logoalt Hacker News

teravor • today at 2:58 PM • 2 replies • view on HN

since GLM 5.2 (perhaps even earlier?) it has been remarkably easy to reverse engineer any closed protocol you want as long as you have a binary. previously, it required so much manual effort as to simply not be worth it 95% of the time.

now all you need is IDA or Ghidra MCP, a binary and some vague sloppy instructions.

some more recent models even started instrumenting a running binary (when possible) to enumerate the protocol without being explicitly instructed to, which is even better.


Replies

Retr0id • today at 3:14 PM

You don't even need an MCP, I just let the agent write scripts for headless ghidra. The MCPs are fragile and there isn't a whole lot of knowledge about how to use them in the training datasets, whereas there are plenty of ghidra scripts (and proper docs for the APIs).

➕ show 2 replies
faithraven • today at 3:06 PM

Without admitting to anything, I was surprised by how little time it took to add support for the new protocol to the library. And I didn't even need an MCP server.