Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
bip — API Python orientada a objetos para simplificar a interação com o IDA para engenharia reversa, permitindo o desenvolvimento de plugins e a automação de análises de desmontagem. | Kitploit
Ferramentas/GitHubGitHub/synacktiv/bip
Análise EstáticaAnálise de CódigoEngenharia ReversaScripting e AutomaçãoAnálise de Binários
GitHubsynacktiv/bip

bip

API Python orientada a objetos para simplificar a interação com o IDA para engenharia reversa, permitindo o desenvolvimento de plugins e a automação de análises de desmontagem.

Ver Repositório
2051913há 4 anosRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

Bip

O Bip é um projeto que visa simplificar o uso do Python para interagir com o IDA. Seus principais objetivos são facilitar o uso do Python no console interativo do IDA e a escrita de plugins. De uma forma mais geral, o objetivo é automatizar tarefas recorrentes feitas por meio da API do Python. O Bip também é desenvolvido para fornecer uma API mais orientada a objetos, "estilo Python" e uma documentação real.

Este código não está completo e muitos recursos ainda estão faltando. O desenvolvimento é priorizado com base no que as pessoas pedem e no que os desenvolvedores usam, portanto, não hesite em enviar PRs, Feature Requests e Issues (inclusive sobre a documentação).

A documentação está disponível no formato RST (e pode ser compilada usando sphinx) no diretório docs/; ela também está disponível online <https://synacktiv.github.io/bip/build/html/index.html>_.

  • Versão atual do IDA: IDA 7.5SP1 e Python 2.7 ou 3.8
  • Última versão do Bip: 1.0

Instalação

Esta instalação foi testada apenas no Windows e no Linux: python install.py.

É possível usar um argumento opcional --dest para instalar em uma pasta específica:

.. code-block:: none

usage: install.py [-h] [--dest DEST]

optional arguments:
  -h, --help   show this help message and exit
  --dest DEST  Destination folder where to install Bip

Este instalador não instala nenhum plugin por padrão, mas apenas o núcleo do Bip. Por padrão, a pasta de destino é aquela usada localmente pelo IDA (%APPDATA%\Hex-Rays\IDA Pro\ para Windows e $HOME/.idapro para Linux e MacOSX).

Visão Geral

Esta visão geral tem como objetivo mostrar como as operações mais comuns podem ser feitas; está longe de ser completa. Todas as funções e objetos do Bip são documentados usando doc string; portanto, basta usar help(BipClass) e help(obj.bipmethod) para obter a documentação no seu shell.

Base

O módulo bip.base contém a maioria dos recursos básicos para interagir com o IDA. Na prática, esta é principalmente a parte do desmontador do IDA, o que inclui: manipulação de instruções, funções, blocos básicos, operandos, dados, xrefs, estruturas, tipos, ...

Instruções / Operandos~~~~~~~~~~~~~~~~~~~~~~~

The classes bip.base.BipInstr and bip.base.BipOperand:

.. code-block:: pycon

>>> from bip.base import *
>>> i = BipInstr() # BipInstr is the base class for representing an instruction
>>> i # by default the address on the screen is taken
BipInstr: 0x1800D324B (mov     rcx, r13)
>>> i2 = BipInstr(0x01800D3242) # pass the address in argument
>>> i2
BipInstr: 0x1800D3242 (mov     r8d, 8)
>>> i2.next # access next instruction, previous with i2.prev
BipInstr: 0x1800D3248 (mov     rdx, r14)
>>> l = [i3 for i3 in BipInstr.iter_all()] # l contains the list of all BipInstruction of the database, iter_all produces a generator object
>>> i.ea # access the address
6443315787
>>> i.mnem # mnemonic representation
mov
>>> i.ops # access to the operands
[<bip.base.operand.BipOperand object at 0x0000022B0291DA90>, <bip.base.operand.BipOperand object at 0x0000022B0291DA58>]
>>> i.ops[0].str # string representation of an operand
rcx
>>> i.bytes # bytes in the instruction
[73L, 139L, 205L]
>>> i.size # number of bytes of this instruction
3
>>> i.comment = "hello" # set a comment, rcomment for the repeatable comments
>>> i
BipInstr: 0x1800D324B (mov     rcx, r13; hello)
>>> i.comment # get a comment
hello
>>> i.func # access to the function
Func: RtlQueryProcessLockInformation (0x1800D2FF0)
>>> i.block # access to basic block
BipBlock: 0x1800D3242 (from Func: RtlQueryProcessLockInformation (0x1800D2FF0))

