about summary refs log tree commit diff stats
path: root/example/asm/mips32.py
blob: fc050f1f1041fc8297b4bec7491db0f7cbad1f7f (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
#! /usr/bin/env python
from pdb import pm

from elfesteem.strpatchwork import StrPatchwork

from miasm2.core.cpu import parse_ast
from miasm2.arch.mips32.arch import mn_mips32, base_expr
from miasm2.core import parse_asm
import miasm2.expression.expression as m2_expr
from miasm2.core import asmbloc

reg_and_id = dict(mn_mips32.regs.all_regs_ids_byname)


def my_ast_int2expr(a):
    return m2_expr.ExprInt32(a)


def my_ast_id2expr(t):
    return reg_and_id.get(t, m2_expr.ExprId(t, size=32))

my_var_parser = parse_ast(my_ast_id2expr, my_ast_int2expr)
base_expr.setParseAction(my_var_parser)


st_l = StrPatchwork()
st_b = StrPatchwork()

txt = '''
main:
    ADDIU      A0, ZERO, 0x10
    ADDIU      A1, ZERO, 0
loop:
    ADDIU      A1, A1, 0x1
    BNE        A0, ZERO, loop
    ADDIU      A0, A0, 0xFFFFFFFF

    ADDIU      A2, A2, 0x1
    MOVN       A1, ZERO, ZERO
    JR         RA
    ADDIU      A2, A2, 0x1
'''

blocs_b, symbol_pool_b = parse_asm.parse_txt(mn_mips32, "b", txt)
blocs_l, symbol_pool_l = parse_asm.parse_txt(mn_mips32, "l", txt)

# fix shellcode addr
symbol_pool_b.set_offset(symbol_pool_b.getby_name("main"), 0)
symbol_pool_l.set_offset(symbol_pool_l.getby_name("main"), 0)

for b in blocs_b[0]:
    print b

resolved_b, patches_b = asmbloc.asm_resolve_final(
    mn_mips32, blocs_b[0], symbol_pool_b)
resolved_l, patches_l = asmbloc.asm_resolve_final(
    mn_mips32, blocs_l[0], symbol_pool_l)
print patches_b
print patches_l

for offset, raw in patches_b.items():
    st_b[offset] = raw
for offset, raw in patches_l.items():
    st_l[offset] = raw

open('mips32_sc_b.bin', 'wb').write(str(st_l))
open('mips32_sc_l.bin', 'wb').write(str(st_l))