From 5a42aec73a77a3a54baf054cde9047533709be31 Mon Sep 17 00:00:00 2001 From: Bambu Date: Thu, 25 Aug 2016 22:04:12 -0400 Subject: Removed dynamic linking. Added c++ version of arm-syscall python plugin. Renamed it since it works for more than just arm --- examples/print_syscalls/src/arm-syscall.cpp | 115 ++++++++++++++++++++++++++++ 1 file changed, 115 insertions(+) create mode 100644 examples/print_syscalls/src/arm-syscall.cpp (limited to 'examples/print_syscalls/src/arm-syscall.cpp') diff --git a/examples/print_syscalls/src/arm-syscall.cpp b/examples/print_syscalls/src/arm-syscall.cpp new file mode 100644 index 00000000..3424619b --- /dev/null +++ b/examples/print_syscalls/src/arm-syscall.cpp @@ -0,0 +1,115 @@ +/* + * Outputs the syscall numbers called by a binary. + */ + +#include + +#include +#include + +#include "binaryninjacore.h" +#include "binaryninjaapi.h" + +using namespace BinaryNinja; +using namespace std; + +#ifndef __WIN32__ +#include +#include +string get_plugins_directory() +{ + Dl_info info; + if (!dladdr((void *)BNGetBundledPluginDirectory, &info)) + return NULL; + + stringstream ss; + ss << dirname((char *)info.dli_fname) << "/plugins/"; + return ss.str(); +} +#else +string get_plugins_directory() +{ + return "C:\\Program Files\\Vector35\\Binary Ninja\\plugins\\"; +} +#endif + +bool is_file(char *fname) +{ + struct stat buf; + if (stat(fname, &buf) == 0 && (buf.st_mode & S_IFREG) == S_IFREG) + return true; + + return false; +} + +int main(int argc, char *argv[]) +{ + if (argc != 2) { + cerr << "USAGE: " << argv[0] << " " << endl; + exit(-1); + } + + char *fname = argv[1]; + if (!is_file(fname)) { + cerr << "Error: " << fname << " is not a regular file" << endl; + exit(-1); + } + + /* In order to initiate the bundled plugins properly, the location + * of where bundled plugins directory is must be set. Since + * libbinaryninjacore is in the path get the path to it and use it to + * determine the plugins directory */ + SetBundledPluginDirectory(get_plugins_directory()); + InitCorePlugins(); + InitUserPlugins(); + + auto bd = BinaryData(new FileMetadata(), fname); + BinaryView *bv = 0; + + for (auto type : BinaryViewType::GetViewTypesForData(&bd)) { + if (type->GetName() != "Raw") { + bv = type->Create(&bd); + break; + } + } + + if (!bv || bv->GetTypeName() == "Raw"){ + cerr << "Error: Unable to get any other view type besides Raw"; + exit(-1); + } + + bv->UpdateAnalysis(); + while (bv->GetAnalysisProgress().state != IdleState); + + auto arch = bv->GetDefaultArchitecture(); + auto platform = bv->GetDefaultPlatform(); + + auto cc = platform->GetSystemCallConvention(); + if (!cc) { + cerr << "Error: No system call conventions found for " + << platform->GetName() << endl; + exit(-1); + } + + auto reg = cc->GetIntegerArgumentRegisters()[0]; + + for (Function *func : bv->GetAnalysisFunctionList()) { + auto il_func = func->GetLowLevelIL(); + + for (size_t i = 0; i < il_func->GetInstructionCount(); i++) { + auto instr = (*il_func)[il_func->GetIndexForInstruction(i)]; + + if (instr.operation == LLIL_SYSCALL) { + auto reg_value = func->GetRegisterValueAtLowLevelILInstruction(i, reg); + + cout << "System call address: 0x" + << hex << instr.address + << " - " + << dec << reg_value.value + << endl; + } + } + } + + return 0; +} -- cgit v1.3.1