Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
bip — API Python orientée objet pour simplifier l'interaction avec IDA pour la rétro-ingénierie, permettant le développement de plugins et l'automatisation des analyses de désassemblage. | Kitploit
Outils/GitHubGitHub/synacktiv/bip
Analyse StatiqueAnalyse de CodeRétro-ingénierieScripting et AutomatisationAnalyse de Binaires
GitHubsynacktiv/bip

bip

API Python orientée objet pour simplifier l'interaction avec IDA pour la rétro-ingénierie, permettant le développement de plugins et l'automatisation des analyses de désassemblage.

Voir le dépôt
2051913il y a 4 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

Bip

Bip est un projet qui vise à simplifier l'utilisation de Python pour interagir avec IDA. Ses objectifs principaux sont de faciliter l'utilisation de Python dans la console interactive d'IDA et l'écriture de plugins. D'une manière plus générale, l'objectif est d'automatiser les tâches récurrentes effectuées via l'API Python. Bip est également développé pour fournir une API plus orientée objet, une API « python-like » et une vraie documentation.

Ce code n'est pas complet, et de nombreuses fonctionnalités manquent encore. Le développement est priorisé en fonction des demandes des utilisateurs et de ce que les développeurs utilisent, alors n'hésitez pas à soumettre des PR, des demandes de fonctionnalités et des issues (y compris pour la documentation).

La documentation est disponible au format RST (et peut être compilée avec sphinx) dans le répertoire docs/, elle est également disponible en ligne <https://synacktiv.github.io/bip/build/html/index.html>_.

  • Version d'IDA actuelle : IDA 7.5SP1 et Python 2.7 ou 3.8
  • Dernière version de Bip : 1.0

Installation

Cette installation a été testée uniquement sous Windows et Linux : python install.py.

Il est possible d'utiliser un argument optionnel --dest pour installer dans un dossier particulier :

.. code-block:: none

usage: install.py [-h] [--dest DEST]

optional arguments:
  -h, --help   show this help message and exit
  --dest DEST  Destination folder where to install Bip

Cet installateur n'installe aucun plugin par défaut, mais simplement le cœur de Bip. Par défaut, le dossier de destination est celui utilisé localement par IDA (%APPDATA%\Hex-Rays\IDA Pro\ sous Windows et $HOME/.idapro sous Linux et MacOSX).

Aperçu

Cet aperçu a pour but de montrer comment effectuer les opérations les plus courantes, il est loin d'être complet. Toutes les fonctions et objets de Bip sont documentés à l'aide de docstrings, il suffit donc d'utiliser help(BipClass) et help(obj.bipmethod) pour obtenir la documentation dans votre shell.

Base

Le module bip.base contient la plupart des fonctionnalités de base pour interfacer avec IDA. En pratique, il s'agit principalement de la partie désassembleur d'IDA, ce qui inclut : la manipulation des instructions, des fonctions, des blocs de base, des opérandes, des données, des xrefs, des structures, des types, ...

Instructions / Opérandes~~~~~~~~~~~~~~~~~~~~~~~

The classes bip.base.BipInstr and bip.base.BipOperand:

.. code-block:: pycon

>>> from bip.base import *
>>> i = BipInstr() # BipInstr is the base class for representing an instruction
>>> i # by default the address on the screen is taken
BipInstr: 0x1800D324B (mov     rcx, r13)
>>> i2 = BipInstr(0x01800D3242) # pass the address in argument
>>> i2
BipInstr: 0x1800D3242 (mov     r8d, 8)
>>> i2.next # access next instruction, previous with i2.prev
BipInstr: 0x1800D3248 (mov     rdx, r14)
>>> l = [i3 for i3 in BipInstr.iter_all()] # l contains the list of all BipInstruction of the database, iter_all produces a generator object
>>> i.ea # access the address
6443315787
>>> i.mnem # mnemonic representation
mov
>>> i.ops # access to the operands
[<bip.base.operand.BipOperand object at 0x0000022B0291DA90>, <bip.base.operand.BipOperand object at 0x0000022B0291DA58>]
>>> i.ops[0].str # string representation of an operand
rcx
>>> i.bytes # bytes in the instruction
[73L, 139L, 205L]
>>> i.size # number of bytes of this instruction
3
>>> i.comment = "hello" # set a comment, rcomment for the repeatable comments
>>> i
BipInstr: 0x1800D324B (mov     rcx, r13; hello)
>>> i.comment # get a comment
hello
>>> i.func # access to the function
Func: RtlQueryProcessLockInformation (0x1800D2FF0)
>>> i.block # access to basic block
BipBlock: 0x1800D3242 (from Func: RtlQueryProcessLockInformation (0x1800D2FF0))

