diff options
| -rw-r--r-- | example/asm_msp430_sc.py | 54 | ||||
| -rw-r--r-- | example/test_jit_msp430.py | 71 | ||||
| -rw-r--r-- | test/test_all.py | 3 |
3 files changed, 128 insertions, 0 deletions
diff --git a/example/asm_msp430_sc.py b/example/asm_msp430_sc.py new file mode 100644 index 00000000..5dee56fb --- /dev/null +++ b/example/asm_msp430_sc.py @@ -0,0 +1,54 @@ +#! /usr/bin/env python + +from miasm2.core.cpu import parse_ast +from miasm2.arch.msp430.arch import mn_msp430, base_expr, variable +from miasm2.core.bin_stream import bin_stream +from miasm2.core import parse_asm +from miasm2.expression.expression import * +from elfesteem.strpatchwork import StrPatchwork + +from pdb import pm +from miasm2.core import asmbloc +import struct + +reg_and_id = dict(mn_msp430.regs.all_regs_ids_byname) + + +def my_ast_int2expr(a): + return ExprInt32(a) + + +def my_ast_id2expr(t): + return reg_and_id.get(t, ExprId(t, size=32)) + +my_var_parser = parse_ast(my_ast_id2expr, my_ast_int2expr) +base_expr.setParseAction(my_var_parser) + + +st = StrPatchwork() + +blocs, symbol_pool = parse_asm.parse_txt(mn_msp430, None, ''' +main: + mov.w 0x10, R10 + mov.w 0x0, R11 +loop: + add.w 1, R11 + sub.w 1, R10 + jnz loop + mov.w @SP+, PC +''') + +# fix shellcode addr +symbol_pool.set_offset(symbol_pool.getby_name("main"), 0) + +for b in blocs[0]: + print b + +resolved_b, patches = asmbloc.asm_resolve_final( + mn_msp430, None, blocs[0], symbol_pool) +print patches + +for offset, raw in patches.items(): + st[offset] = raw + +open('msp430_sc.bin', 'wb').write(str(st)) diff --git a/example/test_jit_msp430.py b/example/test_jit_msp430.py new file mode 100644 index 00000000..d725951a --- /dev/null +++ b/example/test_jit_msp430.py @@ -0,0 +1,71 @@ +#!/usr/bin/env python +#-*- coding:utf-8 -*- +from argparse import ArgumentParser +from miasm2.analysis import debugging, gdbserver +from miasm2.jitter.csts import * + +from miasm2.jitter.jitload import vm_load_elf, libimp, preload_elf +from miasm2.analysis.machine import Machine + +parser = ArgumentParser( + description="""Sandbox raw binary with msp430 engine +(ex: test_jit_msp430.py example/msp430_sc.bin 0)""") +parser.add_argument("-r", "--log-regs", + help="Log registers value for each instruction", + action="store_true") +parser.add_argument("-m", "--log-mn", + help="Log desassembly conversion for each instruction", + action="store_true") +parser.add_argument("-n", "--log-newbloc", + help="Log basic blocks processed by the Jitter", + action="store_true") +parser.add_argument("-j", "--jitter", + help="Jitter engine. Possible values are : tcc (default), llvm", + default="tcc") +parser.add_argument("-d", "--debugging", + help="Attach a CLI debugguer to the sandboxed programm", + action="store_true") +parser.add_argument("binary", + help="binary to run") +parser.add_argument("addr", + help="start exec on addr") + +machine = Machine("msp430") + +def jit_msp430_binary(args): + filepath, entryp = args.binary, int(args.addr, 16) + myjit = machine.jitter(jit_type = args.jitter) + myjit.init_stack() + + # Log level (if available with jitter engine) + myjit.jit.log_regs = args.log_regs + myjit.jit.log_mn = args.log_mn + myjit.jit.log_newbloc = args.log_newbloc + + myjit.vm.vm_add_memory_page(0, PAGE_READ | PAGE_WRITE, open(filepath).read()) + myjit.add_breakpoint(0x1337, lambda _: exit(0)) + + + # for stack + myjit.vm.vm_add_memory_page(0xF000, PAGE_READ | PAGE_WRITE, "\x00"*0x1000) + + myjit.cpu.SP = 0xF800 + + myjit.vm_push_uint16_t(0x1337) + myjit.init_run(entryp) + + + + # Handle debugging + if args.debugging is True: + dbg = debugging.Debugguer(myjit) + cmd = debugging.DebugCmd(dbg) + cmd.cmdloop() + + else: + print(myjit.continue_run()) + +if __name__ == '__main__': + from sys import stderr + args = parser.parse_args() + jit_msp430_binary(args) diff --git a/test/test_all.py b/test/test_all.py index 039234db..77bb7ada 100644 --- a/test/test_all.py +++ b/test/test_all.py @@ -65,6 +65,7 @@ all_tests = { ["asm_box_x86_32_mod.py"], ["asm_box_x86_32_mod_self.py"], ["asm_box_x86_32_repmod.py"], + ["asm_msp430_sc.py"], ["disasm_01.py"], ["disasm_02.py"], ["disasm_03.py", "box_upx.exe", "0x410f90"], @@ -82,6 +83,7 @@ all_tests = { ["test_dis.py", "-g", "-s", "-m", "arm", "demo_arm.bin", "0"], ["test_dis.py", "-g", "-s", "-m", "x86_32", "box_x86_32.bin", "0x401000"], + ["test_dis.py", "-g", "-s", "-m", "msp430", "msp430_sc.bin", "0"], ["expression/solve_condition_stp.py", "expression/simple_test.bin"], ], @@ -90,6 +92,7 @@ all_tests = { ["unpack_upx.py", "box_upx.exe"], # Take 5 mins on a Core i5 ["test_jit_x86_32.py", "x86_32_sc.bin"], ["test_jit_arm.py", "md5_arm", "A684"], + ["test_jit_msp430.py", "msp430_sc.bin", "0"], ["sandbox_pe_x86_32.py", "box_x86_32.bin"], ["sandbox_pe_x86_32.py", "box_x86_32_enc.bin"], ["sandbox_pe_x86_32.py", "box_x86_32_mod.bin"], |