Skip to content

Conversation

@BeyondTheG4te
Copy link
Contributor

This PR introduces the following changes:

  • Entrypoint detection for Mach-O / FAT binaries
  • Different handling of reference symbols for Mach-O binaries, that are used by checkers. OSX Mach-O ABI enforces mangling (leading underscore) even for C symbols (e.g malloc -> _malloc).

The changes have been implemented/tested on MacOS 14.6 (Sonoma) / ARM - M2 and Ghidra 11.1.2.

If its needed I can also add arm64 / Mach-O binaries to https://github.com/KeenSecurityLab/BinAbsInspector-binaries and add the respective integration tests.

@BeyondTheG4te BeyondTheG4te marked this pull request as draft September 5, 2024 13:38
@BeyondTheG4te BeyondTheG4te marked this pull request as ready for review September 5, 2024 13:54
@BeyondTheG4te BeyondTheG4te changed the title Add mach o support Add MachO support Sep 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant