1*9a0e4156SSadaf Ebrahimi#!/usr/bin/env python 2*9a0e4156SSadaf Ebrahimi 3*9a0e4156SSadaf Ebrahimi# Capstone Python bindings, by Nguyen Anh Quynnh <[email protected]> 4*9a0e4156SSadaf Ebrahimi 5*9a0e4156SSadaf Ebrahimifrom __future__ import print_function 6*9a0e4156SSadaf Ebrahimifrom capstone import * 7*9a0e4156SSadaf Ebrahimiimport binascii 8*9a0e4156SSadaf Ebrahimifrom xprint import to_hex 9*9a0e4156SSadaf Ebrahimi 10*9a0e4156SSadaf Ebrahimi 11*9a0e4156SSadaf EbrahimiX86_CODE32 = b"\x8d\x4c\x32\x08\x01\xd8\x81\xc6\x34\x12\x00\x00\x00\x91\x92" 12*9a0e4156SSadaf EbrahimiRANDOM_CODE = b"\xed\x00\x00\x00\x00\x1a\x5a\x0f\x1f\xff\xc2\x09\x80\x00\x00\x00\x07\xf7\xeb\x2a\xff\xff\x7f\x57\xe3\x01\xff\xff\x7f\x57\xeb\x00\xf0\x00\x00\x24\xb2\x4f\x00\x78" 13*9a0e4156SSadaf Ebrahimi 14*9a0e4156SSadaf Ebrahimiall_tests = ( 15*9a0e4156SSadaf Ebrahimi (CS_ARCH_X86, CS_MODE_32, X86_CODE32, "X86 32 (Intel syntax)", None), 16*9a0e4156SSadaf Ebrahimi (CS_ARCH_ARM, CS_MODE_ARM, RANDOM_CODE, "Arm", None), 17*9a0e4156SSadaf Ebrahimi) 18*9a0e4156SSadaf Ebrahimi 19*9a0e4156SSadaf Ebrahimi 20*9a0e4156SSadaf Ebrahimi# Sample callback for SKIPDATA option 21*9a0e4156SSadaf Ebrahimidef testcb(buffer, size, offset, userdata): 22*9a0e4156SSadaf Ebrahimi # always skip 2 bytes of data 23*9a0e4156SSadaf Ebrahimi return 2 24*9a0e4156SSadaf Ebrahimi 25*9a0e4156SSadaf Ebrahimi 26*9a0e4156SSadaf Ebrahimi# ## Test class Cs 27*9a0e4156SSadaf Ebrahimidef test_class(): 28*9a0e4156SSadaf Ebrahimi for (arch, mode, code, comment, syntax) in all_tests: 29*9a0e4156SSadaf Ebrahimi print('*' * 16) 30*9a0e4156SSadaf Ebrahimi print("Platform: %s" %comment) 31*9a0e4156SSadaf Ebrahimi print("Code: %s" % to_hex(code)) 32*9a0e4156SSadaf Ebrahimi print("Disasm:") 33*9a0e4156SSadaf Ebrahimi 34*9a0e4156SSadaf Ebrahimi try: 35*9a0e4156SSadaf Ebrahimi md = Cs(arch, mode) 36*9a0e4156SSadaf Ebrahimi 37*9a0e4156SSadaf Ebrahimi if syntax is not None: 38*9a0e4156SSadaf Ebrahimi md.syntax = syntax 39*9a0e4156SSadaf Ebrahimi 40*9a0e4156SSadaf Ebrahimi md.skipdata = True 41*9a0e4156SSadaf Ebrahimi 42*9a0e4156SSadaf Ebrahimi # Default "data" instruction's name is ".byte". To rename it to "db", just use 43*9a0e4156SSadaf Ebrahimi # the code below. 44*9a0e4156SSadaf Ebrahimi md.skipdata_setup = ("db", None, None) 45*9a0e4156SSadaf Ebrahimi 46*9a0e4156SSadaf Ebrahimi # NOTE: This example ignores SKIPDATA's callback (first None) & user_data (second None) 47*9a0e4156SSadaf Ebrahimi # Can also use dedicated setter 48*9a0e4156SSadaf Ebrahimi #md.skipdata_mnem = 'db' 49*9a0e4156SSadaf Ebrahimi 50*9a0e4156SSadaf Ebrahimi # To customize the SKIPDATA callback, use the line below. 51*9a0e4156SSadaf Ebrahimi #md.skipdata_setup = (".db", testcb, None) 52*9a0e4156SSadaf Ebrahimi 53*9a0e4156SSadaf Ebrahimi # Or use dedicated setter with custom parameter 54*9a0e4156SSadaf Ebrahimi #md.skipdata_callback = (testcb, 42) 55*9a0e4156SSadaf Ebrahimi 56*9a0e4156SSadaf Ebrahimi # Or provide just a function 57*9a0e4156SSadaf Ebrahimi #md.skipdata_callback = testcb 58*9a0e4156SSadaf Ebrahimi # Note that reading this property will always return a tuple 59*9a0e4156SSadaf Ebrahimi #assert md.skipdata_callback == (testcb, None) 60*9a0e4156SSadaf Ebrahimi 61*9a0e4156SSadaf Ebrahimi for insn in md.disasm(code, 0x1000): 62*9a0e4156SSadaf Ebrahimi #bytes = binascii.hexlify(insn.bytes) 63*9a0e4156SSadaf Ebrahimi #print("0x%x:\t%s\t%s\t// hex-code: %s" %(insn.address, insn.mnemonic, insn.op_str, bytes)) 64*9a0e4156SSadaf Ebrahimi print("0x%x:\t%s\t%s" % (insn.address, insn.mnemonic, insn.op_str)) 65*9a0e4156SSadaf Ebrahimi 66*9a0e4156SSadaf Ebrahimi print("0x%x:" % (insn.address + insn.size)) 67*9a0e4156SSadaf Ebrahimi print 68*9a0e4156SSadaf Ebrahimi except CsError as e: 69*9a0e4156SSadaf Ebrahimi print("ERROR: %s" % e) 70*9a0e4156SSadaf Ebrahimi 71*9a0e4156SSadaf Ebrahimi 72*9a0e4156SSadaf Ebrahimiif __name__ == '__main__': 73*9a0e4156SSadaf Ebrahimi test_class() 74