能否在PPC/MIPS架构ELF二进制中识别自定义内存/字符串复制函数?
Identifying Custom String/Memory Copy Functions in PPC/MIPS ELF Binaries
Absolutely—you can absolutely spot custom implementations of strcpy(), strncpy(), memcpy(), and memmove() in PPC/MIPS ELF binaries. This is a staple reverse engineering task, and the key is to focus on behavioral patterns paired with architecture-specific instruction signatures. Here’s how to break it down:
Core Behavioral Traits (Architecture-Agnostic)
First, remember that all these functions share a core purpose: moving data from a source address to a target address. The differences lie in how they handle termination or length:
strcpy()/strncpy(): Copy bytes until a null terminator (0x00) is hit (or until a fixed length forstrncpy()).memcpy(): Copy a fixed number of bytes, no null check.memmove(): Same asmemcpy(), but handles overlapping source/target regions by choosing forward or reverse copy order.
PPC-Specific Instruction Signatures
PPC uses a load/store architecture, so look for these common instruction sequences:
strcpy()-style functions:- Loop with
lbz(load byte zero-extended) to read from the source,stb(store byte) to write to the target. - Check for the null terminator with
cmpwi rX, 0followed by abeq(branch if equal) to exit the loop. - Increment source/target pointers with
addi rY, rY, 1each iteration.
- Loop with
memcpy()-style functions:- Uses a length parameter, often loaded into the count register with
mtctr, then loops withbdnz(branch decrement not zero). - Copies in larger chunks (words/doublewords) with
lwz/stworld/stdfor efficiency, then handles remaining bytes with byte loads/stores.
- Uses a length parameter, often loaded into the count register with
memmove():- Starts with a pointer comparison (e.g.,
cmpw rSource, rTarget) to check for overlap. - Branches to forward copy (same as
memcpy()) if source > target, or reverse copy (starting from the end of the buffer) if source < target.
- Starts with a pointer comparison (e.g.,
MIPS-Specific Instruction Signatures
MIPS also uses load/store, with slightly different instruction mnemonics:
strcpy()-style functions:- Loop with
lb t0, 0(a0)(load byte from source) andsb t0, 0(a1)(store byte to target). - Check for null with
beq t0, $zero, exit_loop, then increment pointers withaddiu a0, a0, 1andaddiu a1, a1, 1.
- Loop with
memcpy()-style functions:- Takes a length argument (usually in
a2), loops by decrementing the length and copying word-sized chunks withlw/sw(or byte chunks for small lengths). - You’ll see sequences like
bne t0, $zero, copy_loopwheret0tracks remaining bytes.
- Takes a length argument (usually in
memmove():- Compares source and target addresses with
subu t0, a0, a1;bgez t0, forward_copymeans "if source >= target, copy forward". - Reverse copy will start at the end of the buffers:
addiu a0, a0, t0(move source pointer to end),addiu a1, a1, t0(same for target), then copy backwards withlb/sband decrement pointers.
- Compares source and target addresses with
Tools to Simplify the Process
- Disassemblers: Use
objdump -d -m ppc your_binary.elforobjdump -d -m mips your_binary.elffor quick raw disassembly. For deeper analysis, IDA Pro or Ghidra are industry standards—they’ll auto-recognize standard library functions, leaving custom ones easier to spot. - Ghidra/IDA Function Analysis: Look for functions with 2-3 arguments (source, target, length) that have no complex logic beyond load/store and loop operations. Use cross-references to see how the function is called (e.g., does it get passed a string and buffer, or two buffers plus a length?).
- Dynamic Debugging: If you can run the binary (e.g., via QEMU for PPC/MIPS), set breakpoints on suspect functions and test with known inputs to confirm behavior.
Verification Tips
- Compare the function’s logic to standard library implementations: Compile a simple C program with
gcc -mppcorgcc -mmipsand disassemble it to see how the standardstrcpy()/memcpy()look—custom functions will often have minor variations (e.g., different loop ordering, no compiler optimizations). - Check for side effects: True copy functions won’t modify data outside the source/target buffers or call unrelated functions.
内容的提问来源于stack exchange,提问作者Gh0st
相关产品推荐
相关产品推荐