Function / Basic block


The classes ``bip.base.BipFunction`` and ``bip.base.BipBlock``:

.. code-block:: pycon

    >>> from bip.base import *
    >>> f = BipFunction() # Get the function, screen address used if not provided
    >>> f
    Func: RtlQueryProcessLockInformation (0x1800D2FF0)
    >>> f2 = BipFunction(0x0018010E975) # provide an address, not necessary the first one
    >>> f2
    Func: sub_18010E968 (0x18010E968)
    >>> f == f2 # compare two functions
    False
    >>> f == BipFunction(0x001800D3021)
    True
    >>> hex(f.ea) # start address
    0x1800d2ff0L
    >>> hex(f.end) # end address
    0x1800d3284L
    >>> f = BipFunction.get_by_name("RtlQueryProcessLockInformation") # fetch the function from its name
    >>> f.name # get and set the name
    RtlQueryProcessLockInformation
    >>> f.name = "test"
    >>> f.name
    test
    >>> f.size # number of bytes in the function
    660
    >>> f.bytes # bytes of the function
    [72L, ..., 255L]
    >>> f.callees # list of functions called by this function
    [<bip.base.func.BipFunction object at 0x0000022B0291DD30>, ..., <bip.base.func.BipFunction object at 0x0000022B045487F0>]
    >>> f.callers # list of functions which call this function
    [<bip.base.func.BipFunction object at 0x0000022B04544048>]
    >>> f.instr # list of instructions in the function
    [<bip.base.instr.BipInstr object at 0x0000022B0291DB00>, ..., <bip.base.instr.BipInstr object at 0x0000022B0454D080>]
    >>> f.comment = "welcome to bip" # comment of the function, rcomment for repeatable ones
    >>> f.comment
    welcome to bip
    >>> f.does_return # does this function return ?
    True
    >>> BipFunction.iter_all() # allows to iter on all functions defined in the database
    <generator object iter_all at 0x0000022B029231F8>
    >>> f.nb_blocks # number of basic blocks
    33
    >>> f.blocks # list of blocks
    [<bip.base.block.BipBlock object at 0x0000022B04544D68>, ..., <bip.base.block.BipBlock object at 0x0000022B04552240>]
    >>> f.blocks[5] # access the basic block 5, could be done with BipBlock(addr)
    BipBlock: 0x1800D306E (from Func: test (0x1800D2FF0))
    >>> f.blocks[5].func # link back to the function
    Func: test (0x1800D2FF0)
    >>> f.blocks[5].instr # list of instructions in the block
    [<bip.base.instr.BipInstr object at 0x0000022B04544710>, ..., <bip.base.instr.BipInstr object at 0x0000022B0291DB00>]
    >>> f.blocks[5].pred # predecessor blocks, blocks where control flow lead to this one
    [<bip.base.block.BipBlock object at 0x0000022B04544D68>]
    >>> f.blocks[5].succ # successor blocks
    [<bip.base.block.BipBlock object at 0x0000022B04544710>, <bip.base.block.BipBlock object at 0x0000022B04544438>]
    >>> f.blocks[5].is_ret # is this block containing a return
    False

Data
~~~~

The class ``bip.base.BipData``:

.. code-block:: pycon
Télécharger l’outil