diff options
| author | Ajax <commial@gmail.com> | 2017-04-05 15:52:48 +0200 |
|---|---|---|
| committer | Ajax <commial@gmail.com> | 2017-04-06 13:47:38 +0200 |
| commit | 53c7778ca9a8877dc56db55ade07afc8864e0270 (patch) | |
| tree | 568ee59584541786b352f1b4c0896dfa7ac7ddbb /miasm2/analysis/sandbox.py | |
| parent | f0891c67b3860de0ffc716994dfc582aa5f0dea8 (diff) | |
| download | miasm-53c7778ca9a8877dc56db55ade07afc8864e0270.tar.gz miasm-53c7778ca9a8877dc56db55ade07afc8864e0270.zip | |
Add command-line and enviornment-vars argument in Sandbox
Note: lot of code is duplicated here, but due to Sandbox class hierarchy, merging them is not trivial (for now)
Diffstat (limited to 'miasm2/analysis/sandbox.py')
| -rw-r--r-- | miasm2/analysis/sandbox.py | 159 |
1 files changed, 146 insertions, 13 deletions
diff --git a/miasm2/analysis/sandbox.py b/miasm2/analysis/sandbox.py index 87e84caf..2b093338 100644 --- a/miasm2/analysis/sandbox.py +++ b/miasm2/analysis/sandbox.py @@ -248,6 +248,8 @@ class OS_Win(OS): class OS_Linux(OS): + PROGRAM_PATH = "./program" + def __init__(self, custom_methods, *args, **kwargs): from miasm2.jitter.loader.elf import vm_load_elf, preload_elf, libimp_elf from miasm2.os_dep import linux_stdlib @@ -269,9 +271,30 @@ class OS_Linux(OS): # Library calls handler self.jitter.add_lib_handler(self.libs, methods) + # Arguments + self.argv = [self.PROGRAM_PATH] + if self.options.command_line: + self.argv += self.options.command_line + self.envp = self.options.environment_vars + + @classmethod + def update_parser(cls, parser): + parser.add_argument('-c', '--command-line', + action="append", + default=[], + help="Command line arguments") + parser.add_argument('--environment-vars', + action="append", + default=[], + help="Environment variables arguments") + parser.add_argument('--mimic-env', + action="store_true", + help="Mimic the environment of a starting executable") class OS_Linux_str(OS): + PROGRAM_PATH = "./program" + def __init__(self, custom_methods, *args, **kwargs): from miasm2.jitter.loader.elf import libimp_elf from miasm2.os_dep import linux_stdlib @@ -293,8 +316,25 @@ class OS_Linux_str(OS): # Library calls handler self.jitter.add_lib_handler(libs, methods) + # Arguments + self.argv = [self.PROGRAM_PATH] + if self.options.command_line: + self.argv += self.options.command_line + self.envp = self.options.environment_vars + @classmethod def update_parser(cls, parser): + parser.add_argument('-c', '--command-line', + action="append", + default=[], + help="Command line arguments") + parser.add_argument('--environment-vars', + action="append", + default=[], + help="Environment variables arguments") + parser.add_argument('--mimic-env', + action="store_true", + help="Mimic the environment of a starting executable") parser.add_argument("load_base_addr", help="load base address") @@ -440,10 +480,32 @@ class Sandbox_Linux_x86_32(Sandbox, Arch_x86_32, OS_Linux): Sandbox.__init__(self, *args, **kwargs) # Pre-stack some arguments - self.jitter.push_uint32_t(2) - self.jitter.push_uint32_t(1) - self.jitter.push_uint32_t(0) - self.jitter.push_uint32_t(0x1337beef) + if self.options.mimic_env: + env_ptrs = [] + for env in self.envp: + env += "\x00" + self.jitter.cpu.ESP -= len(env) + ptr = self.jitter.cpu.ESP + self.jitter.vm.set_mem(ptr, env) + env_ptrs.append(ptr) + argv_ptrs = [] + for arg in self.argv: + arg += "\x00" + self.jitter.cpu.ESP -= len(arg) + ptr = self.jitter.cpu.ESP + self.jitter.vm.set_mem(ptr, arg) + argv_ptrs.append(ptr) + + self.jitter.push_uint32_t(0x1337beef) + self.jitter.push_uint32_t(0) + for ptr in reversed(env_ptrs): + self.jitter.push_uint32_t(ptr) + self.jitter.push_uint32_t(0) + for ptr in reversed(argv_ptrs): + self.jitter.push_uint32_t(ptr) + self.jitter.push_uint32_t(len(self.argv)) + else: + self.jitter.push_uint32_t(0x1337beef) # Set the runtime guard self.jitter.add_breakpoint(0x1337beef, self.