update to ida 7.6, add builds
This commit is contained in:
2
idasdk76/dbg/bochs/sdk/api_user32.idc
Normal file
2
idasdk76/dbg/bochs/sdk/api_user32.idc
Normal file
@@ -0,0 +1,2 @@
|
||||
|
||||
///func=MessageBoxA entry=bxtest.MyMessageBox
|
||||
89
idasdk76/dbg/bochs/sdk/bxtest.c
Normal file
89
idasdk76/dbg/bochs/sdk/bxtest.c
Normal file
@@ -0,0 +1,89 @@
|
||||
#include "bochsys.h"
|
||||
#include <windows.h>
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// dummy entry point so that linker does not use entrypoints from CRT
|
||||
DWORD WINAPI Entry(DWORD a, DWORD b, DWORD c)
|
||||
{
|
||||
return 0;
|
||||
}
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// This function will be called by bochsys.dll from R0 before switching to R3
|
||||
// This is even called before TLS callbacks
|
||||
void WINAPI MyR0Entry(VOID)
|
||||
{
|
||||
__asm
|
||||
{
|
||||
nop
|
||||
mov dx, 0378h
|
||||
in eax, dx
|
||||
nop
|
||||
nop
|
||||
}
|
||||
}
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
DWORD MyHandler(
|
||||
PEXCEPTION_RECORD rec,
|
||||
struct _EXCEPTION_REGISTRATION_RECORD *reg,
|
||||
PCONTEXT ctx,
|
||||
struct _EXCEPTION_REGISTRATION_RECORD **reg2)
|
||||
{
|
||||
ctx->Eip += 2;
|
||||
return ExceptionContinueExecution;
|
||||
}
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
void BuggyFunction()
|
||||
{
|
||||
BxInstallSEH(MyHandler);
|
||||
__asm
|
||||
{
|
||||
xor eax, eax
|
||||
mov eax, [eax]
|
||||
}
|
||||
BxUninstallSEH();
|
||||
}
|
||||
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// In this function, BxXXXXXX functions are used from the bochsys library
|
||||
int __stdcall MyMessageBox(
|
||||
HWND hWnd,
|
||||
LPCTSTR lpText,
|
||||
LPCTSTR lpCaption,
|
||||
UINT uType)
|
||||
{
|
||||
char *p;
|
||||
int i;
|
||||
|
||||
// Allocate memory
|
||||
p = BxVirtualAlloc(0, 0x1000, MEM_COMMIT, PAGE_READWRITE);
|
||||
|
||||
// Fill the memory
|
||||
for (i=1;i<=0x1000;i++)
|
||||
*p++ = i & 0xFF;
|
||||
|
||||
// Resolve an entry and call it
|
||||
(VOID (__stdcall *)(int, int)) BxGetProcAddress(BxLoadLibraryA("kernel32.dll"), "Beep")(5, 1);
|
||||
|
||||
// Call a function that might cause an exception
|
||||
BuggyFunction();
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
//--------------------------------------------------------------------------
|
||||
// In this function we import from user32 and kernel32
|
||||
// (because VirtualAlloc->BxVirtualAlloc and MessageBoxA->bxtest.MyMessageBox are redirected and implemented)
|
||||
int __stdcall MyRoutine(
|
||||
HWND hWnd,
|
||||
LPCTSTR lpText,
|
||||
LPCTSTR lpCaption,
|
||||
UINT uType)
|
||||
{
|
||||
VirtualAlloc(0, 0x1000, MEM_COMMIT, PAGE_READWRITE);
|
||||
MessageBoxA(0, "hey", "info", MB_OK);
|
||||
return 0;
|
||||
}
|
||||
4
idasdk76/dbg/bochs/sdk/bxtest.def
Normal file
4
idasdk76/dbg/bochs/sdk/bxtest.def
Normal file
@@ -0,0 +1,4 @@
|
||||
EXPORTS
|
||||
MyMessageBox
|
||||
MyRoutine
|
||||
MyR0Entry
|
||||
BIN
idasdk76/dbg/bochs/sdk/bxtest.dll
Normal file
BIN
idasdk76/dbg/bochs/sdk/bxtest.dll
Normal file
Binary file not shown.
11
idasdk76/dbg/bochs/sdk/compile.bat
Normal file
11
idasdk76/dbg/bochs/sdk/compile.bat
Normal file
@@ -0,0 +1,11 @@
|
||||
@echo off
|
||||
"C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\bin\cl.exe" -c /Zl /Gd /Tc bxtest.c "/IC:/Program Files (x86)/Windows Kits/8.1/Include/um" "/IC:/Program Files (x86)/Windows Kits/8.1/Include/shared" "/IC:/PROGRA~2/WI3CF2~1/10/Include/10.0.10150.0/ucrt" /I"C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\include"
|
||||
if errorlevel 1 goto end
|
||||
"C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\bin\link.exe" bxtest.obj bochsys.lib kernel32.lib user32.lib /OUT:bxtest.dll /ENTRY:Entry /def:bxtest.def /DRIVER /SAFESEH:NO /NODEFAULTLIB /SUBSYSTEM:WINDOWS /LIBPATH:"C:\Program Files\Microsoft Visual Studio 14.0\VC\Lib" /LIBPATH:"C:/Program Files (x86)/Windows Kits/8.1/Lib/winv6.3/um/x86"
|
||||
if errorlevel 1 goto end
|
||||
|
||||
if exist bxtest.obj del bxtest.obj
|
||||
if exist bxtest.exp del bxtest.exp
|
||||
if exist bxtest.lib del bxtest.lib
|
||||
|
||||
:end
|
||||
90
idasdk76/dbg/bochs/sdk/readme.txt
Normal file
90
idasdk76/dbg/bochs/sdk/readme.txt
Normal file
@@ -0,0 +1,90 @@
|
||||
|
||||
Custom DLLs for emulated MS Windows environment
|
||||
-----------------------------------------------
|
||||
|
||||
This directory contains files that demonstrate how to build a custom DLL
|
||||
for the PE loader of the Bochs debugger.
