class Rex::ElfScan::Scanner::PopPopRetScanner
Public Instance Methods
config(param)
click to toggle source
# File lib/rex/elfscan/scanner.rb, line 156 def config(param) pops = _build_byte_list(0x58, (0 .. 7).to_a - [4]) # we don't want pop esp's... self.regex = Regexp.new("[#{pops}][#{pops}](\xc3|\xc2..)", nil, 'n') end
scan_segment(program_header, param={})
click to toggle source
# File lib/rex/elfscan/scanner.rb, line 161 def scan_segment(program_header, param={}) offset = program_header.p_offset hits = [] while offset < program_header.p_offset + program_header.p_filesz && (offset = elf.index(regex, offset)) != nil rva = elf.offset_to_rva(offset) message = '' pops = elf.read(offset, 2) reg1 = Rex::Arch::X86.reg_name32(pops[0,1].unpack('C*')[0] & 0x7) reg2 = Rex::Arch::X86.reg_name32(pops[1,1].unpack('C*')[0] & 0x7) message = "pop #{reg1}; pop #{reg2}; " retsize = _ret_size(offset+2) message += _parse_ret(elf.read(offset+2, retsize)) offset += 2 + retsize hits << [ rva, message ] end return hits end