
API de Python orientada a objetos para simplificar la interacción con IDA en ingeniería inversa, permitiendo el desarrollo de plugins y la automatización de análisis de desensamblado.
Bip
Bip es un proyecto que tiene como objetivo simplificar el uso de Python para interactuar con IDA. Sus principales objetivos son facilitar el uso de Python en la consola interactiva de IDA y la escritura de plugins. De un modo más general, el objetivo es automatizar tareas recurrentes realizadas a través de la API de Python. Bip también se desarrolla para proporcionar una API más orientada a objetos, "similar a Python" y una documentación real.
Este código no está completo, y muchas características aún faltan. El desarrollo se prioriza en función de lo que la gente pide y de lo que usan los desarrolladores, así que no dudes en hacer PR, Feature Requests e Issues (incluyendo para la documentación).
La documentación está disponible en formato RST (y se puede compilar usando
sphinx) en el directorio docs/; también está
disponible en línea <https://synacktiv.github.io/bip/build/html/index.html>_.
Esta instalación solo se ha probado en Windows y Linux: python install.py.
Es posible usar un argumento opcional --dest para instalar en una
carpeta concreta:
.. code-block:: none
usage: install.py [-h] [--dest DEST]
optional arguments:
-h, --help show this help message and exit
--dest DEST Destination folder where to install Bip
Este instalador no instala ningún plugin por defecto, sino simplemente el núcleo de
Bip. Por defecto, la carpeta de destino es la que usa IDA localmente
(%APPDATA%\Hex-Rays\IDA Pro\ para Windows y $HOME/.idapro para Linux
y MacOSX).
Este resumen tiene como objetivo mostrar cómo se pueden realizar las operaciones más habituales;
está lejos de ser completo. Todas las funciones y objetos en Bip están documentados
usando cadenas de documentación (docstrings), así que solo usa help(BipClass) y help(obj.bipmethod) para
obtener la documentación en tu shell.
El módulo bip.base contiene la mayoría de las características básicas para interactuar
con IDA. En la práctica, esta es principalmente la parte del desensamblador de IDA; esto
incluye: manipulación de instrucciones, funciones, bloques básicos, operandos,
datos, xrefs, estructuras, tipos, ...
Instrucciones / Operandos~~~~~~~~~~~~~~~~~~~~~~~
The classes bip.base.BipInstr and bip.base.BipOperand:
.. code-block:: pycon
>>> from bip.base import *
>>> i = BipInstr() # BipInstr is the base class for representing an instruction
>>> i # by default the address on the screen is taken
BipInstr: 0x1800D324B (mov rcx, r13)
>>> i2 = BipInstr(0x01800D3242) # pass the address in argument
>>> i2
BipInstr: 0x1800D3242 (mov r8d, 8)
>>> i2.next # access next instruction, previous with i2.prev
BipInstr: 0x1800D3248 (mov rdx, r14)
>>> l = [i3 for i3 in BipInstr.iter_all()] # l contains the list of all BipInstruction of the database, iter_all produces a generator object
>>> i.ea # access the address
6443315787
>>> i.mnem # mnemonic representation
mov
>>> i.ops # access to the operands
[<bip.base.operand.BipOperand object at 0x0000022B0291DA90>, <bip.base.operand.BipOperand object at 0x0000022B0291DA58>]
>>> i.ops[0].str # string representation of an operand
rcx
>>> i.bytes # bytes in the instruction
[73L, 139L, 205L]
>>> i.size # number of bytes of this instruction
3
>>> i.comment = "hello" # set a comment, rcomment for the repeatable comments
>>> i
BipInstr: 0x1800D324B (mov rcx, r13; hello)
>>> i.comment # get a comment
hello
>>> i.func # access to the function
Func: RtlQueryProcessLockInformation (0x1800D2FF0)
>>> i.block # access to basic block
BipBlock: 0x1800D3242 (from Func: RtlQueryProcessLockInformation (0x1800D2FF0))
Function / Basic block
The classes ``bip.base.BipFunction`` and ``bip.base.BipBlock``:
.. code-block:: pycon
>>> from bip.base import *
>>> f = BipFunction() # Get the function, screen address used if not provided
>>> f
Func: RtlQueryProcessLockInformation (0x1800D2FF0)
>>> f2 = BipFunction(0x0018010E975) # provide an address, not necessary the first one
>>> f2
Func: sub_18010E968 (0x18010E968)
>>> f == f2 # compare two functions
False
>>> f == BipFunction(0x001800D3021)
True
>>> hex(f.ea) # start address
0x1800d2ff0L
>>> hex(f.end) # end address
0x1800d3284L
>>> f = BipFunction.get_by_name("RtlQueryProcessLockInformation") # fetch the function from its name
>>> f.name # get and set the name
RtlQueryProcessLockInformation
>>> f.name = "test"
>>> f.name
test
>>> f.size # number of bytes in the function
660
>>> f.bytes # bytes of the function
[72L, ..., 255L]
>>> f.callees # list of functions called by this function
[<bip.base.func.BipFunction object at 0x0000022B0291DD30>, ..., <bip.base.func.BipFunction object at 0x0000022B045487F0>]
>>> f.callers # list of functions which call this function
[<bip.base.func.BipFunction object at 0x0000022B04544048>]
>>> f.instr # list of instructions in the function
[<bip.base.instr.BipInstr object at 0x0000022B0291DB00>, ..., <bip.base.instr.BipInstr object at 0x0000022B0454D080>]
>>> f.comment = "welcome to bip" # comment of the function, rcomment for repeatable ones
>>> f.comment
welcome to bip
>>> f.does_return # does this function return ?
True
>>> BipFunction.iter_all() # allows to iter on all functions defined in the database
<generator object iter_all at 0x0000022B029231F8>
>>> f.nb_blocks # number of basic blocks
33
>>> f.blocks # list of blocks
[<bip.base.block.BipBlock object at 0x0000022B04544D68>, ..., <bip.base.block.BipBlock object at 0x0000022B04552240>]
>>> f.blocks[5] # access the basic block 5, could be done with BipBlock(addr)
BipBlock: 0x1800D306E (from Func: test (0x1800D2FF0))
>>> f.blocks[5].func # link back to the function
Func: test (0x1800D2FF0)
>>> f.blocks[5].instr # list of instructions in the block
[<bip.base.instr.BipInstr object at 0x0000022B04544710>, ..., <bip.base.instr.BipInstr object at 0x0000022B0291DB00>]
>>> f.blocks[5].pred # predecessor blocks, blocks where control flow lead to this one
[<bip.base.block.BipBlock object at 0x0000022B04544D68>]
>>> f.blocks[5].succ # successor blocks
[<bip.base.block.BipBlock object at 0x0000022B04544710>, <bip.base.block.BipBlock object at 0x0000022B04544438>]
>>> f.blocks[5].is_ret # is this block containing a return
False
Data
~~~~
The class ``bip.base.BipData``:
.. code-block:: pycon