about summary refs log tree commit diff stats
diff options
context:
space:
mode:
-rw-r--r--example/asm_msp430_sc.py54
-rw-r--r--example/test_jit_msp430.py71
-rw-r--r--test/test_all.py3
3 files changed, 128 insertions, 0 deletions
diff --git a/example/asm_msp430_sc.py b/example/asm_msp430_sc.py
new file mode 100644
index 00000000..5dee56fb
--- /dev/null
+++ b/example/asm_msp430_sc.py
@@ -0,0 +1,54 @@
+#! /usr/bin/env python
+
+from miasm2.core.cpu import parse_ast
+from miasm2.arch.msp430.arch import mn_msp430, base_expr, variable
+from miasm2.core.bin_stream import bin_stream
+from miasm2.core import parse_asm
+from miasm2.expression.expression import *
+from elfesteem.strpatchwork import StrPatchwork
+
+from pdb import pm
+from miasm2.core import asmbloc
+import struct
+
+reg_and_id = dict(mn_msp430.regs.all_regs_ids_byname)
+
+
+def my_ast_int2expr(a):
+    return ExprInt32(a)
+
+
+def my_ast_id2expr(t):
+    return reg_and_id.get(t, ExprId(t, size=32))
+
+my_var_parser = parse_ast(my_ast_id2expr, my_ast_int2expr)
+base_expr.setParseAction(my_var_parser)
+
+
+st = StrPatchwork()
+
+blocs, symbol_pool = parse_asm.parse_txt(mn_msp430, None, '''
+main:
+    mov.w      0x10, R10
+    mov.w      0x0, R11
+loop:
+    add.w      1, R11
+    sub.w      1, R10
+    jnz        loop
+    mov.w      @SP+, PC
+''')
+
+# fix shellcode addr
+symbol_pool.set_offset(symbol_pool.getby_name("main"), 0)
+
+for b in blocs[0]:
+    print b
+
+resolved_b, patches = asmbloc.asm_resolve_final(
+    mn_msp430, None, blocs[0], symbol_pool)
+print patches
+
+for offset, raw in patches.items():
+    st[offset] = raw
+
+open('msp430_sc.bin', 'wb').write(str(st))
diff --git a/example/test_jit_msp430.py b/example/test_jit_msp430.py
new file mode 100644
index 00000000..d725951a
--- /dev/null
+++ b/example/test_jit_msp430.py
@@ -0,0 +1,71 @@
+#!/usr/bin/env python
+#-*- coding:utf-8 -*-
+from argparse import ArgumentParser
+from miasm2.analysis import debugging, gdbserver
+from miasm2.jitter.csts import *
+
+from miasm2.jitter.jitload import vm_load_elf, libimp, preload_elf
+from miasm2.analysis.machine import Machine
+
+parser = ArgumentParser(
+    description="""Sandbox raw binary with msp430 engine
+(ex: test_jit_msp430.py example/msp430_sc.bin 0)""")
+parser.add_argument("-r", "--log-regs",
+                    help="Log registers value for each instruction",
+                    action="store_true")
+parser.add_argument("-m", "--log-mn",
+                    help="Log desassembly conversion for each instruction",
+                    action="store_true")
+parser.add_argument("-n", "--log-newbloc",
+                    help="Log basic blocks processed by the Jitter",
+                    action="store_true")
+parser.add_argument("-j", "--jitter",
+                    help="Jitter engine. Possible values are : tcc (default), llvm",
+                    default="tcc")
+parser.add_argument("-d", "--debugging",
+                    help="Attach a CLI debugguer to the sandboxed programm",
+                    action="store_true")
+parser.add_argument("binary",
+                    help="binary to run")
+parser.add_argument("addr",
+                    help="start exec on addr")
+
+machine = Machine("msp430")
+
+def jit_msp430_binary(args):
+    filepath, entryp = args.binary, int(args.addr, 16)
+    myjit = machine.jitter(jit_type = args.jitter)
+    myjit.init_stack()
+
+    # Log level (if available with jitter engine)
+    myjit.jit.log_regs = args.log_regs
+    myjit.jit.log_mn = args.log_mn
+    myjit.jit.log_newbloc = args.log_newbloc
+
+    myjit.vm.vm_add_memory_page(0, PAGE_READ | PAGE_WRITE, open(filepath).read())
+    myjit.add_breakpoint(0x1337, lambda _: exit(0))
+
+
+    # for stack
+    myjit.vm.vm_add_memory_page(0xF000, PAGE_READ | PAGE_WRITE, "\x00"*0x1000)
+
+    myjit.cpu.SP = 0xF800
+
+    myjit.vm_push_uint16_t(0x1337)
+    myjit.init_run(entryp)
+
+
+
+    # Handle debugging
+    if args.debugging is True:
+        dbg = debugging.Debugguer(myjit)
+        cmd = debugging.DebugCmd(dbg)
+        cmd.cmdloop()
+
+    else:
+        print(myjit.continue_run())
+
+if __name__ == '__main__':
+    from sys import stderr
+    args = parser.parse_args()
+    jit_msp430_binary(args)
diff --git a/test/test_all.py b/test/test_all.py
index 039234db..77bb7ada 100644
--- a/test/test_all.py
+++ b/test/test_all.py
@@ -65,6 +65,7 @@ all_tests = {
             ["asm_box_x86_32_mod.py"],
             ["asm_box_x86_32_mod_self.py"],
             ["asm_box_x86_32_repmod.py"],
+            ["asm_msp430_sc.py"],
             ["disasm_01.py"],
             ["disasm_02.py"],
             ["disasm_03.py", "box_upx.exe", "0x410f90"],
@@ -82,6 +83,7 @@ all_tests = {
             ["test_dis.py", "-g", "-s", "-m", "arm", "demo_arm.bin", "0"],
             ["test_dis.py", "-g", "-s", "-m",
                 "x86_32", "box_x86_32.bin", "0x401000"],
+            ["test_dis.py", "-g", "-s", "-m", "msp430", "msp430_sc.bin", "0"],
             ["expression/solve_condition_stp.py",
                 "expression/simple_test.bin"],
         ],
@@ -90,6 +92,7 @@ all_tests = {
                     ["unpack_upx.py", "box_upx.exe"], # Take 5 mins on a Core i5
                     ["test_jit_x86_32.py", "x86_32_sc.bin"],
                     ["test_jit_arm.py", "md5_arm", "A684"],
+                    ["test_jit_msp430.py", "msp430_sc.bin", "0"],
                     ["sandbox_pe_x86_32.py", "box_x86_32.bin"],
                     ["sandbox_pe_x86_32.py", "box_x86_32_enc.bin"],
                     ["sandbox_pe_x86_32.py", "box_x86_32_mod.bin"],