Sirmabus
January 22nd, 2009, 05:13
Something I've been playing around with after I tried Igorsk's scripts from his excellent article.
http://www.openrce.org/articles/full_view/23 ("http://www.openrce.org/articles/full_view/23")
------------------------------------------------------------
Scans an MSVC 32bit target IDB for vftables with C++ RTTI, and MFC RTCI type data.
Places structure defs, names, labels, and comments to make more sense of class vftables ("Virtual Function Table" and make them read
 and make them read
easier as an aid to reverse engineering.
Creates a list window with found vftables for browsing.
RTTI ("Run-Time Type Identification" :
:
http://en.wikipedia.org/wiki/RTTI
RTCI ("Run Time Class Information" the MFC forerunner to "RTTI":
 the MFC forerunner to "RTTI":
http://msdn.microsoft.com/en-us/library/fych0hw6(VS.80).aspx
------------------------------------------------------------
Example vftable output list:
http://img518.imageshack.us/img518/7774/listshot1zj0.jpg
Example vftable info set by plug-in:
http://img217.imageshack.us/img217/5951/vftabkeshot1ri2.jpg
P.S. Why are my links F'ed up?
http://www.openrce.org/articles/full_view/23 ("http://www.openrce.org/articles/full_view/23")
------------------------------------------------------------
Scans an MSVC 32bit target IDB for vftables with C++ RTTI, and MFC RTCI type data.
Places structure defs, names, labels, and comments to make more sense of class vftables ("Virtual Function Table"
 and make them read
 and make them readeasier as an aid to reverse engineering.
Creates a list window with found vftables for browsing.
RTTI ("Run-Time Type Identification"
 :
:http://en.wikipedia.org/wiki/RTTI
RTCI ("Run Time Class Information"
 the MFC forerunner to "RTTI":
 the MFC forerunner to "RTTI":http://msdn.microsoft.com/en-us/library/fych0hw6(VS.80).aspx
------------------------------------------------------------
Example vftable output list:
http://img518.imageshack.us/img518/7774/listshot1zj0.jpg
Example vftable info set by plug-in:
http://img217.imageshack.us/img217/5951/vftabkeshot1ri2.jpg
P.S. Why are my links F'ed up?

