update to ida 7.6, add builds
This commit is contained in:
34
idasdk76/dbg/bochs/bochsext.h
Normal file
34
idasdk76/dbg/bochs/bochsext.h
Normal file
@@ -0,0 +1,34 @@
|
||||
/*
|
||||
* Interactive disassembler (IDA).
|
||||
* ALL RIGHTS RESERVED.
|
||||
* Copyright (c) 1990-2021 Hex-Rays
|
||||
*
|
||||
*
|
||||
* This file defines the Bochs Debugger module extension functions.
|
||||
* Use debugger_t->get_debmod_extensions() to retrieve this structure.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef __BOCHSEXT__
|
||||
#define __BOCHSEXT__
|
||||
|
||||
#pragma pack(push, 1)
|
||||
|
||||
#define BOCHSEXT_VER 1
|
||||
|
||||
struct bochsext_t
|
||||
{
|
||||
// the structure version
|
||||
uint32 version;
|
||||
|
||||
// Sends an arbitrary command to Bochs internal debugger
|
||||
// cmd - command to send
|
||||
// out - pointer to qstring that will hold the output of the command
|
||||
// Returns: true if ok; false if failed to send command to bochs or receive
|
||||
// a reply
|
||||
bool (idaapi *send_command)(const char *cmd, qstring *out);
|
||||
};
|
||||
|
||||
#pragma pack(pop)
|
||||
|
||||
#endif
|
||||
62
idasdk76/dbg/bochs/ctrl/bochsys.h
Normal file
62
idasdk76/dbg/bochs/ctrl/bochsys.h
Normal file
@@ -0,0 +1,62 @@
|
||||
/*
|
||||
* Interactive disassembler (IDA).
|
||||
* ALL RIGHTS RESERVED.
|
||||
* Copyright (c) 1990-2021 Hex-Rays
|
||||
*
|
||||
*
|
||||
* This file defines the functions prototypes that are exported by bochsys.dll
|
||||
*
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef __BOCHSYS_DLL__
|
||||
#define __BOCHSYS_DLL__
|
||||
|
||||
#define WIN32_LEAN_AND_MEAN
|
||||
#include <windows.h>
|
||||
|
||||
#define BX_CALLCONV WINAPI
|
||||
|
||||
typedef wchar_t wchar16_t;
|
||||
//CASSERT(sizeof(wchar16_t) == 2);
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// These functions are similar to MS Windows functions. Please refer
|
||||
// to the SDK documentation for more information on how to use them.
|
||||
extern FARPROC WINAPI BxGetProcAddress(HMODULE hMod, LPCSTR ProcName);
|
||||
extern HMODULE WINAPI BxGetModuleHandleA(LPCSTR ModuleFileName);
|
||||
extern DWORD WINAPI BxGetModuleFileNameA(HINSTANCE hModule, LPCSTR lpFilename, DWORD nSize);
|
||||
extern DWORD WINAPI BxGetModuleFileNameW(HINSTANCE hModule, LPWSTR lpFilename, DWORD nSize);
|
||||
extern HMODULE WINAPI BxLoadLibraryA(LPCTSTR lpFileName);
|
||||
extern LPVOID WINAPI BxVirtualAlloc(LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect);
|
||||
extern BOOL WINAPI BxVirtualFree(LPVOID lpAddress, SIZE_T dwSize, DWORD dwFreeType);
|
||||
extern DWORD WINAPI BxExitProcess(DWORD);
|
||||
extern DWORD WINAPI BxGetTickCount(VOID);
|
||||
extern BOOL WINAPI BxVirtualProtect(LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect);
|
||||
extern DWORD WINAPI BxWin32SetLastError(DWORD ErrorCode);
|
||||
extern DWORD WINAPI BxWin32GetLastError(VOID);
|
||||
extern LPCSTR WINAPI BxWin32GetCommandLineA(VOID);
|
||||
extern LPWSTR WINAPI BxWin32GetCommandLineW(VOID);
|
||||
extern LPCSTR WINAPI BxWin32GetEnvironmentStringsA(VOID);
|
||||
extern LPWSTR WINAPI BxWin32GetEnvironmentStringsW(VOID);
|
||||
extern LPVOID WINAPI BxWin32TlsGetValue(DWORD dwTlsIndex);
|
||||
extern BOOL WINAPI BxWin32TlsSetValue(DWORD dwTlsIndex,LPVOID lpTlsValue);
|
||||
extern BOOL WINAPI BxWin32TlsFree(DWORD dwTlsIndex);
|
||||
extern DWORD WINAPI BxWin32TlsAlloc(VOID);
|
||||
extern DWORD WINAPI BxWin32FlsAlloc(VOID);
|
||||
extern char * WINAPI BxStrCpyA(char *Dst, char *Src);
|
||||
extern wchar16_t * WINAPI BxStrCpyW(wchar16_t *Dst, wchar16_t *Src);
|
||||
extern char * WINAPI BxStrCatA(char *Dst, char *Src);
|
||||
extern wchar16_t * WINAPI BxStrCatW(wchar16_t *Dst, wchar16_t *Src);
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// Installs an exception handler. Only one exception handler
|
||||
// can be installed at one time. You need to uninstall one
|
||||
// before reinstalling another.
