Search in sources :

Example 31 with ReilInstruction

use of com.google.security.zynamics.reil.ReilInstruction in project binnavi by google.

the class ForwardRegisterTrackingTransformationProviderTest method testTransformMulSecondInputIsZero.

@Test
public void testTransformMulSecondInputIsZero() {
    final RegisterTrackingTransformationProvider transformationProvider = new RegisterTrackingTransformationProvider(new RegisterTrackingOptions(false, new TreeSet<String>(), false, AnalysisDirection.DOWN));
    final ReilInstruction instruction = ReilHelpers.createMul(0, OperandSize.DWORD, "ecx", OperandSize.DWORD, String.valueOf("0"), OperandSize.DWORD, "eax");
    final Pair<RegisterSetLatticeElement, RegisterSetLatticeElement> transformationResult = transformationProvider.transformMul(instruction, createTaintedState("ecx"));
    Assert.assertNull(transformationResult.second());
    transformationResult.first().onInstructionExit();
    Assert.assertTrue(transformationResult.first().getNewlyTaintedRegisters().isEmpty());
    Assert.assertTrue(transformationResult.first().getReadRegisters().isEmpty());
    Assert.assertTrue(transformationResult.first().getTaintedRegisters().contains("ecx"));
    Assert.assertFalse(transformationResult.first().getTaintedRegisters().contains("eax"));
    Assert.assertTrue(transformationResult.first().getUntaintedRegisters().isEmpty());
    Assert.assertTrue(transformationResult.first().getUpdatedRegisters().isEmpty());
}
Also used : ReilInstruction(com.google.security.zynamics.reil.ReilInstruction) TreeSet(java.util.TreeSet) Test(org.junit.Test)

Example 32 with ReilInstruction

use of com.google.security.zynamics.reil.ReilInstruction in project binnavi by google.

the class ForwardRegisterTrackingTransformationProviderTest method testTransformMulSecondInputRegisterIsTainted.

@Test
public void testTransformMulSecondInputRegisterIsTainted() {
    final RegisterTrackingTransformationProvider transformationProvider = new RegisterTrackingTransformationProvider(new RegisterTrackingOptions(false, new TreeSet<String>(), false, AnalysisDirection.DOWN));
    final ReilInstruction instruction = ReilHelpers.createMul(0, OperandSize.DWORD, "ebx", OperandSize.DWORD, "ecx", OperandSize.DWORD, "eax");
    final Pair<RegisterSetLatticeElement, RegisterSetLatticeElement> transformationResult = transformationProvider.transformMul(instruction, createTaintedState("ecx"));
    Assert.assertNull(transformationResult.second());
    transformationResult.first().onInstructionExit();
    Assert.assertTrue(transformationResult.first().getNewlyTaintedRegisters().contains("eax"));
    Assert.assertTrue(transformationResult.first().getReadRegisters().contains("ecx"));
    Assert.assertTrue(transformationResult.first().getTaintedRegisters().contains("eax"));
    Assert.assertTrue(transformationResult.first().getTaintedRegisters().contains("ecx"));
    Assert.assertTrue(transformationResult.first().getUntaintedRegisters().isEmpty());
    Assert.assertTrue(transformationResult.first().getUpdatedRegisters().isEmpty());
}
Also used : ReilInstruction(com.google.security.zynamics.reil.ReilInstruction) TreeSet(java.util.TreeSet) Test(org.junit.Test)

Example 33 with ReilInstruction

use of com.google.security.zynamics.reil.ReilInstruction in project binnavi by google.

the class ForwardRegisterTrackingTransformationProviderTest method testTransformXorSameOperands.

@Test
public void testTransformXorSameOperands() {
    final RegisterTrackingTransformationProvider transformationProvider = new RegisterTrackingTransformationProvider(new RegisterTrackingOptions(false, new TreeSet<String>(), false, AnalysisDirection.DOWN));
    final ReilInstruction instruction = ReilHelpers.createXor(0, OperandSize.DWORD, "ecx", OperandSize.DWORD, "ecx", OperandSize.DWORD, "eax");
    final Pair<RegisterSetLatticeElement, RegisterSetLatticeElement> transformationResult = transformationProvider.transformXor(instruction, createTaintedState("ecx", "eax"));
    Assert.assertNull(transformationResult.second());
    transformationResult.first().onInstructionExit();
    Assert.assertTrue(transformationResult.first().getNewlyTaintedRegisters().isEmpty());
    Assert.assertTrue(transformationResult.first().getReadRegisters().isEmpty());
    Assert.assertFalse(transformationResult.first().getTaintedRegisters().contains("eax"));
    Assert.assertTrue(transformationResult.first().getTaintedRegisters().contains("ecx"));
    Assert.assertTrue(transformationResult.first().getUntaintedRegisters().contains("eax"));
}
Also used : ReilInstruction(com.google.security.zynamics.reil.ReilInstruction) TreeSet(java.util.TreeSet) Test(org.junit.Test)

Example 34 with ReilInstruction

use of com.google.security.zynamics.reil.ReilInstruction in project binnavi by google.

the class ForwardRegisterTrackingTransformationProviderTest method testTransformJccNoFunctionCallClear.

