* Add rafind2 -e to search for regular expression keywords

This commit is contained in:
pancake 2011-06-22 00:28:03 +02:00
parent b66a9cdd42
commit c72cbe9bfa
2 changed files with 35 additions and 30 deletions

6
TODO
View file

@ -5,15 +5,12 @@
CODENAME: #DRY
* implement regexp search in rafind2
* review io.cache with 'wc' to support write patch
* add support for sockets in rarun2
TODO
====
* Implement r_flag_unset_i () ftw
* libmagic internal :? -- find a decent implementation and adopt it
* Ranged/scrollable zoom mode
* Honor string metadata for asmsteps ('jk' in visual)
** BUG **
@ -52,9 +49,9 @@ TODO
------8<-------------------8<--------------------8<-----------------8<----------
To wipe:
========
* check iowrite
- Move the content of libr/*/TODO here
- linestyle?? for disassembly lines
- remove libr/vm and libr/db
@ -142,6 +139,7 @@ Assembler
0.8: focus on debugger and UI
=============================
* Ranged/scrollable zoom mode
* AES/RSA Key finding
http://citp.princeton.edu/memory/code/ <- implement this stuff in r2
* Reimplement or fix the delta diffing in C - first we need to do it for ired..

View file

@ -36,34 +36,35 @@ typedef struct {
static int hit(RSearchKeyword *kw, void *user, ut64 addr) {
int delta = addr-cur;
if (rad) {
printf("f hit%d_%d 0x%08"PFMT64x" ; %s\n", 0, kw->count, addr, curfile);
printf ("f hit%d_%d 0x%08"PFMT64x" ; %s\n", 0, kw->count, addr, curfile);
} else {
if (!kw->count) printf("; %s\n", kw->keyword);
printf("%s: %03d @ 0x%"PFMT64x"\n", curfile, kw->count, addr);
if (!kw->count) printf ("; %s\n", kw->keyword);
printf ("%s: %03d @ 0x%"PFMT64x"\n", curfile, kw->count, addr);
if (pr) {
r_print_hexdump(pr, addr, (ut8*)buffer+delta, 78, 16, R_TRUE);
r_cons_flush();
r_print_hexdump (pr, addr, (ut8*)buffer+delta, 78, 16, R_TRUE);
r_cons_flush ();
}
}
return 1;
}
static int show_help(char *argv0, int line) {
printf("Usage: %s [-Xnzh] [-f from] [-t to] [-s str] [-x hex] file ...\n", argv0);
printf ("Usage: %s [-Xnzh] [-f from] [-t to] [-[m|s|e] str] [-x hex] file ...\n", argv0);
if (line) return 0;
printf(
" -z search for zero-terminated strings\n"
" -s [str] search for zero-terminated strings (can be used multiple times)\n"
" -m [str] set a mask\n"
" -x [hex] search for hexpair string (909090) (can be used multiple times)\n"
" -f [from] start searching from address 'from'\n"
" -t [to] stop search at address 'to'\n"
" -X show hexdump of search results\n"
" -n do not stop on read errors\n"
" -r print using radare commands\n"
" -b set block size\n"
" -h show this help\n"
" -V print version and exit\n"
printf (
" -z search for zero-terminated strings\n"
" -s [str] search for zero-terminated strings (can be used multiple times)\n"
" -e [regex] search for regular expression string matches\n"
" -x [hex] search for hexpair string (909090) (can be used multiple times)\n"
" -m [str] set a mask\n"
" -f [from] start searching from address 'from'\n"
" -t [to] stop search at address 'to'\n"
" -X show hexdump of search results\n"
" -n do not stop on read errors\n"
" -r print using radare commands\n"
" -b set block size\n"
" -h show this help\n"
" -V print version and exit\n"
);
return 0;
}
@ -79,7 +80,7 @@ static int rafind_open(char *file) {
return 1;
}
r_cons_new();
r_cons_new ();
rs = r_search_new (mode);
buffer = malloc (bsize);
if (buffer==NULL) {
@ -124,25 +125,31 @@ static int rafind_open(char *file) {
int main(int argc, char **argv) {
int c;
while ((c = getopt(argc, argv, "b:m:s:x:Xzf:t:rnhV")) != -1) {
BoxedString *kw = R_NEW(BoxedString);
INIT_LIST_HEAD(&(kw->list));
while ((c = getopt(argc, argv, "e:b:m:s:x:Xzf:t:rnhV")) != -1) {
BoxedString *kw = R_NEW (BoxedString);
INIT_LIST_HEAD (&(kw->list));
switch(c) {
switch (c) {
case 'r':
rad = 1;
break;
case 'n':
nonstop = 1;
break;
case 'e':
mode = R_SEARCH_REGEXP;
hexstr = 0;
kw->str = optarg;
list_add (&(kw->list), &(kws_head));
break;
case 's':
mode = R_SEARCH_KEYWORD;
hexstr = 0;
kw->str = optarg;
list_add(&(kw->list), &(kws_head));
list_add (&(kw->list), &(kws_head));
break;
case 'b':
bsize = r_num_math(NULL, optarg);
bsize = r_num_math (NULL, optarg);
break;
case 'z':
mode = R_SEARCH_STRING;