吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn




查看: 6233|回复: 3

[IDA Plugin] Virtuailor - IDAPython tool for C++ vtables reconstruction

m4n0w4r 发表于 2019-2-2 21:10
Virtuailor is an IDAPython tool that reconstructs vtables for C++ code written for intel architecture and both 32bit and 64bit code. The tool constructed from 2 parts, static and dynamic.
The first is the static part, contains the following capabilities:
  • Detects indirect calls.
  • Hooks the value assignment of the indirect calls using conditional breakpoints (the hook code).

The second is the dynamic part, contains the following capabilities:
  • Creates vtable structures.
  • Rename functions and vtables addresses.
  • Add structure offset to the assembly indirect calls.
  • Add xref from indirect calls to their virtual functions(multiple xrefs).

Output and General Functions
vtables structures
The structures Virtuailor creates from the vtable used in virtual call that were hit. The vtable functions are extracted from the memory based on the relevant register that was used in the BP opcode.

More info :


871.83 KB, 下载次数: 54, 下载积分: 吾爱币 -1 CB


参与人数 3吾爱币 +7 热心值 +3 收起 理由
dNp + 1 + 1 谢谢@Thanks!
Hmily + 5 + 1 鼓励转贴优秀软件安全工具和文档!
丿风雪舞神々 + 1 + 1 我很赞同!



chenjingyes 发表于 2019-2-2 23:39
牛逼  还原虚表的工具
dNp 发表于 2019-2-4 09:12
聪本 发表于 2020-12-24 10:00
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-5-15 09:55

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表