summaryrefslogtreecommitdiff
path: root/python/examples
diff options
context:
space:
mode:
authorBambu <arewehuman@hotmail.com>2016-08-25 22:54:38 -0400
committerBambu <arewehuman@hotmail.com>2016-08-25 22:57:47 -0400
commit89eb0f36c13428cba18a5e40600aa2e1975e90d5 (patch)
tree2624a82b5bdd5495861b02a2c4618978caed3b55 /python/examples
parent81219f33feb70b75909b554fc4a276cd42337ed8 (diff)
Updated arm-syscall plugin to work with current api
Diffstat (limited to 'python/examples')
-rw-r--r--python/examples/README.md2
-rw-r--r--python/examples/arm-syscall.py18
-rw-r--r--python/examples/print_syscalls.py50
3 files changed, 51 insertions, 19 deletions
diff --git a/python/examples/README.md b/python/examples/README.md
index 7fd3ab6b..5f89496f 100644
--- a/python/examples/README.md
+++ b/python/examples/README.md
@@ -5,7 +5,7 @@ The following examples demonstrate some of the Binary Ninja API. They include bo
## Stand-alone
* bin-info.py - general binary information
-* arm-syscall.py - extract syscall numbers from IL for arm Mach-O files
+* print_syscalls.py - extract syscall numbers from IL on specified file. Can be run both headless and in Binary Ninja
* version-switcher.py - uses the update API to see raw version notes and manually downgrade or upgrade
To use the stand-alone Python examples, make sure your `PYTHON_PATH` includes the API, like:
diff --git a/python/examples/arm-syscall.py b/python/examples/arm-syscall.py
deleted file mode 100644
index f94b8531..00000000
--- a/python/examples/arm-syscall.py
+++ /dev/null
@@ -1,18 +0,0 @@
-#!/usr/bin/env python
-"""
- Thanks to @theqlabs from arm.ninja for the nice writeup and idea for this plugin:
- http://arm.ninja/2016/03/08/intro-to-binary-ninja-api/
-"""
-import sys, binaryninja, time
-if len(sys.argv) > 1:
- target = sys.argv[1]
-else:
- raise ValueError("Missing argument to binary.")
-
-bv = binaryninja.BinaryViewType["Mach-O"].open(target)
-bv.update_analysis_and_wait()
-
-for func in bv.functions:
- for il in func.low_level_il:
- if il.operation == core.LLIL_SYSCALL:
- print "System call address: %x - %d" % (il.address, func.get_reg_value_at_low_level_il_instruction(il.address, bv.platform.system_call_convention.int_arg_regs[0]).value)
diff --git a/python/examples/print_syscalls.py b/python/examples/print_syscalls.py
new file mode 100644
index 00000000..7e93356c
--- /dev/null
+++ b/python/examples/print_syscalls.py
@@ -0,0 +1,50 @@
+#!/usr/bin/env python
+"""
+ Thanks to @theqlabs from arm.ninja for the nice writeup and idea for this plugin:
+ http://arm.ninja/2016/03/08/intro-to-binary-ninja-api/
+"""
+import sys
+from itertools import chain
+
+from binaryninja import BinaryView, core
+
+
+def print_syscalls(bv):
+ """ Print Syscall numbers for a provided binaryview """
+
+ calling_convention = bv.platform.system_call_convention
+ if not calling_convention:
+ print('Error: No syscall convention available for {:s}'.format(bv.platform))
+ return
+
+ register = calling_convention.int_arg_regs[0]
+
+ for func in bv.functions:
+ syscalls = (il for il in chain.from_iterable(func.low_level_il)
+ if il.operation == core.LLIL_SYSCALL)
+ for il in syscalls:
+ value = func.get_reg_value_at(bv.arch, il.address, register).value
+ print("System call address: {:#x} - {:d}".format(il.address, value))
+
+
+def main():
+ if len(sys.argv) != 2:
+ print('Usage: {} <file>'.format(sys.argv[0]))
+ return -1
+
+ target = sys.argv[1]
+
+ bv = BinaryView.open(target)
+ view_type = next(bvt for bvt in bv.available_view_types if bvt.name != 'Raw')
+ if not view_type:
+ print('Error: Unable to get any other view type besides Raw')
+ return -1
+
+ bv = bv.file.get_view_of_type(view_type.name)
+ bv.update_analysis_and_wait()
+
+ print_syscalls(bv)
+
+
+if __name__ == "__main__":
+ sys.exit(main())