Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 1 | #!/usr/bin/env python |
| 2 | |
| 3 | # Capstone Python bindings, by Nguyen Anh Quynnh <aquynh@gmail.com> |
| 4 | |
Nguyen Anh Quynh | 749046b | 2014-04-12 01:15:10 +0800 | [diff] [blame] | 5 | from __future__ import print_function |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 6 | from capstone import * |
| 7 | import binascii |
Nguyen Anh Quynh | 03d1e1f | 2015-04-27 11:51:48 +0800 | [diff] [blame] | 8 | from xprint import to_hex |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 9 | |
Nguyen Anh Quynh | 749046b | 2014-04-12 01:15:10 +0800 | [diff] [blame] | 10 | |
| 11 | X86_CODE32 = b"\x8d\x4c\x32\x08\x01\xd8\x81\xc6\x34\x12\x00\x00\x00\x91\x92" |
| 12 | RANDOM_CODE = b"\xed\x00\x00\x00\x00\x1a\x5a\x0f\x1f\xff\xc2\x09\x80\x00\x00\x00\x07\xf7\xeb\x2a\xff\xff\x7f\x57\xe3\x01\xff\xff\x7f\x57\xeb\x00\xf0\x00\x00\x24\xb2\x4f\x00\x78" |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 13 | |
| 14 | all_tests = ( |
Niels Boehm | 32b6346 | 2016-06-13 12:25:24 +0200 | [diff] [blame^] | 15 | (CS_ARCH_X86, CS_MODE_32, X86_CODE32, "X86 32 (Intel syntax)", None), |
| 16 | (CS_ARCH_ARM, CS_MODE_ARM, RANDOM_CODE, "Arm", None), |
Nguyen Anh Quynh | 749046b | 2014-04-12 01:15:10 +0800 | [diff] [blame] | 17 | ) |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 18 | |
| 19 | |
Nguyen Anh Quynh | 301d740 | 2014-04-10 22:34:27 +0800 | [diff] [blame] | 20 | # Sample callback for SKIPDATA option |
Nguyen Anh Quynh | cbc7dd9 | 2014-07-10 15:57:42 +0800 | [diff] [blame] | 21 | def testcb(buffer, size, offset, userdata): |
Nguyen Anh Quynh | 301d740 | 2014-04-10 22:34:27 +0800 | [diff] [blame] | 22 | # always skip 2 bytes of data |
| 23 | return 2 |
| 24 | |
| 25 | |
Nguyen Anh Quynh | 749046b | 2014-04-12 01:15:10 +0800 | [diff] [blame] | 26 | # ## Test class Cs |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 27 | def test_class(): |
| 28 | for (arch, mode, code, comment, syntax) in all_tests: |
| 29 | print('*' * 16) |
| 30 | print("Platform: %s" %comment) |
| 31 | print("Code: %s" % to_hex(code)) |
| 32 | print("Disasm:") |
| 33 | |
| 34 | try: |
| 35 | md = Cs(arch, mode) |
| 36 | |
Niels Boehm | 32b6346 | 2016-06-13 12:25:24 +0200 | [diff] [blame^] | 37 | if syntax is not None: |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 38 | md.syntax = syntax |
| 39 | |
| 40 | md.skipdata = True |
Nguyen Anh Quynh | 301d740 | 2014-04-10 22:34:27 +0800 | [diff] [blame] | 41 | |
Nguyen Anh Quynh | b64d1cf | 2014-04-10 23:05:28 +0800 | [diff] [blame] | 42 | # Default "data" instruction's name is ".byte". To rename it to "db", just uncomment |
| 43 | # the code below. |
| 44 | # md.skipdata_setup = ("db", None, None) |
| 45 | # NOTE: This example ignores SKIPDATA's callback (first None) & user_data (second None) |
| 46 | |
| 47 | # To customize the SKIPDATA callback, uncomment the line below. |
Nguyen Anh Quynh | 301d740 | 2014-04-10 22:34:27 +0800 | [diff] [blame] | 48 | # md.skipdata_setup = (".db", CS_SKIPDATA_CALLBACK(testcb), None) |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 49 | |
| 50 | for insn in md.disasm(code, 0x1000): |
| 51 | #bytes = binascii.hexlify(insn.bytes) |
| 52 | #print("0x%x:\t%s\t%s\t// hex-code: %s" %(insn.address, insn.mnemonic, insn.op_str, bytes)) |
Nguyen Anh Quynh | 749046b | 2014-04-12 01:15:10 +0800 | [diff] [blame] | 53 | print("0x%x:\t%s\t%s" % (insn.address, insn.mnemonic, insn.op_str)) |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 54 | |
| 55 | print("0x%x:" % (insn.address + insn.size)) |
| 56 | print |
| 57 | except CsError as e: |
Nguyen Anh Quynh | 749046b | 2014-04-12 01:15:10 +0800 | [diff] [blame] | 58 | print("ERROR: %s" % e) |
Nguyen Anh Quynh | f0c577f | 2014-04-10 16:09:15 +0800 | [diff] [blame] | 59 | |
| 60 | |
Nguyen Anh Quynh | 749046b | 2014-04-12 01:15:10 +0800 | [diff] [blame] | 61 | if __name__ == '__main__': |
| 62 | test_class() |