__class__.code_sentinelle) @@ -462,12 +524,33 @@ class Sandbox_Linux_x86_64(Sandbox, Arch_x86_64, OS_Linux): def __init__(self, *args, **kwargs): Sandbox.__init__(self, *args, **kwargs) - # reserve stack for local reg - for _ in xrange(0x4): + # Pre-stack some arguments + if self.options.mimic_env: + env_ptrs = [] + for env in self.envp: + env += "\x00" + self.jitter.cpu.RSP -= len(env) + ptr = self.jitter.cpu.RSP + self.jitter.vm.set_mem(ptr, env) + env_ptrs.append(ptr) + argv_ptrs = [] + for arg in self.argv: + arg += "\x00" + self.jitter.cpu.RSP -= len(arg) + ptr = self.jitter.cpu.RSP + self.jitter.vm.set_mem(ptr, arg) + argv_ptrs.append(ptr) + + self.jitter.push_uint64_t(0x1337beef) self.jitter.push_uint64_t(0) - - # Pre-stack return address - self.jitter.push_uint64_t(0x1337beef) + for ptr in reversed(env_ptrs): + self.jitter.push_uint64_t(ptr) + self.jitter.push_uint64_t(0) + for ptr in reversed(argv_ptrs): + self.jitter.push_uint64_t(ptr) + self.jitter.push_uint64_t(len(self.argv)) + else: + self.jitter.push_uint64_t(0x1337beef) # Set the runtime guard self.jitter.add_breakpoint(0x1337beef, self.__class__.code_sentinelle) @@ -486,14 +569,39 @@ class Sandbox_Linux_arml(Sandbox, Arch_arml, OS_Linux): def __init__(self, *args, **kwargs): Sandbox.__init__(self, *args, **kwargs) + # Pre-stack some arguments + if self.options.mimic_env: + env_ptrs = [] + for env in self.envp: + env += "\x00" + self.jitter.cpu.SP -= len(env) + ptr = self.jitter.cpu.SP + self.jitter.vm.set_mem(ptr, env) + env_ptrs.append(ptr) + argv_ptrs = [] + for arg in self.argv: + arg += "\x00" + self.jitter.cpu.SP -= len(arg) + ptr = self.jitter.cpu.SP + self.jitter.vm.set_mem(ptr, arg) + argv_ptrs.append(ptr) + + self.jitter.push_uint32_t(0) + for ptr in reversed(env_ptrs): + self.jitter.push_uint32_t(ptr) + self.jitter.push_uint32_t(0) + for ptr in reversed(argv_ptrs): + self.jitter.push_uint32_t(ptr) + self.jitter.push_uint32_t(len(self.argv)) + self.jitter.cpu.LR = 0x1337beef # Set the runtime guard self.jitter.add_breakpoint(0x1337beef, self.__class__.code_sentinelle) def run(self, addr=None): - if addr is None and self.options.address is not None: - addr = int(self.options.address, 16) + if addr is None and self.options.address is None: + addr = self.entry_point super(Sandbox_Linux_arml, self).run(addr) @@ -534,12 +642,37 @@ class Sandbox_Linux_aarch64l(Sandbox, Arch_aarch64l, OS_Linux): def __init__(self, *args, **kwargs): Sandbox.__init__(self, *args, **kwargs) + # Pre-stack some arguments + if self.options.mimic_env: + env_ptrs = [] + for env in self.envp: + env += "\x00" + self.jitter.cpu.SP -= len(env) + ptr = self.jitter.cpu.SP + self.jitter.vm.set_mem(ptr, env) + env_ptrs.append(ptr) + argv_ptrs = [] + for arg in self.argv: + arg += "\x00" + self.jitter.cpu.SP -= len(arg) + ptr = self.jitter.cpu.SP + self.jitter.vm.set_mem(ptr, arg) + argv_ptrs.append(ptr) + + self.jitter.push_uint64_t(0) + for ptr in reversed(env_ptrs): + self.jitter.push_uint64_t(ptr) + self.jitter.push_uint64_t(0) + for ptr in reversed(argv_ptrs): + self.jitter.push_uint64_t(ptr) + self.jitter.push_uint64_t(len(self.argv)) + self.jitter.cpu.LR = 0x1337beef # Set the runtime guard self.jitter.add_breakpoint(0x1337beef, self.__class__.code_sentinelle) def run(self, addr=None): - if addr is None and self.options.address is not None: - addr = int(self.options.address, 0) + if addr is None and self.options.address is None: + addr = self.entry_point super(Sandbox_Linux_aarch64l, self).run(addr) |