mirror of
https://github.com/cea-sec/miasm
synced 2026-06-21 13:48:18 +00:00
16 KiB
16 KiB
In [1]:
from miasm.analysis.machine import Machine
Machine.available_machine()Out [1]:
['arml', 'armb', 'armtl', 'armtb', 'sh4', 'x86_16', 'x86_32', 'x86_64', 'msp430', 'mips32b', 'mips32l', 'aarch64l', 'aarch64b', 'ppc32b', 'mepl', 'mepb']
In [2]:
machine = Machine("x86_32")
print(machine.name)x86_32
In [3]:
from miasm.core.locationdb import LocationDB
loc_db = LocationDB()
jitter = machine.jitter(loc_db)
print(jitter)<miasm.arch.x86.jit.jitter_x86_32 object at 0x7f195fe07d60>
In [12]:
# Read a register
print(jitter.cpu.EAX)
# Write a register
jitter.cpu.EAX = 1
print(jitter.cpu.EAX)0 1
In [13]:
# GPReg : General Purpose registers
regs = jitter.cpu.get_gpreg()
print(regs){'RAX': 1, 'RBX': 0, 'RCX': 0, 'RDX': 0, 'RSI': 0, 'RDI': 0, 'RSP': 0, 'RBP': 0, 'R8': 0, 'R9': 0, 'R10': 0, 'R11': 0, 'R12': 0, 'R13': 0, 'R14': 0, 'R15': 0, 'RIP': 0, 'zf': 0, 'nf': 0, 'pf': 0, 'of': 0, 'cf': 0, 'af': 0, 'df': 0, 'ES': 0, 'CS': 0, 'SS': 0, 'DS': 0, 'FS': 0, 'GS': 0, 'MM0': 0, 'MM1': 0, 'MM2': 0, 'MM3': 0, 'MM4': 0, 'MM5': 0, 'MM6': 0, 'MM7': 0, 'XMM0': 0, 'XMM1': 0, 'XMM2': 0, 'XMM3': 0, 'XMM4': 0, 'XMM5': 0, 'XMM6': 0, 'XMM7': 0, 'XMM8': 0, 'XMM9': 0, 'XMM10': 0, 'XMM11': 0, 'XMM12': 0, 'XMM13': 0, 'XMM14': 0, 'XMM15': 0, 'tsc': 1234605616436508552}
In [14]:
jitter.vmOut [14]:
Addr Size Access Comment
In [16]:
from miasm.jitter.csts import PAGE_READ, PAGE_WRITE, PAGE_EXEC
jitter.vm.add_memory_page(0x1000, PAGE_READ | PAGE_WRITE | PAGE_EXEC, b"\x00" * 0x1000, "test page")
jitter.vm.add_memory_page(0x112233, PAGE_READ | PAGE_WRITE | PAGE_EXEC, b"\x00" * 0x666, "no alignment, byte precision")
jitter.vmOut [16]:
Addr Size Access Comment 0x1000 0x1000 RWX test page 0x112233 0x666 RWX no alignment, byte precision
In [17]:
jitter.vm.get_mem(0x1000, 0x10)Out [17]:
b'\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
In [18]:
jitter.vm.set_mem(0x1000, b"toto")
jitter.vm.get_mem(0x1000, 0x10)Out [18]:
b'toto\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
In [21]:
jitter.vm.set_mem(0x1000, bytes.fromhex("B844332211C3"))In [22]:
jitter.set_trace_log()In [27]:
jitter.vm.add_memory_page(0x88880000, PAGE_READ | PAGE_WRITE | PAGE_EXEC, b"\x00" * 0x1000, "stack")
jitter.vm.set_mem(0x88880000 + 0x1000 - 4, b"\xef\xbe\x37\x13")
jitter.cpu.ESP = 0x88880000 + 0x1000 - 4
jitter.run(0x1000)
# The execution ends with an error, which is expected.
# Indeed, we RET on 0x1337beef, which is not mapped in memory,
# hence the "WARNING: address 0x1337BEEF is not mapped in virtual memory"[WARNING ]: [Errno cannot get mem ad] 0x1337beef WARNING: address 0x1337BEEF is not mapped in virtual memory: [WARNING ]: cannot disasm at 1337BEEF
00001000 MOV EAX, 0x11223344 EAX 11223344 EBX 00000000 ECX 00000000 EDX 00000000 ESI 00000000 EDI 00000000 ESP 88880FFC EBP 00000000 EIP 00001005 zf 0 nf 0 of 0 cf 0 00001005 RET EAX 11223344 EBX 00000000 ECX 00000000 EDX 00000000 ESI 00000000 EDI 00000000 ESP 88881000 EBP 00000000 EIP 1337BEEF zf 0 nf 0 of 0 cf 0
In [31]:
# Breakpoints are actually callbacks which receive the emulation instance in argument
def hello_world(jitter):
print("Hello, world!")
print("EAX value is %d" % jitter.cpu.EAX)
# Stop execution right here
return False
jitter.add_breakpoint(0x1005, hello_world)In [30]:
# Init a stack and set stack pointer accordingly (architecture agnostic way of writing)
jitter.init_stack()
# Push 0x1000 on the stack
jitter.push_uint32_t(0x1000)
# Pop 0x1000 from the stack
print(hex(jitter.pop_uint32_t()))0x1000