|
||||
// These two functions will return non-zero on success.
|
||||
typedef DWORD (*PEXCEPTION_HANDLER)(PEXCEPTION_RECORD, struct _EXCEPTION_REGISTRATION_RECORD *, PCONTEXT,struct _EXCEPTION_REGISTRATION_RECORD **);
|
||||
|
||||
extern DWORD WINAPI BxInstallSEH(PEXCEPTION_HANDLER Handler);
|
||||
extern DWORD WINAPI BxUninstallSEH();
|
||||
|
||||
#endif
|
||||
271
idasdk76/dbg/bochs/ctrl/startup.idc
Normal file
271
idasdk76/dbg/bochs/ctrl/startup.idc
Normal file
@@ -0,0 +1,271 @@
|
||||
// This file contains bochs startup and exit procedures bochs_startup() and bochs_exit()
|
||||
// The former is called when the process starts
|
||||
// The latter is called when the process is about to exit
|
||||
// Both functions cause IDA debugger to suspend if they return a non zero value
|
||||
|
||||
// This section declares which DLLs will be available:
|
||||
// * Use the "stub" to mark a dll for stubbing
|
||||
|
||||
// * Use the "load" to mark a dll to be loaded as is
|
||||
// The "load" keyword has an additional attributes called "R0UserEntry"
|
||||
// This attribute is used to designate an exported function that will be called from ring0
|
||||
// Such a mechanism is useful to extend bochsys kernel or even replace it after it is loaded
|
||||
// One simple application is to modify the IDT and add R3 callable interrupts into your kernel
|
||||
|
||||
// Only lines containing three forward slashes ("/") are processed:
|
||||
|
||||
/// stub ntdll.dll
|
||||
/// stub kernel32.dll
|
||||
/// stub user32.dll
|
||||
/// stub shell32.dll
|
||||
/// stub shlwapi.dll
|
||||
/// stub urlmon.dll
|
||||
/// stub advapi32.dll
|
||||
/// stub mswsock.dll
|
||||
/// stub wininet.dll
|
||||
/// stub msvcrt.dll
|
||||
/// stub gdi32.dll
|
||||
/// stub ole32.dll
|
||||
/// stub wsock32.dll
|
||||
/// stub ws2_32.dll
|
||||
|
||||
// Define our own environment variables.
