Reverse Engineering & Binary Analysis Basics · บทเรียน

ลายเซ็น FLIRT และการระบุฟังก์ชันไลบรารี

ระบุโค้ดไลบรารีที่เชื่อมแบบสแตติกโดยอัตโนมัติ เพื่อให้สคริปต์ของคุณมุ่งเน้นเฉพาะตรรกะจริงของแอปพลิเคชัน

บทเรียน 4 จาก 413 ขั้นตอน

ลายเซ็น FLIRT และการระบุฟังก์ชันไลบรารี เป็นบทเรียน Reverse Engineering & Binary Analysis Basics ฟรีบน CoddyKit นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Reverse Engineering & Binary Analysis Basics และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Reverse Engineering & Binary Analysis Basics มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

The Library Noise Problem

You can script disassemblers, automate structure recovery, and patch binaries. But statically-linked programs bundle thousands of library functions (libc, the C++ STL, runtime).

Wading through them by hand wastes enormous time.

Static Linking Inlines Libraries

When a binary is statically linked, library code is copied directly into the executable. There are no import names; printf just looks like another anonymous function.

Identifying these frees you to focus on the author's own code.

What Are FLIRT Signatures?

FLIRT (Fast Library Identification and Recognition Technology) is IDA's system for matching byte patterns of known library functions and auto-naming them.

Ghidra has an equivalent via Function ID databases.

How Pattern Matching Works

A signature records a function's opcode bytes, masking out parts that vary (like relocated addresses).

The tool scans the binary; when bytes match a signature, it applies the known name and prototype.

; masked pattern (.. = varies)
55 8B EC 83 EC .. 56 57

Applying Signatures in IDA

IDA ships .sig files for common runtimes. You apply them from File, Load file, FLIRT signature file, then IDA renames matched functions.

Suddenly hundreds of sub_xxxx become recognizable like strcpy and malloc.

Building Your Own Signatures

For uncommon or custom static libraries, generate signatures with IDA's FLAIR tools: parse the .a archive into a pattern file, then compile it to a .sig.

pcf libcustom.a libcustom.pat
sigmake libcustom.pat libcustom.sig

Ghidra Function ID

Ghidra's Function ID plugin hashes function bodies and stores them in a database. Importing a database for a known runtime auto-labels matches in your target.

You can build databases from libraries you have analyzed before.

Scripting Around Identified Functions

Once libraries are named, your scripts can skip them. Iterate functions and ignore any tagged as library code, analyzing only user functions.

for f in idautils.Functions():
    flags = idc.get_func_flags(f)
    if flags & idc.FUNC_LIB:
        continue  # skip recognized library
    analyze_user_function(f)

Limits and False Matches

Signatures depend on the exact compiler and version. A different optimization level can prevent a match, and short functions may match the wrong library.

Always sanity-check auto-named functions before trusting them.

Pairing with Other Techniques

Combine signatures with string and xref analysis. A function FLIRT names printf should have format-string xrefs nearby; if not, the match may be wrong.

Cross-validation builds confidence.

Applying Prototypes

Identifying a library function also imports its prototype. Once memcpy(dst, src, n) is recognized, the decompiler labels its three arguments correctly.

This propagates type information into callers, sharply improving pseudocode readability.

; before: sub_401200(a, b, c)
; after:  memcpy(dst, src, len)

Quick Check

What is the main purpose of FLIRT signatures in static analysis?

Recap

You can now cut through library clutter:

  • Static linking hides libraries as anonymous functions
  • FLIRT (IDA) and Function ID (Ghidra) auto-name them by pattern
  • Build custom signatures with FLAIR for uncommon libs
  • Script to skip library code, but verify matches
เริ่มต้นได้ฟรี

เรียนรู้ Assembly ด้วย AI tutor — ฟรี

เขียนและเรียกใช้โค้ดจริงในเบราว์เซอร์ของคุณ รับความช่วยเหลือทันทีจาก AI tutor 24/7 และเรียนรู้ต่อจากที่คุณหยุดบนเว็บหรือในแอป

คอร์ส
12
บทเรียน
48

คำถามที่พบบ่อย

บทเรียน “ลายเซ็น FLIRT และการระบุฟังก์ชันไลบรารี” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “ลายเซ็น FLIRT และการระบุฟังก์ชันไลบรารี” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Reverse Engineering & Binary Analysis Basics ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Reverse Engineering & Binary Analysis Basics มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “ลายเซ็น FLIRT และการระบุฟังก์ชันไลบรารี”

ระบุโค้ดไลบรารีที่เชื่อมแบบสแตติกโดยอัตโนมัติ เพื่อให้สคริปต์ของคุณมุ่งเน้นเฉพาะตรรกะจริงของแอปพลิเคชัน คุณปฏิบัติ Reverse Engineering & Binary Analysis Basics ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Reverse Engineering & Binary Analysis Basics หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Reverse Engineering & Binary Analysis Basics บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน

บทเรียน “ลายเซ็น FLIRT และการระบุฟังก์ชันไลบรารี” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Reverse Engineering & Binary Analysis Basics นี้ได้ไหม

ได้ บทเรียน Reverse Engineering & Binary Analysis Basics ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. การเขียนสคริปต์ IDAPython และ Ghidra
  2. การกู้คืนโครงสร้างข้อมูลโดยอัตโนมัติ
  3. เทคนิคการแพตช์ไบนารี
  4. ลายเซ็น FLIRT และการระบุฟังก์ชันไลบรารี
← กลับไปที่ Reverse Engineering & Binary Analysis Basics