class Rex::MachScan::Scanner::PopPopRetScanner

Public Instance Methods

config(param) click to toggle source
# File lib/rex/machscan/scanner.rb, line 145
def config(param)
  pops = _build_byte_list(0x58, (0 .. 7).to_a - [4]) # we don't want pop esp's...
  self.regex = Regexp.new("[#{pops}][#{pops}](\xc3|\xc2..)", nil, 'n')
end
scan_segment(segment, param={}) click to toggle source
# File lib/rex/machscan/scanner.rb, line 150
def scan_segment(segment, param={})
  base_addr = segment.vmaddr
  segment_offset = segment.fileoff
  offset = segment_offset

  hits = []

  while offset < segment.fileoff + segment.filesize && (offset = mach.index(regex, offset)) != nil

    vaddr = base_addr + (offset - segment_offset)
    message = ''

    pops = mach.read(offset, 2)
    reg1 = Rex::Arch::X86.reg_name32(pops[0,1].unpack("C*")[0] & 0x7)
    reg2 = Rex::Arch::X86.reg_name32(pops[1,1].unpack("C*")[0] & 0x7)

    message = "pop #{reg1}; pop #{reg2}; "

    retsize = _ret_size(offset+2)
    message += _parse_ret(mach.read(offset+2, retsize))

    offset += 2 + retsize

    hits << [ vaddr, message ]
  end

  return hits
end