|
||||
// (add triple slashes to enable)
|
||||
// env path=c:\games\bin;d:\bin\asdf\
|
||||
// env userprofile=c:\games\
|
||||
|
||||
// Define your dependency mappings
|
||||
// (add triple slashes to enable the following lines)
|
||||
// map /home/guest/sys_dlls/user32.dll=d:\winnt\system32\user32.dll
|
||||
// map /home/guest/sys_dlls/shell32.dll=d:\winnt\system32\shell32.dll
|
||||
// map /home/guest/sys_dlls/kernel32.dll=d:\winnt\system32\kernel32.dll
|
||||
// map /home/guest/sys_dlls/shlwapi.dll=d:\winnt\system32\shlwapi.dll
|
||||
// map /home/guest/sys_dlls/urlmon.dll=d:\winnt\system32\urlmon.dll
|
||||
// map /home/guest/sys_dlls/mswsock.dll=d:\winnt\system32\mswsock.dll
|
||||
// map /home/guest/sys_dlls/wininet.dll=d:\winnt\system32\wininet.dll
|
||||
// map /home/guest/sys_dlls/msvcrt.dll=d:\winnt\system32\msvcrt.dll
|
||||
// map /home/guest/sys_dlls/gdi32.dll=d:\winnt\system32\gdi32.dll
|
||||
// map /home/guest/sys_dlls/ntdll.dll=d:\winnt\system32\ntdll.dll
|
||||
// map /home/guest/sys_dlls/advapi32.dll=d:\winnt\system32\advapi32.dll
|
||||
|
||||
// Define additional DLL path
|
||||
// (add triple slashes to enable the following lines)
|
||||
// path /home/guest/sys_dlls/=c:\winnt\system32\
|
||||
|
||||
// Bochs debugger plugin also allows you to specify the DLL path through the environment variable IDABXPATHMAP
|
||||
// (It is possible to specify more than one key/value pair by separating them with a semi-colon)
|
||||
// For example:
|
||||
// $ export IDABXPATHMAP="/home/guest/sys_dlls/=c:/winnt/system32/;/home/user2/other_dlls/=c:/program files/common files/3rd party/"
|
||||
// Similarly, one can specify the environment variables through the environment variable IDABXENVMAP
|
||||
// (it is possible to specify more than one key/value pair by separating them with a "++")
|
||||
// For example:
|
||||
// $ export IDABXENVMAP="TMP=c:/Users/Guest/Temp++SystemDrive=C:++windir=c:/windows/"
|
||||
//
|
||||
// Please note that the forward slashes "/" in the value part of the key/value pair will always be replaced with a backslash
|
||||
|
||||
//
|
||||
// The following are oneshot options. Once set they cannot be unset.
|
||||
// To define them simply preceed the option name with triple slashes.
|
||||
// - nosearchpath: Disables SearchPath() use for finding DLLs (this option is applicable on MS Windows only).
|
||||
// By turning this option, Bochs plugin will try to load DLLs from the current directory.
|
||||
// It useful for loading certain (old or new) versions of system DLLs instead of the ones currently installed
|
||||
// on the system.
|
||||
// - noactivationcontext: Disables the use of "Activation Context" (this option is applicable on MS Windows only).
|
||||
//
|
||||
|
||||
//
|
||||
// For loading drivers, you may uncomment the following stub definition(s):
|
||||
//
|
||||
// stub ntoskrnl.exe
|
||||
|
||||
// For example: to load a dll as is: load mydll.dll
|
||||
// For example: to load a dll as is and specify a user R0 entry: load mydll.dll R0UserEntry=MyExportedFunc
|
||||
|
||||
#include <idc.idc>
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// IDC scripts that will be available during the debugging session
|
||||
|
||||
// MS Windows related functions
|
||||
// ------------------------------
|
||||
// BochsVirtXXXX functions allocate/free virtual memory in the emulated session.
|
||||
// The "size" parameter is always rounded to a page.
|
||||
//
|
||||
|
||||
//
|
||||
// Allocate virtual memory
|
||||
// This function emulates the VirtualAlloc function from MS Windows
|
||||
// addr - the preferred address for the allocation. Zero means no preference
|
||||
// size - size of the block to allocate
|
||||
// writable - should be allocated memory be wrtiable?
|
||||
// Currently only read/write page protections are supported
|
||||
// Returns: the address of the allocated block or zero
|
||||
//
|
||||
// long BochsVirtAlloc(long addr, long size, bool writable);
|
||||
//
|
||||
|
||||
//
|
||||
// Change protection of memory page
|
||||
// This function emulates the VirtualProtect function from MS Windows
|
||||
// addr - the desired address to change protection.
|
||||
// size - size of the block
|
||||
// attr - the new page attribute:
|
||||
// 0 = Read only
|
||||
// 1 = Read/Write
|
||||
// Returns: the old protection value or -1 on failure
|
||||
//
|
||||
// long BochsVirtProtect(long addr, long size, long attr);
|
||||
//
|
||||
|
||||
|
||||
//
|
||||
// Free virtual memory
|
||||
// This function emulates the VirtualFree function from MS Windows
|
||||
// addr - the address of previously allocated memory block
|
||||
// size - the size of the block. If zero, then the entire block at addr
|
||||
// will be freed.
