Files
idapython-src/examples/debugging/appcall/simple_appcall_win.py
T
2020-05-27 14:34:02 +02:00

43 lines
1.1 KiB
Python

from __future__ import print_function
#
# This sample illustrates how to use appcall, with the
# 'simple_appcall_win32.exe' or 'simple_appcall_win64.exe' test
# programs (see subdirectories.)
#
# This example will run the test program and stop wherever
# the cursor currently is, and then perform an appcall to
# `ref4` and `ref8`
#
# To use this example:
# * run `ida64` on test program `simple_appcall_win64.exe`, or
# `ida` on test program `simple_appcall_win32.exe`, and wait for
# auto-analysis to finish
# * select the 'windows debugger' (either local, or remote)
# * run this script
#
import os
import sys
sys.path.append(os.path.dirname(__file__))
# Windows binaries don't have any symbols, thus we'll have
# to assign names to addresses of interest before we can
# appcall them by name.
import ida_ida
if ida_ida.inf_is_64bit():
ref4_ea = 0x140001000
ref8_ea = 0x140001060
else:
ref4_ea = 0x401000
ref8_ea = 0x401050
import simple_appcall_common
appcall_hooks = simple_appcall_common.appcall_hooks_t(
name_funcs=[
(ref4_ea, "ref4"),
(ref8_ea, "ref8"),
])
appcall_hooks.hook()
appcall_hooks.run()