
تصحيح ثنائي من بايثون
يقوم بتطبيق رقع (Patches) على ملف ثنائي بصيغة ELF باستخدام سكريبت بايثون واحد أو أكثر.
الاستخدام:
patch <binary> <patchdir|file> [patchdir|file...]
يحتوي على ملف أو أكثر من ملفات رقع بايثون، والتي سيتم تنفيذها بترتيب أبجدي ضد ملف ثنائي.
إلغاء عنوان، حقن دالة تجميع، وربط نقطة الدخول:
def simple_patch(pt):
# nop out a jump at the entry point
pt.patch(pt.entry, hex='90' * 5)
# inject assembly into the binary and return the address
addr = pt.inject(asm='mov eax, 1; ret')
# hook the entry point to make it call addr (ret will run the original entry point)
pt.hook(pt.entry, addr)
استبدال دالة بلغة C:
def replace_free(pt):
# pretend free() is at this address:
old_free = 0x804fc4
# inject a function to replace free()
new_free = pt.inject(c=r'''
void free_stub(void *addr) {
printf("stubbed free(%p)\n", addr);
}
''')
# patch the beginning of free() with a jump to our new function
pt.patch(old_free, jmp=new_free)
addr = search(data)
hook(addr, new_addr)
patch(addr, *compile arg*)
addr = inject(*compile arg*)
*compile arg* هو أي مما يلي:
raw='data'
hex='0bfe'
asm='nop'
jmp=0xaddr
c='void func() { int a; a = 1; }' (مدعوم فقط في inject، وليس في patch)
توجد بعض السكريبتات في المسار ida/. قم بتشغيلها هكذا:
/Applications/IDA\ Pro\ 6.8/idaq.app/Contents/MacOS/idaq64 -A -Sida/allfuncs.py a.out
عند التشغيل بهذه الطريقة، سينشئ allfuncs.py الملف a.out.funcs الذي تستخدمه سكريبتات التقوية (hardening scripts).
هذه الأدوات حالياً خاصة إلى حد ما بـ CGC و x86، لكن سيتم نقلها للاستخدام العام في المستقبل.
./deps.sh لتثبيتها تلقائياً.