
Objektorientierte Python-API zur Vereinfachung der Interaktion mit IDA für Reverse Engineering, die Plugin-Entwicklung und Automatisierung von Disassembly-Analysen ermöglicht.
Bip
Bip ist ein Projekt, das die Verwendung von Python für die Interaktion mit IDA vereinfachen soll. Die Hauptziele sind die Nutzung von Python in der interaktiven Konsole von IDA und das Schreiben von Plugins zu erleichtern. Allgemeiner gesagt soll das Ziel darin bestehen, wiederkehrende Aufgaben, die über die Python-API erledigt werden, zu automatisieren. Bip wird außerdem entwickelt, um eine objektorientiertere, "python-artige" API und eine echte Dokumentation bereitzustellen.
Dieser Code ist nicht vollständig, und viele Funktionen fehlen noch. Die Entwicklung priorisiert das, was die Leute anfragen und was die Entwickler selbst verwenden. Zögern Sie also nicht, PRs, Feature Requests und Issues zu erstellen (auch für die Dokumentation).
Die Dokumentation ist im RST-Format (und kann mit Sphinx kompiliert werden) im
Verzeichnis docs/ verfügbar; sie ist auch
online <https://synacktiv.github.io/bip/build/html/index.html>_ verfügbar.
Diese Installation wurde nur unter Windows und Linux getestet: python install.py.
Es ist möglich, ein optionales --dest-Argument zu verwenden, um in einem
bestimmten Ordner zu installieren:
.. code-block:: none
usage: install.py [-h] [--dest DEST]
optional arguments:
-h, --help show this help message and exit
--dest DEST Destination folder where to install Bip
Dieser Installer installiert standardmäßig keine Plugins, sondern nur den Kern
von Bip. Standardmäßig ist der Zielordner derjenige, der von IDA lokal verwendet
wird (%APPDATA%\Hex-Rays\IDA Pro\ für Windows und $HOME/.idapro für
Linux und MacOSX).
Diese Übersicht soll zeigen, wie die gängigsten Operationen ausgeführt werden
können; sie ist alles andere als vollständig. Alle Funktionen und Objekte in Bip
sind mit Docstrings dokumentiert. Verwenden Sie einfach help(BipClass) und
help(obj.bipmethod), um die Doku in Ihrer Shell zu erhalten.
Das Modul bip.base enthält die meisten grundlegenden Funktionen für die
Schnittstelle zu IDA. In der Praxis betrifft das hauptsächlich den
Disassembler-Teil von IDA, einschließlich: Manipulation von Anweisungen,
Funktionen, Basisblöcken, Operanden, Daten, Xrefs, Strukturen, Typen, ...
Anweisungen / Operanden~~~~~~~~~~~~~~~~~~~~~~~
The classes bip.base.BipInstr and bip.base.BipOperand:
.. code-block:: pycon
>>> from bip.base import *
>>> i = BipInstr() # BipInstr is the base class for representing an instruction
>>> i # by default the address on the screen is taken
BipInstr: 0x1800D324B (mov rcx, r13)
>>> i2 = BipInstr(0x01800D3242) # pass the address in argument
>>> i2
BipInstr: 0x1800D3242 (mov r8d, 8)
>>> i2.next # access next instruction, previous with i2.prev
BipInstr: 0x1800D3248 (mov rdx, r14)
>>> l = [i3 for i3 in BipInstr.iter_all()] # l contains the list of all BipInstruction of the database, iter_all produces a generator object
>>> i.ea # access the address
6443315787
>>> i.mnem # mnemonic representation
mov
>>> i.ops # access to the operands
[<bip.base.operand.BipOperand object at 0x0000022B0291DA90>, <bip.base.operand.BipOperand object at 0x0000022B0291DA58>]
>>> i.ops[0].str # string representation of an operand
rcx
>>> i.bytes # bytes in the instruction
[73L, 139L, 205L]
>>> i.size # number of bytes of this instruction
3
>>> i.comment = "hello" # set a comment, rcomment for the repeatable comments
>>> i
BipInstr: 0x1800D324B (mov rcx, r13; hello)
>>> i.comment # get a comment
hello
>>> i.func # access to the function
Func: RtlQueryProcessLockInformation (0x1800D2FF0)
>>> i.block # access to basic block
BipBlock: 0x1800D3242 (from Func: RtlQueryProcessLockInformation (0x1800D2FF0))
Function / Basic block
The classes ``bip.base.BipFunction`` and ``bip.base.BipBlock``:
.. code-block:: pycon
>>> from bip.base import *
>>> f = BipFunction() # Get the function, screen address used if not provided
>>> f
Func: RtlQueryProcessLockInformation (0x1800D2FF0)
>>> f2 = BipFunction(0x0018010E975) # provide an address, not necessary the first one
>>> f2
Func: sub_18010E968 (0x18010E968)
>>> f == f2 # compare two functions
False
>>> f == BipFunction(0x001800D3021)
True
>>> hex(f.ea) # start address
0x1800d2ff0L
>>> hex(f.end) # end address
0x1800d3284L
>>> f = BipFunction.get_by_name("RtlQueryProcessLockInformation") # fetch the function from its name
>>> f.name # get and set the name
RtlQueryProcessLockInformation
>>> f.name = "test"
>>> f.name
test
>>> f.size # number of bytes in the function
660
>>> f.bytes # bytes of the function
[72L, ..., 255L]
>>> f.callees # list of functions called by this function
[<bip.base.func.BipFunction object at 0x0000022B0291DD30>, ..., <bip.base.func.BipFunction object at 0x0000022B045487F0>]
>>> f.callers # list of functions which call this function
[<bip.base.func.BipFunction object at 0x0000022B04544048>]
>>> f.instr # list of instructions in the function
[<bip.base.instr.BipInstr object at 0x0000022B0291DB00>, ..., <bip.base.instr.BipInstr object at 0x0000022B0454D080>]
>>> f.comment = "welcome to bip" # comment of the function, rcomment for repeatable ones
>>> f.comment
welcome to bip
>>> f.does_return # does this function return ?
True
>>> BipFunction.iter_all() # allows to iter on all functions defined in the database
<generator object iter_all at 0x0000022B029231F8>
>>> f.nb_blocks # number of basic blocks
33
>>> f.blocks # list of blocks
[<bip.base.block.BipBlock object at 0x0000022B04544D68>, ..., <bip.base.block.BipBlock object at 0x0000022B04552240>]
>>> f.blocks[5] # access the basic block 5, could be done with BipBlock(addr)
BipBlock: 0x1800D306E (from Func: test (0x1800D2FF0))
>>> f.blocks[5].func # link back to the function
Func: test (0x1800D2FF0)
>>> f.blocks[5].instr # list of instructions in the block
[<bip.base.instr.BipInstr object at 0x0000022B04544710>, ..., <bip.base.instr.BipInstr object at 0x0000022B0291DB00>]
>>> f.blocks[5].pred # predecessor blocks, blocks where control flow lead to this one
[<bip.base.block.BipBlock object at 0x0000022B04544D68>]
>>> f.blocks[5].succ # successor blocks
[<bip.base.block.BipBlock object at 0x0000022B04544710>, <bip.base.block.BipBlock object at 0x0000022B04544438>]
>>> f.blocks[5].is_ret # is this block containing a return
False
Data
~~~~
The class ``bip.base.BipData``:
.. code-block:: pycon