|
||||
// Returns: success
|
||||
//
|
||||
// bool BochsVirtFree(long addr, long size);
|
||||
//
|
||||
|
||||
//
|
||||
// Returns the base address of a given module name
|
||||
// module_name - The name of the module.
|
||||
// The name can be full path or filename with extension, or simply filename without extension
|
||||
// Returns: zero if it fails
|
||||
//
|
||||
// long BochsGetModuleHandle(string module_name);
|
||||
//
|
||||
|
||||
//
|
||||
// Returns a procedure's address
|
||||
// This function calls the internal GetProcAddress to resolve function addresses.
|
||||
// hmod - the module handle
|
||||
// procname - name of the procedure inside the module
|
||||
// Returns: the zero if procedure not found, otherwise the address
|
||||
//
|
||||
// long BochsGetProcAddress(long hmod, string procname);
|
||||
//
|
||||
|
||||
//
|
||||
// Returns the module name given its base address
|
||||
// module_handle: the base address of a given module
|
||||
// Returns: empty string if module was not found
|
||||
//
|
||||
// string BochsGetModuleFileName(long module_handle)
|
||||
//
|
||||
|
||||
//
|
||||
// Returns the command line value passed to the application
|
||||
//
|
||||
// string BochsGetCommandLine()
|
||||
//
|
||||
|
||||
//
|
||||
// Set last error code
|
||||
// This function emulates the SetLastError function from MS Windows.
|
||||
// It writes the specified code to TIB.
|
||||
// error_code - new error code to set
|
||||
// Returns: success
|
||||
//
|
||||
// success BochsWin32SetLastError(long error_num);
|
||||
//
|
||||
|
||||
//
|
||||
// Other functions:
|
||||
// -------------------
|
||||
//
|
||||
|
||||
//
|
||||
// Sends arbitrary commands to the internal debugger of BOCHS. The output is returned as a string.
|
||||
// This is useful for example to send some commands to BOCHS that are not exposed via the GUI of IDA.
|
||||
// command: the command you want to send
|
||||
// Returns: output string or empty string if it failed
|
||||
//
|
||||
// string send_dbg_command(string command)
|
||||
//
|
||||
|
||||
//
|
||||
// Retrieves the parameter value passed to an IDC script that is implementing a given API.
|
||||
// This same function can be implemented with this expression: #define BX_GETPARAM(n) get_wide_dword(esp+4*(n+1))
|
||||
// arg_num: the argument number (starting by one)
|
||||
// Returns: the value or zero in case it fails
|
||||
//
|
||||
// string BochsGetParam(long arg_num)
|
||||
//
|
||||
|
||||
//
|
||||
// Calls a function inside Bochs
|
||||
// This function can call functions inside Bochs. Very useful if you want to call
|
||||
// functions in the user's code. The arguments are pushed from right to left.
|
||||
// func_ptr - The address of the function to be called
|
||||
// argN - a set of dwords that contain the arguments.
|
||||
// Arguments can be numbers or pointers
|
||||
// Returns: success
|
||||
//
|
||||
// long BochsCall(long func_ptr, arg1, arg2, ...);
|
||||
//
|
||||
|
||||
|
||||
//
|
||||
// These functions will return the total physical memory amount and the remaining free
|
||||
// memory in bytes.
