forked from pdasilva/vtrace_scripts
-
Notifications
You must be signed in to change notification settings - Fork 0
/
simpleFunctionList.py
50 lines (40 loc) · 1.4 KB
/
simpleFunctionList.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
import sys
import simpleAPI as v_api
#VDB_ROOT = "<path-to-VDB>"
sys.path.append(VDB_ROOT)
import vtrace
import vdb
import PE as PE
from envi.archs.i386 import *
import vdb.stalker as v_stalker
#######################################################################
def load_binary(filepath, pattern, base=None):
# Get the current trace object from vtrace
trace = vtrace.getTrace()
# If attempting to attach to a 64 bit process
# 64 bit python is required.
trace.execute(filepath)
pattern = pattern.lower()
# Get the list of all library names
# Iterate over the list of function names for values that match pattern
libs = trace.getNormalizedLibNames()
libs.sort()
for libname in libs:
for sym in trace.getSymsForFile(libname):
r = repr(sym)
if pattern != None:
if r.lower().find(pattern) == -1:
continue
print("0x%.8x %s" % (sym.value, r))
######################################################################
def main(argv):
if len(argv) != 3:
print "Usage: %s <exe bin>" " <pattern>"% sys.argv[0]
sys.exit(1)
filepath = sys.argv[1]
# Pattern is the dll you want to search for function names in
pattern = sys.argv[2]
load_binary(filepath, pattern)
if __name__ == "__main__":
main(sys.argv)
sys.exit(0)