From e5f3e22bd784b4c6bab7a18fbfcc276e4189f678 Mon Sep 17 00:00:00 2001 From: Andrew Haberlandt Date: Wed, 8 May 2024 09:12:29 +0000 Subject: [PATCH] example: ltrace --- examples/ltrace.py | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 examples/ltrace.py diff --git a/examples/ltrace.py b/examples/ltrace.py new file mode 100644 index 0000000..d394962 --- /dev/null +++ b/examples/ltrace.py @@ -0,0 +1,40 @@ +from pyda import * +from pwnlib.elf.elf import ELF +from pwnlib.util.packing import u64 +import string +import sys + +p = process() + +e = ELF(p.exe_path) +e.address = p.maps[p.exe_path].base + +plt_map = { e.plt[x]: x for x in e.plt } + +def guess_arg(x): + printable_chars = bytes(string.printable, 'ascii') + + # Is pointer? + if x > 0x100000000: + try: + data = p.read(x, 0x20) + if all([c in printable_chars for c in data[:4]]): + return str(data[:data.index(0)]) + except: + pass + + return hex(x) + +def lib_hook(p): + name = plt_map[p.regs.rip] + print(f"{name}(" + ", ".join([ + f"rdi={guess_arg(p.regs.rdi)}", + f"rsi={guess_arg(p.regs.rsi)}", + f"rdx={guess_arg(p.regs.rdx)}", + f"rcx={guess_arg(p.regs.rcx)}", + ]) + ")") + +for x in e.plt: + p.hook(e.plt[x], lib_hook) + +p.run() \ No newline at end of file