From 57d00b0eee4f55163e40705aedaec3ecc16c8ef2 Mon Sep 17 00:00:00 2001 From: Jordan Wiens Date: Mon, 11 Apr 2016 11:55:14 -0400 Subject: adding readme, arm-syscall, bin-info, and breakpoint plugins --- python/examples/arm-syscall.py | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 python/examples/arm-syscall.py (limited to 'python/examples/arm-syscall.py') diff --git a/python/examples/arm-syscall.py b/python/examples/arm-syscall.py new file mode 100644 index 00000000..cbd8f4bf --- /dev/null +++ b/python/examples/arm-syscall.py @@ -0,0 +1,21 @@ +#!/usr/bin/env python +""" + Thanks to @theqlabs from arm.ninja for the nice writeup and idea for this plugin: + http://arm.ninja/2016/03/08/intro-to-binary-ninja-api/ +""" +import sys, binaryninja, time +if len(sys.argv) > 1: + target = sys.argv[1] +else: + raise ValueError("Missing argument to binary.") + +bv = binaryninja.BinaryViewType["Mach-O"].open(target) +bv.update_analysis() + +"""Until update_analysis_and_wait is complete, sleep is necessary as the analysis is multi-threaded.""" +time.sleep(5) + +for func in bv.functions: + for il in func.low_level_il: + if il.operation == core.LLIL_SYSCALL: + print "System call address: %x - %d" % (il.address, func.get_reg_value_at_low_level_il_instruction(il.address, bv.platform.system_call_convention.int_arg_regs[0]).value) -- cgit v1.3.1