吾爱破解 - 52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 6795|回复: 3
收起左侧

[IDA Plugin] Virtuailor - IDAPython tool for C++ vtables reconstruction

[复制链接]
m4n0w4r 发表于 2019-2-2 21:10
Virtuailor is an IDAPython tool that reconstructs vtables for C++ code written for intel architecture and both 32bit and 64bit code. The tool constructed from 2 parts, static and dynamic.
The first is the static part, contains the following capabilities:
  • Detects indirect calls.
  • Hooks the value assignment of the indirect calls using conditional breakpoints (the hook code).

The second is the dynamic part, contains the following capabilities:
  • Creates vtable structures.
  • Rename functions and vtables addresses.
  • Add structure offset to the assembly indirect calls.
  • Add xref from indirect calls to their virtual functions(multiple xrefs).




Output and General Functions
vtables structures
The structures Virtuailor creates from the vtable used in virtual call that were hit. The vtable functions are extracted from the memory based on the relevant register that was used in the BP opcode.






More info :
https://github.com/0xgalz/Virtuailor


Virtuailor-master.zip

871.83 KB, 下载次数: 54, 下载积分: 吾爱币 -1 CB

免费评分

参与人数 3吾爱币 +7 热心值 +3 收起 理由
dNp + 1 + 1 谢谢@Thanks!
Hmily + 5 + 1 鼓励转贴优秀软件安全工具和文档!
丿风雪舞神々 + 1 + 1 我很赞同!

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

chenjingyes 发表于 2019-2-2 23:39
牛逼  还原虚表的工具
dNp 发表于 2019-2-4 09:12
聪本 发表于 2020-12-24 10:00
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则

返回列表

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-11-17 00:34

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表