Skip to content

idaxex + xex1tool 0.24a

Choose a tag to compare

@emoose emoose released this 06 Jul 18:04
· 93 commits to master since this release

idaxex: XEX loader for IDA 7+, supporting most known Xbox360/Xenon executable formats.

Built for IDA Pro 7.2.

To install idaxex simply extract idaxex64.dll into IDA's 'loaders' directory (eg. C:\Program Files\IDA 7.2\loaders)

Also included is a preliminary build of xex1tool, which should hopefully support printing headers & extracting basefile/resources from all the XEX revisions supported by idaxex, usage is the same as XexTool.

Changes from 0.23

xex: load XEX2D imagesize properly, fixes XEX2D decompression
xex1tool: fix XEX3F displaying as XEX2F, fix basefile extraction text, some minor XEX0 work

Recommendations

Recommend pairing this loader with the PPCAltivec plugin, to help IDA understand any Altivec instructions. Fortunately yui-konnu has released an updated version for IDA 7 here: https://github.com/yui-konnu/PPC-Altivec-IDA

PPC2C also comes in useful for making sense of some of the bit-fiddling opcodes, updated code for IDA 7 can be found on gibbed's repo here: https://github.com/gibbed/ppc2c

You can also integrate Ghidra's decompiler into IDA by using cseagle's blc plugin, which works pretty well with both X360 executable formats (XEX / EXE): https://github.com/cseagle/blc

Symbols

If you want to load any symbols in they should hopefully work fine with this loader - IDA should be able to load .PDBs fine by itself (though not .XDBs, which aren't that interesting anyway since they only include symbols for XDK librarys).

When loading the PDB IDA will ask for the address to load it to, make sure to give it the correct base address of the XEX (eg. 0x82000000 is common, but others might be used too - check with xex1tool first), and uncheck the "Types only" option - you'll probably get an alert about the input file not matching (as the PDB was made for the EXE before it was converted to XEX), you can usually ignore that, and as long as you have the correct PDB it should then load in fine.

I've also modified the ida-pro-loadmap .MAP symbols loader to work with loader plugins like this one too, and also allow it to mark even more functions than it previously could, along with being able to mark functions that were imported from known SDK libraries: https://github.com/emoose/ida-pro-loadmap/releases

Support

As there's only an x64 build of PPCAltivec I've decided to only release the x64 build of idaxex - to help make sure people don't accidentally load into the 32-bit IDA and lose out on Altivec support. (a 32-bit version of idaxex can be built, but IMO there's not really any point)

idaxex has no user-configurable options - just extract the loader, reload IDA and you should now be able to load XEX files!

If you have any problems please let me know about them on the Issues page!