Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
bip — API Python orientata agli oggetti per semplificare l'interazione con IDA per il reverse engineering, consentendo lo sviluppo di plugin e l'automazione delle analisi di disassemblaggio. | Kitploit
Strumenti/GitHubGitHub/synacktiv/bip
Analisi StaticaAnalisi del CodiceReverse EngineeringScripting e AutomazioneAnalisi di Binari
GitHubsynacktiv/bip

bip

API Python orientata agli oggetti per semplificare l'interazione con IDA per il reverse engineering, consentendo lo sviluppo di plugin e l'automazione delle analisi di disassemblaggio.

Vedi Repository
20519134 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Bip

Bip è un progetto che mira a semplificare l'uso di Python per interagire con IDA. I suoi obiettivi principali sono facilitare l'uso di Python nella console interattiva di IDA e la scrittura di plugin. In modo più generale l'obiettivo è automatizzare i compiti ricorrenti svolti tramite l'API Python. Bip è sviluppato anche per fornire un'API più orientata agli oggetti, una "python-like" API e una documentazione reale.

Questo codice non è completo e mancano ancora molte funzionalità. Lo sviluppo è prioritizzato in base a ciò che le persone richiedono e a ciò che gli sviluppatori usano, quindi non esitate a creare PR, Richieste di Funzionalità e Issue (anche per la documentazione).

La documentazione è disponibile in formato RST (e può essere compilata usando sphinx) nella directory docs/; è anche disponibile online <https://synacktiv.github.io/bip/build/html/index.html>_.

  • Versione IDA attuale: IDA 7.5SP1 e Python 2.7 o 3.8
  • Ultima versione di Bip: 1.0

Installazione

Questa installazione è stata testata solo su Windows e Linux: python install.py.

È possibile usare un argomento opzionale --dest per installare in una cartella specifica:

.. code-block:: none

usage: install.py [-h] [--dest DEST]

optional arguments:
  -h, --help   show this help message and exit
  --dest DEST  Destination folder where to install Bip

Questo installer non installa alcun plugin di default, ma semplicemente il nucleo di Bip. Di default la cartella di destinazione è quella usata localmente da IDA (%APPDATA%\Hex-Rays\IDA Pro\ per Windows e $HOME/.idapro per Linux e MacOSX).

Panoramica

Questa panoramica ha lo scopo di mostrare come possono essere eseguite le operazioni più comuni, è lungi dall'essere completa. Tutte le funzioni e gli oggetti in Bip sono documentati usando docstring, quindi basta usare help(BipClass) e help(obj.bipmethod) per ottenere la documentazione nella propria shell.

Base

Il modulo bip.base contiene la maggior parte delle funzionalità base per interfacciarsi con IDA. In pratica si tratta principalmente della parte disassembler di IDA; questo include: manipolazione di istruzioni, funzioni, blocchi di base, operandi, dati, xref, strutture, tipi, ...

Istruzioni / Operandi~~~~~~~~~~~~~~~~~~~~~~~

The classes bip.base.BipInstr and bip.base.BipOperand:

.. code-block:: pycon

>>> from bip.base import *
>>> i = BipInstr() # BipInstr is the base class for representing an instruction
>>> i # by default the address on the screen is taken
BipInstr: 0x1800D324B (mov     rcx, r13)
>>> i2 = BipInstr(0x01800D3242) # pass the address in argument
>>> i2
BipInstr: 0x1800D3242 (mov     r8d, 8)
>>> i2.next # access next instruction, previous with i2.prev
BipInstr: 0x1800D3248 (mov     rdx, r14)
>>> l = [i3 for i3 in BipInstr.iter_all()] # l contains the list of all BipInstruction of the database, iter_all produces a generator object
>>> i.ea # access the address
6443315787
>>> i.mnem # mnemonic representation
mov
>>> i.ops # access to the operands
[<bip.base.operand.BipOperand object at 0x0000022B0291DA90>, <bip.base.operand.BipOperand object at 0x0000022B0291DA58>]
>>> i.ops[0].str # string representation of an operand
rcx
>>> i.bytes # bytes in the instruction
[73L, 139L, 205L]
>>> i.size # number of bytes of this instruction
3
>>> i.comment = "hello" # set a comment, rcomment for the repeatable comments
>>> i
BipInstr: 0x1800D324B (mov     rcx, r13; hello)
>>> i.comment # get a comment
hello
>>> i.func # access to the function
Func: RtlQueryProcessLockInformation (0x1800D2FF0)
>>> i.block # access to basic block
BipBlock: 0x1800D3242 (from Func: RtlQueryProcessLockInformation (0x1800D2FF0))

