CARVIEW |
Select Language
HTTP/2 200
date: Sun, 27 Jul 2025 08:57:16 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"c44f8b74822e2655872a6eeaf2524140"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=FZMBH1EM%2Fp6Qys1ghWgpP1NhTHz2aJpQmUY7NemJEXQftt8GR27UTVzKiPdCrxW8jMZC%2B6InsafH%2BBkFhLyXuxo2JWA0zuxOHv1YTtyQ8eo7aQz751I8x%2FpPFr1Ic2tRqSDf4QXfTLTeBECNBbTBBNUGqw9mfB1rvyly%2Bc7Xz3oj10OLaVDyiDdy2dKLd2xMkc0Z1v7crx%2B9hpMHnWqtSUl9itNlNQnN6ijttQEmZjxQCDM1CiR9jUHQYdIKmo9MDd9rCH6FkuStAdE2%2FphMNA%3D%3D--vuidJnCy8sPJNUmF--1IZTIjEBQbD5jqT2PbEc0Q%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.875440929.1753606636; Path=/; Domain=github.com; Expires=Mon, 27 Jul 2026 08:57:16 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Mon, 27 Jul 2026 08:57:16 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: BDDA:2F5ED7:C7D794:10902AB:6885E9EC
GitHub - gdbinit/ExtractMachO: IDA plugin to extract Mach-O binaries located in the disassembly or data
Skip to content
Navigation Menu
{{ message }}
-
Notifications
You must be signed in to change notification settings - Fork 15
gdbinit/ExtractMachO
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
___________ __ __ \_ _____/__ ____/ |_____________ _____/ |_ | __)_\ \/ /\ __\_ __ \__ \ _/ ___\ __\ | \> < | | | | \// __ \\ \___| | /_______ /__/\_ \ |__| |__| (____ /\___ >__| \/ \/ \/ \/ _____ .__ ________ / \ _____ ____ | |__ \_____ \ / \ / \\__ \ _/ ___\| | \ ______ / | \ / Y \/ __ \\ \___| Y \ /_____/ / | \ \____|__ (____ /\___ >___| / \_______ / \/ \/ \/ \/ \/ v1.1 (c) 2012, fG! - reverser@put.as - https://reverse.put.as This is a very simple IDA plugin to extract all Mach-O binaries contained anywhere in the disassembly. It supports 32 and 64bits binaries, and also fat binaries, Intel, PPC and ARM! The default behavior is to search all the IDA database for Mach-O binaries. If you position the cursor at a Mach-O binary start address (Mach-O magic values 0xFEEDFACE or 0xFEEDFACF), it will ask if you want to dump that specific binary. If you say no, it will fallback to default behavior. Tested with IDA 6.3 Mac OS X version. To compile for OS X use the Makefile or the XCode Project. The Makefile is easier to use since you just need to set the __EA64__ environment variable if you want to compile to IDA 64bits version. You will need to edit the Makefile or the XCode project and set the paths to the SDK. Refer to https://reverse.put.as/2011/10/31/how-to-create-ida-cc-plugins-with-xcode/ for XCode. Set the environment variable __EA64__ if you want the plugin for IDA 64bits. For Windows, DEVC++ project file is included for IDA 32 and 64 bits versions. You will need to edit the DEVC++ project and set the paths to the SDK and plugin binary output. Please refer to https://www.binarypool.com/idapluginwriting/ for more information. You should do a Rebuild All in DEVC++ (especially if you switch from 32 to 64 project or vice-versa). No default shortcut is set. Edit IDAP_hotkey at extractmacho.cpp to your own preference if you wish so. Bug reports, fixes and patches are welcome: reverser@put.as or github.com/gdbinit/extractmacho IDA BUGS: Another bug is related to the PLUGIN_UNL flag. It is used to "Unload the plugin immediately after calling 'run'.". If this option is set, it crashes the Windows version. Mac version seems do to fine with it. That's it! Enjoy :-) fG! v0.1 - Initial version that supports 32 and 64bits isolated binaries. v0.2 - Support for fat binaries and ability to search all IDA database for binaries to be extracted. Now it's able to extract 32bit kernel extensions, which use MH_OBJECT file format. v1.0 - Add report capabilities. Cleanups and small fixes. v1.1 - Add PPC and ARM extraction support!
About
IDA plugin to extract Mach-O binaries located in the disassembly or data
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published
You can’t perform that action at this time.