Reverse Engineering & Binary Analysis Basics · Aula

Assinaturas FLIRT e Identificação de Funções de Bibliotecas

Reconheça automaticamente código de bibliotecas vinculadas estaticamente para que seus scripts se concentrem apenas na lógica real do aplicativo.

Aula 4 de 413 etapas

Assinaturas FLIRT e Identificação de Funções de Bibliotecas é uma aula grátis de Reverse Engineering & Binary Analysis Basics no CoddyKit. Esta é a aula 4 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de Reverse Engineering & Binary Analysis Basics, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de Reverse Engineering & Binary Analysis Basics inclui 4 aulas no total.

Partes desta aula ainda não foram traduzidas e aparecem em inglês.

The Library Noise Problem

You can script disassemblers, automate structure recovery, and patch binaries. But statically-linked programs bundle thousands of library functions (libc, the C++ STL, runtime).

Wading through them by hand wastes enormous time.

Static Linking Inlines Libraries

When a binary is statically linked, library code is copied directly into the executable. There are no import names; printf just looks like another anonymous function.

Identifying these frees you to focus on the author's own code.

What Are FLIRT Signatures?

FLIRT (Fast Library Identification and Recognition Technology) is IDA's system for matching byte patterns of known library functions and auto-naming them.

Ghidra has an equivalent via Function ID databases.

How Pattern Matching Works

A signature records a function's opcode bytes, masking out parts that vary (like relocated addresses).

The tool scans the binary; when bytes match a signature, it applies the known name and prototype.

; masked pattern (.. = varies)
55 8B EC 83 EC .. 56 57

Applying Signatures in IDA

IDA ships .sig files for common runtimes. You apply them from File, Load file, FLIRT signature file, then IDA renames matched functions.

Suddenly hundreds of sub_xxxx become recognizable like strcpy and malloc.

Building Your Own Signatures

For uncommon or custom static libraries, generate signatures with IDA's FLAIR tools: parse the .a archive into a pattern file, then compile it to a .sig.

pcf libcustom.a libcustom.pat
sigmake libcustom.pat libcustom.sig

Ghidra Function ID

Ghidra's Function ID plugin hashes function bodies and stores them in a database. Importing a database for a known runtime auto-labels matches in your target.

You can build databases from libraries you have analyzed before.

Scripting Around Identified Functions

Once libraries are named, your scripts can skip them. Iterate functions and ignore any tagged as library code, analyzing only user functions.

for f in idautils.Functions():
    flags = idc.get_func_flags(f)
    if flags & idc.FUNC_LIB:
        continue  # skip recognized library
    analyze_user_function(f)

Limits and False Matches

Signatures depend on the exact compiler and version. A different optimization level can prevent a match, and short functions may match the wrong library.

Always sanity-check auto-named functions before trusting them.

Pairing with Other Techniques

Combine signatures with string and xref analysis. A function FLIRT names printf should have format-string xrefs nearby; if not, the match may be wrong.

Cross-validation builds confidence.

Applying Prototypes

Identifying a library function also imports its prototype. Once memcpy(dst, src, n) is recognized, the decompiler labels its three arguments correctly.

This propagates type information into callers, sharply improving pseudocode readability.

; before: sub_401200(a, b, c)
; after:  memcpy(dst, src, len)

Quick Check

What is the main purpose of FLIRT signatures in static analysis?

Recap

You can now cut through library clutter:

  • Static linking hides libraries as anonymous functions
  • FLIRT (IDA) and Function ID (Ghidra) auto-name them by pattern
  • Build custom signatures with FLAIR for uncommon libs
  • Script to skip library code, but verify matches
Grátis para começar

Aprenda Assembly com um tutor de IA — grátis

Escreva e execute código real no seu navegador, obtenha ajuda instantânea de um tutor de IA 24/7 e continue de onde parou na web ou no app.

Cursos
12
Aulas
48

Perguntas Frequentes

A aula “Assinaturas FLIRT e Identificação de Funções de Bibliotecas” é grátis?

Sim — o texto completo de “Assinaturas FLIRT e Identificação de Funções de Bibliotecas” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de Reverse Engineering & Binary Analysis Basics, atualize para CoddyKit PRO. O curso de Reverse Engineering & Binary Analysis Basics inclui 4 aulas no total.

O que vou aprender em “Assinaturas FLIRT e Identificação de Funções de Bibliotecas”?

Reconheça automaticamente código de bibliotecas vinculadas estaticamente para que seus scripts se concentrem apenas na lógica real do aplicativo. Você pratica Reverse Engineering & Binary Analysis Basics com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.

Preciso ter experiência prévia para começar Reverse Engineering & Binary Analysis Basics?

Nenhuma experiência prévia é necessária. Reverse Engineering & Binary Analysis Basics no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 4 de 4.

Quanto tempo leva a aula “Assinaturas FLIRT e Identificação de Funções de Bibliotecas”?

A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.

Posso escrever e executar código nesta aula de Reverse Engineering & Binary Analysis Basics?

Sim. Cada aula de Reverse Engineering & Binary Analysis Basics inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.

Todas as aulas deste curso

  1. Scripts com IDAPython e Ghidra
  2. Automação da Recuperação de Estruturas de Dados
  3. Técnicas de Aplicação de Patches em Binários
  4. Assinaturas FLIRT e Identificação de Funções de Bibliotecas
← Voltar para Reverse Engineering & Binary Analysis Basics