mirror of
https://github.com/NationalSecurityAgency/ghidra.git
synced 2026-09-28 17:11:11 -09:00
GP-3878 Corrected ELF x86 32-bit PLT processing issue
This commit is contained in:
@@ -54,18 +54,18 @@ public class X86_32_ElfExtension extends ElfExtension {
|
|||||||
}
|
}
|
||||||
|
|
||||||
super.processGotPlt(elfLoadHelper, monitor);
|
super.processGotPlt(elfLoadHelper, monitor);
|
||||||
|
|
||||||
processX86Plt(elfLoadHelper, monitor);
|
processX86PltSections(elfLoadHelper, monitor);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Handle the case where GOT entry offset are computed based upon EBX.
|
* Handle the case where GOT entry offset are computed based upon EBX.
|
||||||
* This implementation replaces the old "magic map" which had previously been used.
|
* This implementation replaces the old "magic map" which had previously been used.
|
||||||
* @param elfLoadHelper
|
* @param elfLoadHelper ELF load helper
|
||||||
* @param monitor
|
* @param monitor task monitor
|
||||||
* @throws CancelledException
|
* @throws CancelledException thrown if load cancelled
|
||||||
*/
|
*/
|
||||||
private void processX86Plt(ElfLoadHelper elfLoadHelper, TaskMonitor monitor) throws CancelledException {
|
private void processX86PltSections(ElfLoadHelper elfLoadHelper, TaskMonitor monitor) throws CancelledException {
|
||||||
|
|
||||||
// TODO: Does 64-bit have a similar mechanism?
|
// TODO: Does 64-bit have a similar mechanism?
|
||||||
|
|
||||||
@@ -73,37 +73,50 @@ public class X86_32_ElfExtension extends ElfExtension {
|
|||||||
// the unresolved issue is to determine the length of the PLT area without a section
|
// the unresolved issue is to determine the length of the PLT area without a section
|
||||||
|
|
||||||
ElfHeader elfHeader = elfLoadHelper.getElfHeader();
|
ElfHeader elfHeader = elfLoadHelper.getElfHeader();
|
||||||
ElfSectionHeader pltSection = elfHeader.getSection(ElfSectionHeaderConstants.dot_plt);
|
|
||||||
if (pltSection == null || !pltSection.isExecutable()) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
ElfDynamicTable dynamicTable = elfHeader.getDynamicTable();
|
ElfDynamicTable dynamicTable = elfHeader.getDynamicTable();
|
||||||
if (dynamicTable == null || !dynamicTable.containsDynamicValue(ElfDynamicType.DT_PLTGOT)) {
|
if (dynamicTable == null || !dynamicTable.containsDynamicValue(ElfDynamicType.DT_PLTGOT)) {
|
||||||
return; // avoid NotFoundException which causes issues for importer
|
return; // avoid NotFoundException which causes issues for importer
|
||||||
}
|
}
|
||||||
|
|
||||||
Program program = elfLoadHelper.getProgram();
|
long pltgotOffset;
|
||||||
Memory memory = program.getMemory();
|
|
||||||
|
|
||||||
// MemoryBlock pltBlock = getBlockPLT(pltSection);
|
|
||||||
MemoryBlock pltBlock = memory.getBlock(pltSection.getNameAsString());
|
|
||||||
if (pltBlock == null) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Paint pltgot base over .plt section to allow thunks to be resolved during analysis
|
|
||||||
Register ebxReg = program.getRegister("EBX");
|
|
||||||
try {
|
try {
|
||||||
long pltgotOffset = elfHeader.adjustAddressForPrelink(dynamicTable.getDynamicValue(
|
pltgotOffset = elfHeader.adjustAddressForPrelink(dynamicTable.getDynamicValue(
|
||||||
ElfDynamicType.DT_PLTGOT));
|
ElfDynamicType.DT_PLTGOT));
|
||||||
pltgotOffset = elfLoadHelper.getDefaultAddress(pltgotOffset).getOffset(); // adjusted for image base
|
pltgotOffset = elfLoadHelper.getDefaultAddress(pltgotOffset).getOffset(); // adjusted for image base
|
||||||
RegisterValue pltgotValue = new RegisterValue(ebxReg, BigInteger.valueOf(pltgotOffset));
|
}
|
||||||
program.getProgramContext().setRegisterValue(pltBlock.getStart(), pltBlock.getEnd(), pltgotValue);
|
catch (NotFoundException e) {
|
||||||
} catch (NotFoundException | ContextChangeException e) {
|
|
||||||
throw new AssertException("unexpected", e);
|
throw new AssertException("unexpected", e);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Program program = elfLoadHelper.getProgram();
|
||||||
|
Register ebxReg = program.getRegister("EBX");
|
||||||
|
Memory memory = program.getMemory();
|
||||||
|
|
||||||
|
String pltPrefix = ElfSectionHeaderConstants.dot_plt + ".";
|
||||||
|
|
||||||
|
for (ElfSectionHeader section : elfHeader.getSections()) {
|
||||||
|
monitor.checkCancelled();
|
||||||
|
String sectionName = section.getNameAsString();
|
||||||
|
if (!section.isExecutable()) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (sectionName.equals(ElfSectionHeaderConstants.dot_plt) || sectionName.startsWith(pltPrefix)) {
|
||||||
|
|
||||||
|
MemoryBlock pltBlock = memory.getBlock(sectionName);
|
||||||
|
if (pltBlock == null) {
|
||||||
|
elfLoadHelper.log("Skipped processing of " + sectionName + ": memory block not found");
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Paint pltgot base over .plt section as EBX value to allow thunks to be resolved during analysis
|
||||||
|
try {
|
||||||
|
RegisterValue pltgotValue = new RegisterValue(ebxReg, BigInteger.valueOf(pltgotOffset));
|
||||||
|
program.getProgramContext().setRegisterValue(pltBlock.getStart(), pltBlock.getEnd(), pltgotValue);
|
||||||
|
} catch (ContextChangeException e) {
|
||||||
|
throw new AssertException("unexpected", e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user