|
||||
// Returns: memory size in bytes
|
||||
//
|
||||
// long BochsGetFreeMem()
|
||||
// long BochsGetMaxMem()
|
||||
//
|
||||
|
||||
// ----------------------------------------------------------------------------
|
||||
static BochsPatchDbgDword(ea, dv)
|
||||
{
|
||||
auto i;
|
||||
for (i=0;i<4;i++)
|
||||
{
|
||||
patch_dbg_byte(ea, dv & 0xFF);
|
||||
ea = ea + 1;
|
||||
dv = dv >> 8;
|
||||
}
|
||||
}
|
||||
|
||||
// ----------------------------------------------------------------------------
|
||||
// Utility function that can be used as a conditional breakpoint condition
|
||||
// in order to skip to the next instruction w/o suspending IDA
|
||||
static bochs_skipnext()
|
||||
{
|
||||
Eip = next_head(eip, BADADDR);
|
||||
return 0;
|
||||
}
|
||||
|
||||
// ----------------------------------------------------------------------------
|
||||
// Utility function that can be used as a conditional breakpoint condition
|
||||
// in order to execute the contents of the comments at the bp location
|
||||
static bochs_execidc_comments()
|
||||
{
|
||||
exec_idc(Comment(eip));
|
||||
return 0;
|
||||
}
|
||||
|
||||
// ----------------------------------------------------------------------------
|
||||
// Utility function used to dump registers. The output can be used as a comment
|
||||
// with the bochs_execidc_comments() bp condition
|
||||
static bochs_dump_registers()
|
||||
{
|
||||
msg("eax=0x%x;ebx=0x%x;ecx=0x%x;edx=0x%x;esi=0x%x;edi=0x%x;ebp=0x%x;", eax, ebx, ecx, edx, esi, edi, ebp);
|
||||
}
|
||||
|
||||
// ----------------------------------------------------------------------------
|
||||
static bochs_startup()
|
||||
{
|
||||
msg("Bochs debugger has been initialized.\n");
|
||||
return 0;
|
||||
}
|
||||
|
||||
// ----------------------------------------------------------------------------
|
||||
static bochs_exit()
|
||||
{
|
||||
msg("Bochs debugger has been terminated.\n");
|
||||
return 0;
|
||||
}
|
||||
|
||||
2
idasdk76/dbg/bochs/sdk/api_user32.idc
Normal file
2
idasdk76/dbg/bochs/sdk/api_user32.idc
Normal file
@@ -0,0 +1,2 @@
|
||||
|
||||
///func=MessageBoxA entry=bxtest.MyMessageBox
|
||||
89
idasdk76/dbg/bochs/sdk/bxtest.c
Normal file
89
idasdk76/dbg/bochs/sdk/bxtest.c
Normal file
@@ -0,0 +1,89 @@
|
||||
#include "bochsys.h"
|
||||
#include <windows.h>
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// dummy entry point so that linker does not use entrypoints from CRT
|
||||
DWORD WINAPI Entry(DWORD a, DWORD b, DWORD c)
|
||||
{
|
||||
return 0;
|
||||
}
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// This function will be called by bochsys.dll from R0 before switching to R3
|
||||
// This is even called before TLS callbacks
|
||||
void WINAPI MyR0Entry(VOID)
|
||||
{
|
||||
__asm
|
||||
{
|
||||
nop
|
||||
mov dx, 0378h
|
||||
in eax, dx
|
||||
nop
|
||||
nop
|
||||
}
|
||||
}
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
DWORD MyHandler(
|
||||
PEXCEPTION_RECORD rec,
|
||||
struct _EXCEPTION_REGISTRATION_RECORD *reg,
|
||||
PCONTEXT ctx,
|
||||
struct _EXCEPTION_REGISTRATION_RECORD **reg2)
|
||||
{
|
||||
ctx->Eip += 2;
|
||||
return ExceptionContinueExecution;
|
||||
}
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
void BuggyFunction()
|
||||
{
|
||||
BxInstallSEH(MyHandler);
|
||||
__asm
|
||||
{
|
||||
xor eax, eax
|
||||
mov eax, [eax]
|
||||
}
|
||||
BxUninstallSEH();
|
||||
}
|
||||
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// In this function, BxXXXXXX functions are used from the bochsys library
|
||||
int __stdcall MyMessageBox(
|
||||
HWND hWnd,
|
||||
LPCTSTR lpText,
|
||||
LPCTSTR lpCaption,
|
||||
UINT uType)
|
||||
{
|
