Vector35 / Vector35/binaryninja-api

Figure out which import libs import which functions, on MacOS and Linux

Open
#2,385 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Component: BinaryViewType Effort: Low Impact: Low
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

We know for PE files, for every imported DLL files, we know for sure which functions it imports. However, this is not the case on MacOS and Linux, that the executable file contains the imported libraries and imported functions, but there are no clear mappings between the two set. So we currently cannot find out their relationship in the best way.

However, it is still possible to figure out their links, e.g., using certain heuristics. We would better explore this possibility and see where we can get to.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no files, tests, or entry points. Start by examining how imported libraries and functions are currently represented for PE files, then investigate whether heuristics can map imports on macOS and Linux; done means documenting or implementing a reliable approach, if one is found.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp, linux, macos
Domain
operating-systems, reverse-engineering
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.