diff options
| author | Camille Mougey <camille.mougey@cea.fr> | 2015-01-22 17:59:11 +0100 |
|---|---|---|
| committer | Camille Mougey <camille.mougey@cea.fr> | 2015-01-23 17:24:43 +0100 |
| commit | 8b9047402913c46a545aadeea10fce1011ddd6bd (patch) | |
| tree | ef3f66c76e5f46096b0d26d92e08b3fe3b856629 /example/asm/box_x86_32.py | |
| parent | 9bec8ef1242d03a791014d71eaf896fc11def3fa (diff) | |
| download | focaccia-miasm-8b9047402913c46a545aadeea10fce1011ddd6bd.tar.gz focaccia-miasm-8b9047402913c46a545aadeea10fce1011ddd6bd.zip | |
Example/ASM: Avoid duplicating code by using a common script shellcode.py
Diffstat (limited to 'example/asm/box_x86_32.py')
| -rw-r--r-- | example/asm/box_x86_32.py | 61 |
1 files changed, 0 insertions, 61 deletions
diff --git a/example/asm/box_x86_32.py b/example/asm/box_x86_32.py deleted file mode 100644 index def7af99..00000000 --- a/example/asm/box_x86_32.py +++ /dev/null @@ -1,61 +0,0 @@ -#! /usr/bin/env python -from argparse import ArgumentParser -from pdb import pm - -from elfesteem import pe_init - -from miasm2.core.cpu import parse_ast -from miasm2.arch.x86.arch import mn_x86, base_expr -from miasm2.core import parse_asm -import miasm2.expression.expression as m2_expr -from miasm2.core import asmbloc - -parser = ArgumentParser("x86 32bits assembler") -parser.add_argument("source", help="Source to assemble") -args = parser.parse_args() - -pe = pe_init.PE() -s_text = pe.SHList.add_section(name="text", addr=0x1000, rawsize=0x1000) -s_iat = pe.SHList.add_section(name="iat", rawsize=0x100) -new_dll = [({"name": "USER32.dll", - "firstthunk": s_iat.addr}, ["MessageBoxA"])] -pe.DirImport.add_dlldesc(new_dll) -s_myimp = pe.SHList.add_section(name="myimp", rawsize=len(pe.DirImport)) -pe.DirImport.set_rva(s_myimp.addr) - -reg_and_id = dict(mn_x86.regs.all_regs_ids_byname) - - -def my_ast_int2expr(a): - return m2_expr.ExprInt32(a) - - -def my_ast_id2expr(t): - return reg_and_id.get(t, m2_expr.ExprId(t, size=32)) - -my_var_parser = parse_ast(my_ast_id2expr, my_ast_int2expr) -base_expr.setParseAction(my_var_parser) - -with open(args.source) as fstream: - source = fstream.read() - -blocs, symbol_pool = parse_asm.parse_txt(mn_x86, 32, source) - -# fix shellcode addr -symbol_pool.set_offset(symbol_pool.getby_name("main"), pe.rva2virt(s_text.addr)) -symbol_pool.set_offset(symbol_pool.getby_name_create("MessageBoxA"), - pe.DirImport.get_funcvirt('MessageBoxA')) -pe.Opthdr.AddressOfEntryPoint = s_text.addr - -for bloc in blocs[0]: - print bloc - -resolved_b, patches = asmbloc.asm_resolve_final( - mn_x86, blocs[0], symbol_pool) -print patches - -for offset, raw in patches.items(): - pe.virt[offset] = raw - -output = args.source.replace(".S", ".bin") -open(output, 'wb').write(str(pe)) |