||||
char *p;
|
||||
int i;
|
||||
|
||||
// Allocate memory
|
||||
p = BxVirtualAlloc(0, 0x1000, MEM_COMMIT, PAGE_READWRITE);
|
||||
|
||||
// Fill the memory
|
||||
for (i=1;i<=0x1000;i++)
|
||||
*p++ = i & 0xFF;
|
||||
|
||||
// Resolve an entry and call it
|
||||
(VOID (__stdcall *)(int, int)) BxGetProcAddress(BxLoadLibraryA("kernel32.dll"), "Beep")(5, 1);
|
||||
|
||||
// Call a function that might cause an exception
|
||||
BuggyFunction();
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// In this function we import from user32 and kernel32
|
||||
// (because VirtualAlloc->BxVirtualAlloc and MessageBoxA->bxtest.MyMessageBox are redirected and implemented)
|
||||
int __stdcall MyRoutine(
|
||||
HWND hWnd,
|
||||
LPCTSTR lpText,
|
||||
LPCTSTR lpCaption,
|
||||
UINT uType)
|
||||
{
|
||||
VirtualAlloc(0, 0x1000, MEM_COMMIT, PAGE_READWRITE);
|
||||
MessageBoxA(0, "hey", "info", MB_OK);
|
||||
return 0;
|
||||
}
|
||||
4
idasdk76/dbg/bochs/sdk/bxtest.def
Normal file
4
idasdk76/dbg/bochs/sdk/bxtest.def
Normal file
@@ -0,0 +1,4 @@
|
||||
EXPORTS
|
||||
MyMessageBox
|
||||
MyRoutine
|
||||
MyR0Entry
|
||||
BIN
idasdk76/dbg/bochs/sdk/bxtest.dll
Normal file
BIN
idasdk76/dbg/bochs/sdk/bxtest.dll
Normal file
Binary file not shown.
11
idasdk76/dbg/bochs/sdk/compile.bat
Normal file
11
idasdk76/dbg/bochs/sdk/compile.bat
Normal file
@@ -0,0 +1,11 @@
|
||||
@echo off
|
||||
"C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\bin\cl.exe" -c /Zl /Gd /Tc bxtest.c "/IC:/Program Files (x86)/Windows Kits/8.1/Include/um" "/IC:/Program Files (x86)/Windows Kits/8.1/Include/shared" "/IC:/PROGRA~2/WI3CF2~1/10/Include/10.0.10150.0/ucrt" /I"C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\include"
|
||||
if errorlevel 1 goto end
|
||||
"C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\bin\link.exe" bxtest.obj bochsys.lib kernel32.lib user32.lib /OUT:bxtest.dll /ENTRY:Entry /def:bxtest.def /DRIVER /SAFESEH:NO /NODEFAULTLIB /SUBSYSTEM:WINDOWS /LIBPATH:"C:\Program Files\Microsoft Visual Studio 14.0\VC\Lib" /LIBPATH:"C:/Program Files (x86)/Windows Kits/8.1/Lib/winv6.3/um/x86"
|
||||
if errorlevel 1 goto end
|
||||
|
||||
if exist bxtest.obj del bxtest.obj
|
||||
if exist bxtest.exp del bxtest.exp
|
||||
if exist bxtest.lib del bxtest.lib
|
||||
|
||||
:end
|
||||
90
idasdk76/dbg/bochs/sdk/readme.txt
Normal file
90
idasdk76/dbg/bochs/sdk/readme.txt
Normal file
@@ -0,0 +1,90 @@
|
||||
|
||||
Custom DLLs for emulated MS Windows environment
|
||||
-----------------------------------------------
|
||||
|
||||
This directory contains files that demonstrate how to build a custom DLL
|
||||
for the PE loader of the Bochs debugger.
|
||||
|
||||
compile.bat shows how to build a custom DLL with the MS compiler/linker.
|
||||
The general rule is not to link with runtime libraries, but linking with
|
||||
import libraries is ok.
|
||||
|
||||
"bxtest.c" demonstrates how to call functions in bochsys.dll.
|
||||
"bochsys.h" has the list of functions that can be called from custom DLLs.
|
||||
"bochsys.lib" is the corresponding import library
|
||||
|
||||
Custom DLLs must be mentioned in plugins\bochs\startup.idc.
|
||||
For that please add a line like this:
|
||||
|
||||
/// load bxtest.dll
|
||||
|
||||
This will cause the DLL to be present in the memory space of the debugged process.
|
||||
For the custom DLL to be useful, its exported functions should be connected
|
||||
to API function names. For example, the following line redirects MessageBoxA
|
||||
to bxtest.MyMessageBox:
|
||||
|
||||
/// func=MessageBoxA entry=bxtest.MyMessageBox
|
||||
|
||||
The exact format of the startup.idc file is explained in its header.
