Показаны сообщения с ярлыком code analysis. Показать все сообщения
Показаны сообщения с ярлыком code analysis. Показать все сообщения

четверг, 9 апреля 2020 г.

armpatched

Several days ago I started my new pet project on GitHub, bcs
  • quarantine is boring
  • reading a book "ARM 64-Bit Assembly Language" without practice is useless
So I just forked arm64 disasm called armadillo, ported it on windows, added naïve pe loader (btw attempt to use MapViewOfFile function was unsuccessful with GetLastError 1132) and today add some practical usage of static code analysis to extract lists and lock of lookaside lists from arm64 windows kernel

Main magic happens in ntoskrnl_hack::find_lock_list function

воскресенье, 5 апреля 2020 г.

static code analysis

This cool article is good case to show how you can employ static code analysis for extracting some unexported symbols from binary code - in this case we need ExNPagedLookasideLock & ExNPagedLookasideListHead

Sure the first thing you need is disassembler. If you search at GitHub "x86 disasm" you will get something about 20 repositories, but we need one that satisfies some requirements:
  • disasm to some intermediate code and not in string output
  • can be used in kernel mode (just in case if you want to do it) which means that it must be written in C

So just choose the one with the most comprehensible code - bcs they all contains bugs and you anyway will fix them and/or add missed instructions

Lets start with exported function ExInitializeNPagedLookasideList. Simplest cases - xp 64bit:

пятница, 29 июня 2018 г.

interesting case of memory leak

after three weeks of work service osqueryd.exe consumed about 150 mb of memory. so I made full memory dump with process explorer and run !heap -l in windbg
298991 string in log ! lets write quick and ditry perl script to calculate sizes of leaked blocks:
my $state = 0;
my($str, %dict, $size);
while( $str = <> )
{
  chomp $str;
  last if ( $str eq '' );
  if ( ! $state )
  {
    $state = 1 if ( $str =~ /^-----/ );
    next;
  }
  $str = substr($str, 72, 10);
  $str =~ s/^\s+//g;
  $str =~ s/\s+$//g;
  $size = hex($str);
  next if ( !$size );
  $dict{$size} += 1;
}

# dump results
my $iter;
foreach $iter ( sort { $dict{$b} <=> $dict{$a} } keys %dict )
{
  printf("%X %d\n", $iter, $dict{$iter});
}
results are encouraging:

понедельник, 5 сентября 2011 г.

serious business

Klocwork всего три дня спустя прислал письмо на предмет пощупать их мега-продуктЪ:
Our min. configuration/price € 24.000 per year and it will include:
 - UP to 20 fixed user licenses (or 4 floating licenses) Single Language-Klocwork insight
 -1 fixed build license (server)
 -unlimited LOC (lines of code)
 -Maintenance & support for 12 month

All prices depends on the following choices :
 - Insight or Insight Pro license
 - fixed or floating license
 - single language  or all languages (C,C++,Java)

Ильфак в сравнении с занимается чистой благотворительностью по моему

пятница, 2 сентября 2011 г.

прогнал сорцы wincheck

на PVS Studio
Нашло 2253 possible errors
Начну с плохих новостей
  • оно работает дико медленно - на 2.5 метрах ~13 минут
  • находит в основном всякий треш типа вот такого:
  • Dangerous magic number 4 used: UCHAR Tag[4]
    Дико опасная ошибка, да. Я заметил что оно вообще всегда делает стойку на константы 4 и 32
  • On 64-bit platform, structure size can be reduced from 48 to 40 bytes by rearranging the fields according to their sizes in decreasing order.
    Ну круто, чо. А как делать rearranging the fields то ? Хоть бы варианты какие предлагала
  • И самое угарное - большинство таких структур находятся например в ntdll.h, бгг
  • отчего-то вот такой вполне легальный кусок кода sizeof(PBYTE) * _countof(m_index_table) считается
    It is odd that a sizeof() operator is multiplied by sizeof()
  • также раздражает что if ( memcmp(hash, old_hash, HASH_SIZE) ) считается как
    The 'memcmp' function returns 0 if corresponding buffers are equal. Consider examining the condition for mistakes
    ну и чо - проверил я хэши и если не совпали - мне нужно предпринять какие-то действия например
Хорошие новости
  • нашла одно присваивание в if. Даже странно что visual studio ни слова не сказала
  • нашлась пара printf с меньшим числом аргументов, чем указано в format string. 
  • один printf соотв-но с большим числом аргументов, чем указано в format string.

    воскресенье, 14 августа 2011 г.

    code coverage analysis tools

    вырипал из книжки API design for C++ (книжка впрочем так себе - как дочитаю - напишу пару ласковых) например:
    • Bullseye Coverage (http://www.bullseye.com/). This coverage tool, from Bullseye Testing Technology, provides function as well as condition/decision coverage, to give you a range of coverage precision. It offers features such as covering system-level and kernel mode code, merging results from distributed testing, and integration with Microsoft Visual Studio. It also gives you the ability to exclude certain portions of your code from analysis.Bullseye is a mature product that has support for a wide range of platforms and compilers.
    • Rational PureCoverage (http://www.rational.com/). This code coverage analysis tool is sold as
    part of the PurifyPlus package from IBM. It can report coverage at executable, library, file, function, block, and line levels.PureCoverage can accumulate coverage over multiple runs and merge data from different programs that share the same source code. It offers both graphical and textual output to let you explore its results.
    • Intel Code-CoverageTool (http://www.intel.com/). This tool is included with Intel compilers and runs on instrumentation files produced by those compilers. It provides function and basic block coverage and can restrict analysis to only those modules of interest. It also supports differential coverage, that is, comparing the output of one run against another run.The Code-Coverage Tool runs on Intel processors under Windows or Linux.
    • Gcov (http://gcc.gnu.org/onlinedocs/gcc/Gcov.html). This test coverage program is part of
    the open-source GNU GCC compiler collection. It operates on code generated by
    -fprofile-arcs and -ftest-coverage options.Gcov provides function, line, and branch code coverage. It outputs its report in a textual format; however, the accompanying lcov script
    can be used to output results as an HTML report