The brief method. If I get good response to this post, I will put up a more detailed and in-depth look at malware reversing on Linux. Steps: * Download IDA Pro (freeware) * Install wine * Install IDA Pro * Start reversing Download IDA Pro (freeware): $ cd /tmp $ wget Install wine: $ sudo aptitude install wine Install IDA Pro: $ wine /tmp/idafree49.exe Start reversing: $ wine '~/.wine/drive_c/Program Files/IDA Free/idag.exe' -> Now open the malware binary and select the option for ELF executables This post is a stub for a future longer version if anyone shows interest.

IDA Pro is a programmable, interactive, multi-processor disassembler combined with a local and remote debugger and augmented by a complete plugin programming environment.IDA Pro is in many ways unique.

Film I don't even know how many Linux Journal readers actually reverse malware on Linux.

The problem with your suggestion is the annoying fact that you still need a valid license in order to run Windows in a virtual machine (not that this ever stopped anyone, but I'm just stating the facts), at which point you might as well just get the real/whole thing (Windows, that is). IDA Pro is generally the de-facto standard for any malware analysts I've spoken with. For me however, everse engineering is just a side hobby in which I occasionally dabble; so it's not really an area of my expertise. From my limited experince, the free version has always worked just fine for me with WINE, though a VM is certainly a better option (given you have the choice!).

There are some other interactive dissamblers such as the reasonablly popular and well accepted Lida, which is for Linux. The paid version(s) (of IDA) do support Linux and Mac in addition to Winblowz. EDIT: If you're going to 'pirate'/hack a Windows license (for the VM or whatever), you might as well go all out and do the same for IDA as well. Not That I encourage you or anyone else to do such a thing.