|
||||
|
||||
On the other hand, it is also possible to write a custom DLL that replaces system
|
||||
DLLs like kernel32.dll or user32.dll.
|
||||
|
||||
|
||||
The "load" command has an additional parameter "R0UserEntry=MyR0Entry" used as:
|
||||
///load bxtest.dll R0UserEntry=MyR0Entry
|
||||
|
||||
Which means that bxtest.dll should be loaded into the process memory and
|
||||
that this DLL has an exported entry that should be called by bochsys from ring0.
|
||||
Such a facility is ideal if you're looking to replace or enhance bochsys's kernel.
|
||||
|
||||
To test how MessageBoxA is redirected to MyMessageBox, please follow these
|
||||
steps:
|
||||
|
||||
- compile and link bxtest.dll with compile.bat
|
||||
(we provide ready-to-use bxtest.dll for your convenience, so you
|
||||
skip this step)
|
||||
|
||||
- add two lines mentioned above to startup.idc and api_user32.idc respectively
|
||||
|
||||
- load test.pe into IDA and select Bochs debugger
|
||||
|
||||
- run it and single step into the MessageBoxA function
|
||||
|
||||
With any questions, please contact us at support@hex-rays.com
|
||||
|
||||
|
||||
Bochs plugin debugger extensions
|
||||
-----------------------------------
|
||||
|
||||
Bochs extensions allow for accessing extended debugger functionality.
|
||||
|
||||
To get and use the extensions, query the currently loaded debugger using
|
||||
get_debmod_extensions(). Usually it returns a pointer to a structure with
|
||||
pointers to functions. Please follow this example:
|
||||
|
||||
#include "bochsext.h"
|
||||
|
||||
void idaapi run(int)
|
||||
{
|
||||
if ( dbg == NULL )
|
||||
{
|
||||
msg("dbg == NULL\n");
|
||||
return;
|
||||
}
|
||||
const bochsext_t *ext = (const bochsext_t *)dbg->get_debmod_extensions();
|
||||
if ( ext == NULL )
|
||||
{
|
||||
msg("no debugger extensions!\n");
|
||||
return;
|
||||
}
|
||||
|
||||
// dump 10 bytes from physical memory at 0x0
|
||||
qstring out;
|
||||
if ( !ext->send_command("xp /10mb 0x0\r\n", &out) )
|
||||
{
|
||||
msg("failed to send command!\n");
|
||||
return;
|
||||
}
|
||||
msg("->result=%s\n", out.c_str());
|
||||
}
|
||||
36
idasdk76/dbg/bochs/sdk/test.asm
Normal file
36
idasdk76/dbg/bochs/sdk/test.asm
Normal file
@@ -0,0 +1,36 @@
|
||||
; #########################################################################
|
||||
|
||||
.386
|
||||
.model flat, stdcall
|
||||
option casemap :none ; case sensitive
|
||||
|
||||
; #########################################################################
|
||||
|
||||
include d:\masm32\include\windows.inc
|
||||
include d:\masm32\include\user32.inc
|
||||
include d:\masm32\include\kernel32.inc
|
||||
|
||||
includelib d:\masm32\lib\user32.lib
|
||||
includelib d:\masm32\lib\kernel32.lib
|
||||
|
||||
; #########################################################################
|
||||
; --------------------------------------------------------
|
||||
.data
|
||||
szDlgTitle db "Minimum MASM",0
|
||||
szMsg db " --- Assembler Pure and Simple --- ",0
|
||||
.code
|
||||
start:
|
||||
; --------------------------------------------------------
|
||||
; script
|
||||
push MB_OK
|
||||
push offset szDlgTitle
|
||||
push offset szMsg
|
||||
push 0
|
||||
call MessageBox
|
||||
|
||||
; --------------------------------------------------------
|
||||
; idacall
|
||||
push -2
|
||||
call ExitProcess
|
||||
|
||||
end start
|
||||
BIN
idasdk76/dbg/bochs/sdk/test.pe
Normal file
BIN
idasdk76/dbg/bochs/sdk/test.pe
Normal file
Binary file not shown.
Reference in New Issue
Block a user