| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
Contributed By Check Point Software Technologies LTD.
It can be useful in the following cases:
We support the following list of debug backends for now:
Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debug backend, with complex memory dumping and interactive Python scripting capabilities. It consists of two parts: IDA plugin and debug backend's plugin.
Labeless significantly reduces time that researcher spends on transferring already reversed/documented code information from IDA (static) to debugger (dynamic). It saves time, preventing from doing the same job twice. Also, you can document and add data to the IDB on the fly and your changes will be automatically propagated to debug backend, even if you will restart the virtual machine or instance of debug backend will crash. So, you will never lose your research.
This solution is highly upgradable. You can implement any helper scripts in Python on debug backend's side and then just call them from IDA with one line of code, parsing the results and automatically propagating changes to IDB.
We can take that memory region and put it in the IDB, fixing imports 'on-the-fly', using debug backend's functionality. No more need in ImpRec or BinScylla, searching for the regions in memory that contain the real IAT, because we get that information dynamically from the debugged process itself.
As a result we have a lot of memory regions that may represent even different modules (if the unpacking process if multistage) with valid references between them, which gives us a possibility to build a full control flow graph of the executable. Basically, we will end up with one big IDB, containing all the info on the specific case.
If you want to use both x86 and x86_64 targets, then you should do the following steps for each python distro.
Sidenote: I'm trying to keep it as fresh as possible, but it takes my time to maintain. In case you want to use your version of python other than Python 3.10, you might copy your Python X's includes and libs to corresponding folder in 3rdparty\Python310\ / 3rdparty\Python310x64\ (take a look at existing files to understand how to update) and re-build all needed plugins.
cd labeless_release_full_1.1.7.0\deploy
c:\Python310\python.exe -m pip install .\protobuf-3.20.3-py2.py3-none-any.whl
c:\Python310\python.exe -m pip install .\labeless-1.1.7.0-py2.py3-none-any.whlNote: If you have already used Labeless before and you want to update it, don't forget to reinstall python module each time you have new release
Labeless supports Windows, Linux and MacOS Arm64 IDA PRO. Labeless handles only PE/AMD64 binaries. Labeless requires IDAPython plugin idapython3.{dll,so,dylib} (it ships with IDA PRO, but make sure it works well).
There are plugins:
IDA[XX]\plugins\labeless_ida_xx.{dll,so} - for IDA for Windows, 32-bit targets
IDA[XX]\plugins\labeless_ida_xx_64.{dll,so,dylib} - for IDA for Windows (dll), Linux (so) and MacOS (dylib), 64-bit targets, starting from IDA 9 this will be the only needed to handle both 32 and 64 bit targets
Copy Labeless plugins to your IDA's plugins directory, for example c:\IDA90rc1\plugins
You may find prepared debugger in the following directory OllyDbg110. (Note!: Don't forget to set up debugger's plugins directory).
Copy DeFixed110\plugins\labeless_olly_foff.dll to DeFixed plugins directory (Note!: Don't forget to set up debugger's plugins directory)
You may find prepared debugger in the following directory OllyDbg201. (Note!: Don't forget to set up debugger's plugins directory).
You may find prepared debugger in the following directory x64dbg.
Also, you may see the firewall alert
If you want to access the debug backend from another computer, you should allow the backend to listen by this dialog or manually.
Repeatable - are comments, which IDA shows in any referenced place.
If you enabled 'Enable labels & comments sync' option, then Labeless will automatically synchronize all the data on any rename operation in IDA
Q: Labeless for x64dbg x32 is works, but x64 doesn't. Why?
A: Please, recheck that you have installed protobuf and 'labeless' module for Python x64
| Back | FazBrowse Home | New Git URL |