about summary refs log tree commit diff stats
path: root/example
diff options
context:
space:
mode:
Diffstat (limited to 'example')
-rw-r--r--example/asm_msp430_sc.py54
-rw-r--r--example/test_jit_msp430.py71
-rw-r--r--example/unpack_upx.py10
3 files changed, 130 insertions, 5 deletions
diff --git a/example/asm_msp430_sc.py b/example/asm_msp430_sc.py
new file mode 100644
index 00000000..5dee56fb
--- /dev/null
+++ b/example/asm_msp430_sc.py
@@ -0,0 +1,54 @@
+#! /usr/bin/env python
+
+from miasm2.core.cpu import parse_ast
+from miasm2.arch.msp430.arch import mn_msp430, base_expr, variable
+from miasm2.core.bin_stream import bin_stream
+from miasm2.core import parse_asm
+from miasm2.expression.expression import *
+from elfesteem.strpatchwork import StrPatchwork
+
+from pdb import pm
+from miasm2.core import asmbloc
+import struct
+
+reg_and_id = dict(mn_msp430.regs.all_regs_ids_byname)
+
+
+def my_ast_int2expr(a):
+    return ExprInt32(a)
+
+
+def my_ast_id2expr(t):
+    return reg_and_id.get(t, ExprId(t, size=32))
+
+my_var_parser = parse_ast(my_ast_id2expr, my_ast_int2expr)
+base_expr.setParseAction(my_var_parser)
+
+
+st = StrPatchwork()
+
+blocs, symbol_pool = parse_asm.parse_txt(mn_msp430, None, '''
+main:
+    mov.w      0x10, R10
+    mov.w      0x0, R11
+loop:
+    add.w      1, R11
+    sub.w      1, R10
+    jnz        loop
+    mov.w      @SP+, PC
+''')
+
+# fix shellcode addr
+symbol_pool.set_offset(symbol_pool.getby_name("main"), 0)
+
+for b in blocs[0]:
+    print b
+
+resolved_b, patches = asmbloc.asm_resolve_final(
+    mn_msp430, None, blocs[0], symbol_pool)
+print patches
+
+for offset, raw in patches.items():
+    st[offset] = raw
+
+open('msp430_sc.bin', 'wb').write(str(st))
diff --git a/example/test_jit_msp430.py b/example/test_jit_msp430.py
new file mode 100644
index 00000000..d725951a
--- /dev/null
+++ b/example/test_jit_msp430.py
@@ -0,0 +1,71 @@
+#!/usr/bin/env python
+#-*- coding:utf-8 -*-
+from argparse import ArgumentParser
+from miasm2.analysis import debugging, gdbserver
+from miasm2.jitter.csts import *
+
+from miasm2.jitter.jitload import vm_load_elf, libimp, preload_elf
+from miasm2.analysis.machine import Machine
+
+parser = ArgumentParser(
+    description="""Sandbox raw binary with msp430 engine
+(ex: test_jit_msp430.py example/msp430_sc.bin 0)""")
+parser.add_argument("-r", "--log-regs",
+                    help="Log registers value for each instruction",
+                    action="store_true")
+parser.add_argument("-m", "--log-mn",
+                    help="Log desassembly conversion for each instruction",
+                    action="store_true")
+parser.add_argument("-n", "--log-newbloc",
+                    help="Log basic blocks processed by the Jitter",
+                    action="store_true")
+parser.add_argument("-j", "--jitter",
+                    help="Jitter engine. Possible values are : tcc (default), llvm",
+                    default="tcc")
+parser.add_argument("-d", "--debugging",
+                    help="Attach a CLI debugguer to the sandboxed programm",
+                    action="store_true")
+parser.add_argument("binary",
+                    help="binary to run")
+parser.add_argument("addr",
+                    help="start exec on addr")
+
+machine = Machine("msp430")
+
+def jit_msp430_binary(args):
+    filepath, entryp = args.binary, int(args.addr, 16)
+    myjit = machine.jitter(jit_type = args.jitter)
+    myjit.init_stack()
+
+    # Log level (if available with jitter engine)
+    myjit.jit.log_regs = args.log_regs
+    myjit.jit.log_mn = args.log_mn
+    myjit.jit.log_newbloc = args.log_newbloc
+
+    myjit.vm.vm_add_memory_page(0, PAGE_READ | PAGE_WRITE, open(filepath).read())
+    myjit.add_breakpoint(0x1337, lambda _: exit(0))
+
+
+    # for stack
+    myjit.vm.vm_add_memory_page(0xF000, PAGE_READ | PAGE_WRITE, "\x00"*0x1000)
+
+    myjit.cpu.SP = 0xF800
+
+    myjit.vm_push_uint16_t(0x1337)
+    myjit.init_run(entryp)
+
+
+
+    # Handle debugging
+    if args.debugging is True:
+        dbg = debugging.Debugguer(myjit)
+        cmd = debugging.DebugCmd(dbg)
+        cmd.cmdloop()
+
+    else:
+        print(myjit.continue_run())
+
+if __name__ == '__main__':
+    from sys import stderr
+    args = parser.parse_args()
+    jit_msp430_binary(args)
diff --git a/example/unpack_upx.py b/example/unpack_upx.py
index 14eac9ef..05e3f4b7 100644
--- a/example/unpack_upx.py
+++ b/example/unpack_upx.py
@@ -10,13 +10,12 @@ from elfesteem import *
 from elfesteem.strpatchwork import StrPatchwork
 
 from miasm2.core import asmbloc
-from miasm2.arch.x86.arch import mn_x86
-from miasm2.arch.x86.disasm import dis_x86_32
-from miasm2.jitter.jitload import jitter_x86_32, vm_load_pe, preload_pe, libimp
+from miasm2.jitter.jitload import vm_load_pe, preload_pe, libimp
 from miasm2.jitter.jitload import bin_stream_vm
 from miasm2.jitter.csts import *
 from miasm2.jitter.os_dep import win_api_x86_32
 
+from miasm2.analysis.machine import Machine
 # Debug settings #
 from pdb import pm
 
@@ -56,7 +55,8 @@ else:
     logging.basicConfig(level=logging.WARNING)
 
 # Init arch
-myjit = jitter_x86_32(jit_type=args.jitter)
+machine = Machine("x86_32")
+myjit = machine.jitter(args.jitter)
 myjit.init_stack()
 
 # Log level (if available with jitter engine)
@@ -74,7 +74,7 @@ if args.verbose is True:
 ep = e.rva2virt(e.Opthdr.AddressOfEntryPoint)
 
 # Ensure there is one and only one leave (for OEP discovering)
-mdis = dis_x86_32(myjit.bs)
+mdis = machine.dis_engine(myjit.bs)
 mdis.dont_dis_nulstart_bloc = True
 ab = mdis.dis_multibloc(ep)