Function / Basic block


The classes ``bip.base.BipFunction`` and ``bip.base.BipBlock``:

.. code-block:: pycon

    >>> from bip.base import *
    >>> f = BipFunction() # Get the function, screen address used if not provided
    >>> f
    Func: RtlQueryProcessLockInformation (0x1800D2FF0)
    >>> f2 = BipFunction(0x0018010E975) # provide an address, not necessary the first one
    >>> f2
    Func: sub_18010E968 (0x18010E968)
    >>> f == f2 # compare two functions
    False
    >>> f == BipFunction(0x001800D3021)
    True
    >>> hex(f.ea) # start address
    0x1800d2ff0L
    >>> hex(f.end) # end address
    0x1800d3284L
    >>> f = BipFunction.get_by_name("RtlQueryProcessLockInformation") # fetch the function from its name
    >>> f.name # get and set the name
    RtlQueryProcessLockInformation
    >>> f.name = "test"
    >>> f.name
    test
    >>> f.size # number of bytes in the function
    660
    >>> f.bytes # bytes of the function
    [72L, ..., 255L]
    >>> f.callees # list of functions called by this function
    [<bip.base.func.BipFunction object at 0x0000022B0291DD30>, ..., <bip.base.func.BipFunction object at 0x0000022B045487F0>]
    >>> f.callers # list of functions which call this function
    [<bip.base.func.BipFunction object at 0x0000022B04544048>]
    >>> f.instr # list of instructions in the function
    [<bip.base.instr.BipInstr object at 0x0000022B0291DB00>, ..., <bip.base.instr.BipInstr object at 0x0000022B0454D080>]
    >>> f.comment = "welcome to bip" # comment of the function, rcomment for repeatable ones
    >>> f.comment
    welcome to bip
    >>> f.does_return # does this function return ?
    True
    >>> BipFunction.iter_all() # allows to iter on all functions defined in the database
    <generator object iter_all at 0x0000022B029231F8>
    >>> f.nb_blocks # number of basic blocks
    33
    >>> f.blocks # list of blocks
    [<bip.base.block.BipBlock object at 0x0000022B04544D68>, ..., <bip.base.block.BipBlock object at 0x0000022B04552240>]
    >>> f.blocks[5] # access the basic block 5, could be done with BipBlock(addr)
    BipBlock: 0x1800D306E (from Func: test (0x1800D2FF0))
    >>> f.blocks[5].func # link back to the function
    Func: test (0x1800D2FF0)
    >>> f.blocks[5].instr # list of instructions in the block
    [<bip.base.instr.BipInstr object at 0x0000022B04544710>, ..., <bip.base.instr.BipInstr object at 0x0000022B0291DB00>]
    >>> f.blocks[5].pred # predecessor blocks, blocks where control flow lead to this one
    [<bip.base.block.BipBlock object at 0x0000022B04544D68>]
    >>> f.blocks[5].succ # successor blocks
    [<bip.base.block.BipBlock object at 0x0000022B04544710>, <bip.base.block.BipBlock object at 0x0000022B04544438>]
    >>> f.blocks[5].is_ret # is this block containing a return
    False

Data
~~~~

The class ``bip.base.BipData``:

.. code-block:: pycon
Baixar ferramenta