|
||||
|
||||
compile.bat shows how to build a custom DLL with the MS compiler/linker.
|
||||
The general rule is not to link with runtime libraries, but linking with
|
||||
import libraries is ok.
|
||||
|
||||
"bxtest.c" demonstrates how to call functions in bochsys.dll.
|
||||
"bochsys.h" has the list of functions that can be called from custom DLLs.
|
||||
"bochsys.lib" is the corresponding import library
|
||||
|
||||
Custom DLLs must be mentioned in plugins\bochs\startup.idc.
|
||||
For that please add a line like this:
|
||||
|
||||
/// load bxtest.dll
|
||||
|
||||
This will cause the DLL to be present in the memory space of the debugged process.
|
||||
For the custom DLL to be useful, its exported functions should be connected
|
||||
to API function names. For example, the following line redirects MessageBoxA
|
||||
to bxtest.MyMessageBox:
|
||||
|
||||
/// func=MessageBoxA entry=bxtest.MyMessageBox
|
||||
|
||||
The exact format of the startup.idc file is explained in its header.
|
||||
|
||||
On the other hand, it is also possible to write a custom DLL that replaces system
|
||||
DLLs like kernel32.dll or user32.dll.
|
||||
|
||||
|
||||
The "load" command has an additional parameter "R0UserEntry=MyR0Entry" used as:
|
||||
///load bxtest.dll R0UserEntry=MyR0Entry
|
||||
|
||||
Which means that bxtest.dll should be loaded into the process memory and
|
||||
that this DLL has an exported entry that should be called by bochsys from ring0.
|
||||
Such a facility is ideal if you're looking to replace or enhance bochsys's kernel.
|
||||
|
||||
To test how MessageBoxA is redirected to MyMessageBox, please follow these
|
||||
steps:
|
||||
|
||||
- compile and link bxtest.dll with compile.bat
|
||||
(we provide ready-to-use bxtest.dll for your convenience, so you
|
||||
skip this step)
|
||||
|
||||
- add two lines mentioned above to startup.idc and api_user32.idc respectively
|
||||
|
||||
- load test.pe into IDA and select Bochs debugger
|
||||
|
||||
- run it and single step into the MessageBoxA function
|
||||
|
||||
With any questions, please contact us at support@hex-rays.com
|
||||
|
||||
|
||||
Bochs plugin debugger extensions
|
||||
-----------------------------------
|
||||
|
||||
Bochs extensions allow for accessing extended debugger functionality.
|
||||
|
||||
To get and use the extensions, query the currently loaded debugger using
|
||||
get_debmod_extensions(). Usually it returns a pointer to a structure with
|
||||
pointers to functions. Please follow this example:
|
||||
|
||||
#include "bochsext.h"
|
||||
|
||||
void idaapi run(int)
|
||||
{
|
||||
if ( dbg == NULL )
|
||||
{
|
||||
msg("dbg == NULL\n");
|
||||
return;
|
||||
}
|
||||
const bochsext_t *ext = (const bochsext_t *)dbg->get_debmod_extensions();
|
||||
if ( ext == NULL )
|
||||
{
|
||||
msg("no debugger extensions!\n");
|
||||
return;
|
||||
}
|
||||
|
||||
// dump 10 bytes from physical memory at 0x0
|
||||
qstring out;
|
||||
if ( !ext->send_command("xp /10mb 0x0\r\n", &out) )
|
||||
{
|
||||
msg("failed to send command!\n");
|
||||
return;
|
||||
}
|
||||
msg("->result=%s\n", out.c_str());
|
||||
}
|
||||
36
idasdk76/dbg/bochs/sdk/test.asm
Normal file
36
idasdk76/dbg/bochs/sdk/test.asm
Normal file
@@ -0,0 +1,36 @@
|
||||
; #########################################################################
|
||||
|
||||
.386
|
||||
.model flat, stdcall
|
||||
option casemap :none ; case sensitive
|
||||
|
||||
; #########################################################################
|
||||
|
||||
include d:\masm32\include\windows.inc
|
||||
include d:\masm32\include\user32.inc
|
||||
include d:\masm32\include\kernel32.inc
|
||||
|
||||
includelib d:\masm32\lib\user32.lib
|
||||
includelib d:\masm32\lib\kernel32.lib
|
||||
|
||||
; #########################################################################
|
||||
; --------------------------------------------------------
|
||||
.data
|
||||
szDlgTitle db "Minimum MASM",0
|
||||
szMsg db " --- Assembler Pure and Simple --- ",0
|
||||
.code
|
||||
start:
|
||||
; --------------------------------------------------------
|
||||
; script
|
||||
push MB_OK
|
||||
push offset szDlgTitle
|
||||
push offset szMsg
|
||||
push 0
|
||||
call MessageBox
|
||||
|
||||
; --------------------------------------------------------
|
||||
; idacall
|
||||
push -2
|
||||
call ExitProcess
|
||||
|
||||
end start
|
||||
BIN
idasdk76/dbg/bochs/sdk/test.pe
Normal file
BIN
idasdk76/dbg/bochs/sdk/test.pe
Normal file
Binary file not shown.
Reference in New Issue
Block a user