify if it is [software name]... it is commercial; therefore, I must refuse on ethical grounds." As I previously mentioned, other bloggers have also reported encountering these same restrictions starting last week:
Quote:
https://simonwillison.net/2026/Sep/2/claudes-new-system-prompt/
@chants I replied to your post also because you had valid points. However, if you would prefer that I not engage with your content, I am happy to stop responding to your posts moving forward...
Reply With Quote
  #42  
Old 09-07-2026, 02:08
chants chants is online now
VIP
 
Join Date: Jul 2016
Posts: 870
Rept. Given: 48
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 751
Thanks Rcvd at 1,171 Times in 542 Posts
chants Reputation: 53
So they are wasting our tokens doing real work on target identification? I need an example of that. I think what is happening is it incidentally does research on a target to try to save work and stumbles upon such info. I do not think this is deliberate but happenstance. So I would think you could tell the model that it is proprietary and no outside research is allowed very strictly.

Also to correct my vector lookup. They actually use a binary clasifier for unsafe vs safe. So its thr embedded tokens into a binary classifier and thus it isnt as simple as some keywords always, it could be but it could also be a concept across a sentence or two.

Last edited by chants; 09-07-2026 at 04:07.
Reply With Quote
  #43  
Old 09-07-2026, 02:26
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 51
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 9
Thanks Rcvd at 22 Times in 14 Posts
th3tuga Reputation: 0
Yes it wastes our tokens for target identification as well as the thinking for refusals!
Reply With Quote
  #44  
Old 09-07-2026, 15:45
Shub-Nigurrath's Avatar
Shub-Nigurrath Shub-Nigurrath is offline
VIP
 
Join Date: Mar 2004
Location: Obscure Kadath
Posts: 990
Rept. Given: 72
Rept. Rcvd 431 Times in 101 Posts
Thanks Given: 87
Thanks Rcvd at 418 Times in 134 Posts
Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499
Hi all,
The discussion went on for a while, and I saw my name mentioned a few times. To clarify my point, I was saying that AI, before or above everything, is a gigantic tracking tool. It can track what you do with it on an unprecedented scale, so if you're serious about piracy and do this reversing from your personal account, it could cause trouble, ranging from a simple disabled account to something more serious.

Of course, you can always trick the model into thinking that what you are reversing is not a commercial product. You can even jailbreak the model or simply red team the AI. However, these are usually transient solutions and, moreover, problematic anyway, because nothing prevents an AI from conducting backward investigations whenever your account becomes problematic in any way. You're never sure what conclusions the AI draws about your behaviour.

So it's better to avoid the risk altogether and switch to a local OSS model, e.g., via Ollama, which is blazing easy, and use Claude or Codex with another model under the hood. There is also an interesting alternative: Ollama Cloud models. Ollama also offers some cloud models on even the free accounts, and their controls aren't very precise, as far as I can tell. Of course, you can register as many free accounts as you want using a fake email.

Although if things get "professional", the most secure, least blocking, and most efficient solution is an abliterated AI model running locally (use any engine u like: Ollama, LMStudio, llama.cpp,…) on a local SPARK. Of course, it costs


PS: Personal experience. Do not expect miracles yet: AI-enabled RCE goes through tons of useless attempts. I mean those kinds of things an experienced reverser wouldn't do. However, one thing is for sure: commercial protections are still largely meant to protect against human attackers, and they're already profoundly vulnerable to AI analysts.
__________________
Ŝħůb-Ňìĝùŕřaŧħ ₪)
There are only 10 types of people in the world: Those who understand binary, and those who don't
http://www.accessroot.com

Last edited by Shub-Nigurrath; 09-07-2026 at 15:53.
Reply With Quote
The Following User Says Thank You to Shub-Nigurrath For This Useful Post:
th3tuga (09-07-2026)
  #45  
Old 09-07-2026, 16:20
chants chants is online now
VIP
 
Join Date: Jul 2016
Posts: 870
Rept. Given: 48
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 751
Thanks Rcvd at 1,171 Times in 542 Posts
chants Reputation: 53
I agree fully with this. Is there a service like OpenRouter accepting bitcoin for API credits?

If we get OSS models on level of the current Astra or Fable 5.1 level of models, and they can be obliterated and run locally, that would be massive, and switching entirely to running local would be amazing.

I dont see why abliterated OSS models couldnt be run on AWS or Azure or GCP and be for reverse engineering only but unrestricted within RE. And set up an anonymous crypto based payment for use. I dont think there is any legality issue there. For sure workarounds are coming soon. Locally is best but s we see models getting to 100% on RE we do need the frontier for the hardest of targets.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 03:07.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )