符号表恢复

符号表恢复

flair

1
2
3
4
5
pelf.exe ./libgmp.a ./a.pat
skipped 1, total 510
sigmake.exe ./a.pat b.sig
b.sig: modules/leaves: 462/509, COLLISIONS: 3
See the documentation to learn how to resolve collisions.

rizzo

安装rizzo插件

1
2
3
arm架构的libc在 /usr/arm-linux-gnueabihf/lib里面
file-->Produce file-->Rizzo signature file使用rizzo
file-->Load file-->Rizzo signature file加载符号