Function / Basic block


The classes ``bip.base.BipFunction`` and ``bip.base.BipBlock``:

.. code-block:: pycon

    >>> from bip.base import *
    >>> f = BipFunction() # Get the function, screen address used if not provided
    >>> f
    Func: RtlQueryProcessLockInformation (0x1800D2FF0)
    >>> f2 = BipFunction(0x0018010E975) # provide an address, not necessary the first one
    >>> f2
    Func: sub_18010E968 (0x18010E968)
    >>> f == f2 # compare two functions
    False
    >>> f == BipFunction(0x001800D3021)
    True
    >>> hex(f.ea) # start address
    0x1800d2ff0L
    >>> hex(f.end) # end address
    0x1800d3284L
    >>> f = BipFunction.get_by_name("RtlQueryProcessLockInformation") # fetch the function from its name
    >>> f.name # get and set the name
    RtlQueryProcessLockInformation
    >>> f.name = "test"
    >>> f.name
    test
    >>> f.size # number of bytes in the function
    660
    >>> f.bytes # bytes of the function
    [72L, ..., 255L]
    >>> f.callees # list of functions called by this function
    [<bip.base.func.BipFunction object at 0x0000022B0291DD30>, ..., <bip.base.func.BipFunction object at 0x0000022B045487F0>]
    >>> f.callers # list of functions which call this function
    [<bip.base.func.BipFunction object at 0x0000022B04544048>]
    >>> f.instr # list of instructions in the function
    [<bip.base.instr.BipInstr object at 0x0000022B0291DB00>, ..., <bip.base.instr.BipInstr object at 0x0000022B0454D080>]
    >>> f.comment = "welcome to bip" # comment of the function, rcomment for repeatable ones
    >>> f.comment
    welcome to bip
    >>> f.does_return # does this function return ?
    True
    >>> BipFunction.iter_all() # allows to iter on all functions defined in the database
    <generator object iter_all at 0x0000022B029231F8>
    >>> f.nb_blocks # number of basic blocks
    33
    >>> f.blocks # list of blocks
    [<bip.base.block.BipBlock object at 0x0000022B04544D68>, ..., <bip.base.block.BipBlock object at 0x0000022B04552240>]
    >>> f.blocks[5] # access the basic block 5, could be done with BipBlock(addr)
    BipBlock: 0x1800D306E (from Func: test (0x1800D2FF0))
    >>> f.blocks[5].func # link back to the function
    Func: test (0x1800D2FF0)
    >>> f.blocks[5].instr # list of instructions in the block
    [<bip.base.instr.BipInstr object at 0x0000022B04544710>, ..., <bip.base.instr.BipInstr object at 0x0000022B0291DB00>]
    >>> f.blocks[5].pred # predecessor blocks, blocks where control flow lead to this one
    [<bip.base.block.BipBlock object at 0x0000022B04544D68>]
    >>> f.blocks[5].succ # successor blocks
    [<bip.base.block.BipBlock object at 0x0000022B04544710>, <bip.base.block.BipBlock object at 0x0000022B04544438>]
    >>> f.blocks[5].is_ret # is this block containing a return
    False

Data
~~~~

The class ``bip.base.BipData``:

.. code-block:: pycon
Scarica lo strumento