2015-08-26 01:48:12 +00:00
|
|
|
#!/usr/bin/python
|
|
|
|
from unicorn import *
|
|
|
|
from unicorn.x86_const import *
|
|
|
|
|
|
|
|
ESP = 0x2000
|
|
|
|
PAGE_SIZE = 1 * 1024 * 1024
|
|
|
|
|
2015-09-19 17:02:30 +00:00
|
|
|
# wait
|
|
|
|
# fnstcw word ptr [esp]
|
|
|
|
# pop ecx
|
2015-08-26 01:48:12 +00:00
|
|
|
CODE = b'\x9B\xD9\x3C\x24\x59'
|
|
|
|
|
|
|
|
def mem_reader(addr, size):
|
2015-09-19 17:02:30 +00:00
|
|
|
tmp = mu.mem_read(addr, size)
|
2015-08-26 01:48:12 +00:00
|
|
|
|
2015-09-19 17:02:30 +00:00
|
|
|
for i in tmp:
|
|
|
|
print(" 0x%x" % i),
|
|
|
|
print("")
|
2015-08-26 01:48:12 +00:00
|
|
|
|
|
|
|
def hook_mem_write(uc, access, address, size, value, user_data):
|
2015-09-19 17:02:30 +00:00
|
|
|
print("mem WRITE: 0x%x, data size = %u, data value = 0x%x" % (address, size, value))
|
|
|
|
return True
|
2015-08-26 01:48:12 +00:00
|
|
|
|
|
|
|
mu = Uc(UC_ARCH_X86, UC_MODE_32)
|
|
|
|
mu.mem_map(0, PAGE_SIZE)
|
|
|
|
mu.mem_write(0, CODE)
|
|
|
|
mu.reg_write(UC_X86_REG_ESP, ESP)
|
|
|
|
mu.hook_add(UC_HOOK_MEM_WRITE, hook_mem_write)
|
|
|
|
|
2015-09-19 17:02:30 +00:00
|
|
|
mu.emu_start(0x0, 5, 0, 2)
|
2015-08-26 01:48:12 +00:00
|
|
|
esp = mu.reg_read(UC_X86_REG_ESP)
|
|
|
|
print("value at ESP [0x%X]: " % esp)
|
2015-09-19 17:02:30 +00:00
|
|
|
mem_reader(esp, 10)
|