1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
|
#! /usr/bin/env python
from miasm2.core.cpu import parse_ast
from miasm2.arch.arm.arch import mn_arm, base_expr, variable
from miasm2.core import parse_asm
from miasm2.expression.expression import *
from miasm2.core import asmbloc
from elfesteem.strpatchwork import StrPatchwork
my_mn = mn_arm
reg_and_id = dict(mn_arm.regs.all_regs_ids_byname)
def my_ast_int2expr(a):
return ExprInt32(a)
def my_ast_id2expr(t):
return reg_and_id.get(t, ExprId(t, size=32))
my_var_parser = parse_ast(my_ast_id2expr, my_ast_int2expr)
base_expr.setParseAction(my_var_parser)
txt = '''
main:
STMFD SP!, {R4, R5, LR}
MOV R0, mystr & 0xffff
ORR R0, R0, mystr & 0xffff0000
MOV R4, R0
MOV R1, mystrend & 0xffff
ORR R1, R1, mystrend & 0xffff0000
xxx:
LDR R2, [PC, key-$]
LDR R6, [PC, test-$]
loop:
LDRB R3, [R0]
EOR R3, R3, R2
STRB R3, [R0], 1
CMP R0, R1
BNE loop
end:
MOV R0, R4
LDMFD SP!, {R4, R5, PC}
key:
.long 0x11223344
mystr:
.string "test string"
mystrend:
.long 0
test:
.long mystrend - key + 0x1122
'''
blocs_b, symbol_pool_b = parse_asm.parse_txt(my_mn, "b", txt)
blocs_l, symbol_pool_l = parse_asm.parse_txt(my_mn, "l", txt)
# fix shellcode addr
symbol_pool_b.set_offset(symbol_pool_b.getby_name("main"), 0x0)
symbol_pool_l.set_offset(symbol_pool_l.getby_name("main"), 0x0)
# graph sc####
g = asmbloc.bloc2graph(blocs_l[0])
open("graph.txt", "w").write(g)
s_b = StrPatchwork()
s_l = StrPatchwork()
print "symbols"
print symbol_pool_l
# dont erase from start to shell code padading
resolved_b, patches_b = asmbloc.asm_resolve_final(
my_mn, blocs_b[0], symbol_pool_b)
resolved_l, patches_l = asmbloc.asm_resolve_final(
my_mn, blocs_l[0], symbol_pool_l)
print patches_b
for offset, raw in patches_b.items():
s_b[offset] = raw
for offset, raw in patches_l.items():
s_l[offset] = raw
open('demo_arm_b.bin', 'w').write(str(s_b))
open('demo_arm_l.bin', 'w').write(str(s_l))
|