mirror of
https://github.com/idapython/src
synced 2026-06-08 14:47:00 +00:00
43 lines
1.1 KiB
Python
43 lines
1.1 KiB
Python
from __future__ import print_function
|
|
#
|
|
# This sample illustrates how to use appcall, with the
|
|
# 'simple_appcall_win32.exe' or 'simple_appcall_win64.exe' test
|
|
# programs (see subdirectories.)
|
|
#
|
|
# This example will run the test program and stop wherever
|
|
# the cursor currently is, and then perform an appcall to
|
|
# `ref4` and `ref8`
|
|
#
|
|
# To use this example:
|
|
# * run `ida64` on test program `simple_appcall_win64.exe`, or
|
|
# `ida` on test program `simple_appcall_win32.exe`, and wait for
|
|
# auto-analysis to finish
|
|
# * select the 'windows debugger' (either local, or remote)
|
|
# * run this script
|
|
#
|
|
|
|
import os
|
|
import sys
|
|
sys.path.append(os.path.dirname(__file__))
|
|
|
|
# Windows binaries don't have any symbols, thus we'll have
|
|
# to assign names to addresses of interest before we can
|
|
# appcall them by name.
|
|
import ida_ida
|
|
if ida_ida.inf_is_64bit():
|
|
ref4_ea = 0x140001000
|
|
ref8_ea = 0x140001060
|
|
else:
|
|
ref4_ea = 0x401000
|
|
ref8_ea = 0x401050
|
|
|
|
import simple_appcall_common
|
|
appcall_hooks = simple_appcall_common.appcall_hooks_t(
|
|
name_funcs=[
|
|
(ref4_ea, "ref4"),
|
|
(ref8_ea, "ref8"),
|
|
])
|
|
|
|
appcall_hooks.hook()
|
|
appcall_hooks.run()
|