@Test
public void testTransformJccNoFunctionCallClear() {
    final Set<String> cleared = new TreeSet<String>();
    cleared.add("ecx");
    final RegisterTrackingTransformationProvider transformationProvider = new RegisterTrackingTransformationProvider(new RegisterTrackingOptions(false, cleared, false, AnalysisDirection.DOWN));
    final ReilInstruction instruction = ReilHelpers.createJcc(0, OperandSize.DWORD, "eax", OperandSize.DWORD, "ecx");
    final Pair<RegisterSetLatticeElement, RegisterSetLatticeElement> transformationResult = transformationProvider.transformJcc(instruction, createTaintedState("ecx"));
    transformationResult.first().onInstructionExit();
    Assert.assertTrue(transformationResult.first().getNewlyTaintedRegisters().isEmpty());
    Assert.assertTrue(transformationResult.first().getReadRegisters().isEmpty());
    Assert.assertTrue(transformationResult.first().getTaintedRegisters().contains("ecx"));
    Assert.assertTrue(transformationResult.first().getUntaintedRegisters().isEmpty());
    Assert.assertTrue(transformationResult.first().getUpdatedRegisters().isEmpty());
}
Also used : ReilInstruction(com.google.security.zynamics.reil.ReilInstruction) TreeSet(java.util.TreeSet) Test(org.junit.Test)

Example 35 with ReilInstruction

use of com.google.security.zynamics.reil.ReilInstruction in project binnavi by google.

the class BackwardRegisterTrackingTransformationProviderTest method testTransformBisz.

@Test
public void testTransformBisz() {
    final RegisterTrackingTransformationProvider transformationProvider = new RegisterTrackingTransformationProvider(new RegisterTrackingOptions(false, new TreeSet<String>(), false, AnalysisDirection.UP));
    final ReilInstruction instruction = ReilHelpers.createBisz(0, OperandSize.DWORD, "ecx", OperandSize.DWORD, "eax");
    final Pair<RegisterSetLatticeElement, RegisterSetLatticeElement> transformationResult = transformationProvider.transformBisz(instruction, createTaintedState("eax"));
    Assert.assertTrue(transformationResult.first().getTaintedRegisters().contains("ecx"));
}
Also used : ReilInstruction(com.google.security.zynamics.reil.ReilInstruction) TreeSet(java.util.TreeSet) Test(org.junit.Test)

Aggregations

ReilInstruction (com.google.security.zynamics.reil.ReilInstruction)144 Test (org.junit.Test)102 TreeSet (java.util.TreeSet)73 ArrayList (java.util.ArrayList)35 IInstruction (com.google.security.zynamics.zylib.disassembly.IInstruction)18 OperandSize (com.google.security.zynamics.reil.OperandSize)16 ReilBlock (com.google.security.zynamics.reil.ReilBlock)16 MockInstruction (com.google.security.zynamics.zylib.disassembly.MockInstruction)16 MockOperandTree (com.google.security.zynamics.zylib.disassembly.MockOperandTree)16 MockOperandTreeNode (com.google.security.zynamics.zylib.disassembly.MockOperandTreeNode)16 ReilEdge (com.google.security.zynamics.reil.ReilEdge)12 HashMap (java.util.HashMap)12 TranslationResult (com.google.security.zynamics.reil.translators.TranslationResult)9 IAddress (com.google.security.zynamics.zylib.disassembly.IAddress)7 List (java.util.List)7 ReilGraph (com.google.security.zynamics.reil.ReilGraph)6 InternalTranslationException (com.google.security.zynamics.reil.translators.InternalTranslationException)6 BigInteger (java.math.BigInteger)6 INaviInstruction (com.google.security.zynamics.binnavi.disassembly.INaviInstruction)5 ValueTrackerElement (com.google.security.zynamics.reil.algorithms.mono.valuetracking.ValueTrackerElement)5