LyScript 插件默认提供了一个get_disasm_code()
方法可以直接获取到指定行数的反汇编代码,但如果需要自定义获取或者是需要自己封装一个反汇编方法,则你可以用如下两种方式来得到。
第一步直接获取到指定EIP位置的反汇编代码,这段代码可以这样来写。
from LyScript32 import MyDebug
if __name__ == "__main__": dbg = MyDebug() conn = dbg.connect()
eip = dbg.get_register("eip") print("eip = {}".format(hex(eip)))
count = eip + 15 while True: dissasm = dbg.get_disasm_one_code(eip)
print("0x{:08x} | {}".format(eip, dissasm))
if eip >= count: break else: dis_size = dbg.assemble_code_size(dissasm) eip = eip + dis_size
dbg.close() pass
|
输出效果如下。

第二步得到当前EIP机器码,获取到当前EIP指针所在位置的机器码,你可以灵活运用反汇编代码的组合实现。
from LyScript32 import MyDebug
def GetHexCode(dbg,address): ref_bytes = [] asm_len = dbg.assemble_code_size( dbg.get_disasm_one_code(address) )
for index in range(0,asm_len): ref_bytes.append(dbg.read_memory_byte(address)) address = address + 1 return ref_bytes
if __name__ == "__main__": dbg = MyDebug() conn = dbg.connect()
eip = dbg.get_register("eip") print("eip = {}".format(hex(eip)))
ref = GetHexCode(dbg,eip) for i in range(0,len(ref)): print("0x{:02x} ".format(ref[i]),end="")
dbg.close() pass
|
输出效果如下所示:

如果将如上两种方法结合在一起,那么你就可以获取到x64dbg反汇编窗口中的三个主要参数区中的内容了。
from LyScript32 import MyDebug
def GetHexCode(dbg,address): ref_bytes = [] asm_len = dbg.assemble_code_size( dbg.get_disasm_one_code(address) ) for index in range(0,asm_len): ref_bytes.append(dbg.read_memory_byte(address)) address = address + 1 return ref_bytes
if __name__ == "__main__": dbg = MyDebug() conn = dbg.connect()
eip = dbg.get_register("eip") print("eip = {}".format(hex(eip)))
count = eip + 20 while True: dissasm = dbg.get_disasm_one_code(eip)
print("0x{:08x} | {:50} | ".format(eip, dissasm),end="")
ref = GetHexCode(dbg, eip) for i in range(0, len(ref)): print("0x{:02x} ".format(ref[i]), end="") print()
if eip >= count: break else: dis_size = dbg.assemble_code_size(dissasm) eip = eip + dis_size
dbg.close() pass
|
获取效果图如下:
