-
Notifications
You must be signed in to change notification settings - Fork 13
/
xbinary.h
1649 lines (1396 loc) · 64.3 KB
/
xbinary.h
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
/* Copyright (c) 2017-2024 hors<[email protected]>
*
* Permission is hereby granted, free of charge, to any person obtaining a copy
* of this software and associated documentation files (the "Software"), to deal
* in the Software without restriction, including without limitation the rights
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
* copies of the Software, and to permit persons to whom the Software is
* furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in
* all copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
* SOFTWARE.
*/
#ifndef XBINARY_H
#define XBINARY_H
#include <QBuffer>
#include <QCoreApplication>
#include <QCryptographicHash>
#include <QDataStream>
#include <QDateTime>
#include <QDirIterator>
#include <QDir>
#include <QElapsedTimer>
#include <QFile>
#include <QFileInfo>
#include <QIODevice>
#include <QMap>
#include <QMutex>
#include <QSet>
#include <QTemporaryFile>
#include <QTextStream>
#include <QUuid>
#include <QXmlStreamReader>
#include <QXmlStreamWriter>
#include <QtEndian>
#if (QT_VERSION_MAJOR < 6) || defined(QT_CORE5COMPAT_LIB)
#include <QTextCodec> // Qt5 Compat
#endif
#if (QT_VERSION_MAJOR < 5) // TODO Check
#include <QRegExp>
#else
#include <QRegularExpression>
#include <QRegularExpressionMatch>
#endif
#ifdef QT_DEBUG
#include <QDebug>
#endif
#if QT_VERSION >= QT_VERSION_CHECK(5, 10, 0)
#include <QRandomGenerator>
#elif (QT_VERSION_MAJOR >= 6) // TODO Check
#include <QRandomGenerator>
#endif
#ifdef QT_GUI_LIB
#include <QColor>
#endif
#include <math.h>
#include "subdevice.h"
#include "xbinary_def.h"
#include "xelf_def.h"
#include "xle_def.h"
#include "xmach_def.h"
#include "xmsdos_def.h"
#include "xne_def.h"
#include "xpe_def.h"
// TODO mb Functions
#define S_ALIGN_DOWN32(value, align) (((quint32)value) & ~((quint32)align - 1))
#define S_ALIGN_UP32(value, align) ((((quint32)value) & ((quint32)align - 1)) ? (S_ALIGN_DOWN32((quint32)value, (quint32)align) + (quint32)align) : ((quint32)value))
#define S_ALIGN_DOWN64(value, align) (((quint64)value) & ~((quint64)align - 1))
#define S_ALIGN_UP64(value, align) ((((quint64)value) & ((quint64)align - 1)) ? (S_ALIGN_DOWN64((quint64)value, (quint64)align) + (quint64)align) : ((quint64)value))
#define S_ALIGN_DOWN(value, align) ((value) & ~(align - 1))
#define S_ALIGN_UP(value, align) (((value) & (align - 1)) ? S_ALIGN_DOWN(value, align) + align : value)
#define S_LOWORD(value) ((quint16)((quint32)(value)&0xFFFF))
#define S_HIWORD(value) ((quint16)((quint32)(value) >> 16))
#define S_FULL_VERSION(value1, value2, value3) ((quint32)((((quint16)value1) << 16) | (((quint8)value2) << 8) | ((quint8)value3)))
typedef quint64 XADDR;
// #define XADDR_ERROR (XADDR)-1
#ifdef Q_OS_MAC
#include <CoreFoundation/CoreFoundation.h> // Check
#endif
class XBinary : public QObject {
Q_OBJECT
static const double D_ENTROPY_THRESHOLD; // 6.5 TODO set get
public:
enum LT {
LT_UNKNOWN = 0,
LT_OFFSET,
LT_ADDRESS,
LT_RELADDRESS,
};
struct DATASET {
qint64 nOffset;
XADDR nAddress;
qint64 nSize;
QString sName;
quint32 nType;
// Optional
qint64 nStringTableOffset;
qint64 nStringTableSize;
};
struct BYTE_COUNTS {
qint64 nSize;
qint64 nCount[256]; // TODO const
};
struct OS_STRING {
qint64 nOffset;
qint64 nSize;
QString sString;
};
struct OFFSETSIZE {
qint64 nOffset;
qint64 nSize;
};
struct ADDRESSSIZE {
XADDR nAddress;
qint64 nSize;
};
struct RELADDRESSSIZE {
qint64 nAddress;
qint64 nSize;
};
enum ADDRESS_SEGMENT {
ADDRESS_SEGMENT_UNKNOWN = -1,
ADDRESS_SEGMENT_FLAT = 0,
ADDRESS_SEGMENT_CODE,
// ADDRESS_SEGMENT_DATA
};
enum FILEPART {
FILEPART_UNKNOWN = 0,
FILEPART_REGION,
FILEPART_ARCHIVERECORD,
FILEPART_HEADER,
FILEPART_OVERLAY,
FILEPART_RESOURCE,
FILEPART_DEBUGDATA
};
enum MMT {
MMT_UNKNOWN = 0,
MMT_HEADER,
MMT_FOOTER,
MMT_LOADSEGMENT, // Section in PE; LoadProgram in ELF; Segments in MACH
MMT_NOLOADABLE, // For ELF TODO Check
MMT_FILESEGMENT,
MMT_OVERLAY,
MMT_DATA,
MMT_OBJECT,
MMT_TABLE
};
struct _MEMORY_RECORD {
qint64 nOffset;
XADDR nAddress;
ADDRESS_SEGMENT segment;
qint64 nSize;
MMT type;
qint32 nLoadSectionNumber;
QString sName;
qint32 nIndex;
bool bIsVirtual;
quint64 nID;
};
enum FORMATTYPE {
FORMATTYPE_UNKNOWN = 0,
FORMATTYPE_TEXT,
FORMATTYPE_PLAINTEXT,
FORMATTYPE_XML,
FORMATTYPE_JSON,
FORMATTYPE_CSV,
FORMATTYPE_TSV
};
enum FT {
FT_UNKNOWN = 0,
FT_DATA,
FT_REGION, // For Memory regions
FT_PROCESS,
FT_BINARY,
FT_BINARY16,
FT_BINARY32,
FT_BINARY64,
FT_COM,
FT_MSDOS,
FT_DOS16M,
FT_DOS4G,
FT_NE,
FT_LE,
FT_LX,
FT_PE,
FT_PE32,
FT_PE64,
FT_ELF,
FT_ELF32,
FT_ELF64,
FT_MACHO,
FT_MACHO32,
FT_MACHO64,
FT_AMIGAHUNK,
// Extra
FT_7Z,
FT_ANDROIDASRC,
FT_ANDROIDXML,
FT_APK,
FT_APKS,
FT_AR,
FT_TAR,
FT_TARGZ,
FT_ARCHIVE,
FT_CAB,
FT_DEX,
FT_DOCUMENT,
FT_GIF,
FT_BMP,
FT_IMAGE,
FT_VIDEO,
FT_AUDIO,
FT_IPA,
FT_JAR,
FT_JPEG,
FT_MACHOFAT,
FT_PDF,
FT_PLAINTEXT,
FT_PNG,
FT_RAR,
FT_TEXT,
FT_TIFF,
FT_UNICODE,
FT_UNICODE_BE,
FT_UNICODE_LE,
FT_UTF8,
FT_ZIP,
FT_GZIP,
FT_ZLIB,
FT_LHA,
FT_ICO,
FT_CUR,
FT_MP3,
FT_MP4,
FT_RIFF,
FT_AVI,
FT_WEBP,
FT_SIGNATURE,
FT_NPM,
FT_DEB,
FT_BWDOS16M
// TODO more
};
enum MODE {
MODE_UNKNOWN = 0,
MODE_DATA, // Raw data
MODE_BIT, // 1/0
MODE_8,
MODE_16,
MODE_16SEG,
MODE_32,
MODE_64,
MODE_128,
MODE_256,
MODE_FREG
// TODO more
};
enum DMFAMILY {
DMFAMILY_UNKNOWN,
DMFAMILY_X86,
DMFAMILY_ARM,
DMFAMILY_ARM64,
DMFAMILY_MIPS,
DMFAMILY_PPC,
DMFAMILY_SPARC,
DMFAMILY_SYSZ,
DMFAMILY_XCORE,
DMFAMILY_M68K,
DMFAMILY_M68OK,
DMFAMILY_RISCV,
DMFAMILY_EVM,
DMFAMILY_MOS65XX,
DMFAMILY_WASM,
DMFAMILY_BPF
};
enum DM {
DM_UNKNOWN = 0,
DM_DATA,
DM_X86_16,
DM_X86_32,
DM_X86_64,
DM_ARM_LE,
DM_ARM_BE,
DM_AARCH64_LE,
DM_AARCH64_BE,
DM_CORTEXM,
DM_THUMB_LE,
DM_THUMB_BE,
DM_MIPS_LE,
DM_MIPS_BE,
DM_MIPS64_LE,
DM_MIPS64_BE,
DM_PPC_LE,
DM_PPC_BE,
DM_PPC64_LE,
DM_PPC64_BE,
DM_SPARC,
DM_SPARCV9,
DM_S390X,
DM_XCORE,
DM_M68K,
DM_M68K00,
DM_M68K10,
DM_M68K20,
DM_M68K30,
DM_M68K40,
DM_M68K60,
DM_TMS320C64X,
DM_M6800,
DM_M6801,
DM_M6805,
DM_M6808,
DM_M6809,
DM_M6811,
DM_CPU12,
DM_HD6301,
DM_HD6309,
DM_HCS08,
DM_EVM,
DM_RISKV32,
DM_RISKV64,
DM_RISKVC,
DM_MOS65XX,
DM_WASM,
DM_BPF_LE,
DM_BPF_BE
};
enum SYNTAX {
SYNTAX_DEFAULT = 0,
SYNTAX_INTEL,
SYNTAX_ATT,
SYNTAX_MASM,
SYNTAX_MOTOROLA
};
enum TYPE {
TYPE_UNKNOWN = 0,
// TODO more
};
// TODO reactOS
// TODO FreeDOS
enum OSNAME {
OSNAME_UNKNOWN = 0,
OSNAME_MULTIPLATFORM,
OSNAME_AIX,
OSNAME_ALPINELINUX,
OSNAME_AMIGA,
OSNAME_ANDROID,
OSNAME_AROS,
OSNAME_ASPLINUX,
OSNAME_BORLANDOSSERVICES,
OSNAME_BRIDGEOS,
OSNAME_DEBIANLINUX,
OSNAME_FENIXOS,
OSNAME_FREEBSD,
OSNAME_GENTOOLINUX,
OSNAME_HANCOMLINUX,
OSNAME_HPUX,
OSNAME_IOS,
OSNAME_IPADOS,
OSNAME_IPHONEOS,
OSNAME_IRIX,
OSNAME_LINUX,
OSNAME_MACOS,
OSNAME_MAC_OS,
OSNAME_MAC_OS_X,
OSNAME_MANDRAKELINUX,
OSNAME_MCLINUX,
OSNAME_MINIX,
OSNAME_MODESTO,
OSNAME_MSDOS,
OSNAME_NETBSD,
OSNAME_NSK,
OSNAME_OPENBSD,
OSNAME_OPENVMS,
OSNAME_OPENVOS,
OSNAME_OS2,
OSNAME_OS_X,
OSNAME_POSIX,
OSNAME_QNX,
OSNAME_REDHATLINUX,
OSNAME_SOLARIS,
OSNAME_STARTOSLINUX,
OSNAME_SUNOS,
OSNAME_SUSELINUX,
OSNAME_SYLLABLE,
OSNAME_TRU64,
OSNAME_TURBOLINUX,
OSNAME_TVOS,
OSNAME_UBUNTULINUX,
OSNAME_UEFI,
OSNAME_UNIX,
OSNAME_VINELINUX,
OSNAME_WATCHOS,
OSNAME_WINDOWS,
OSNAME_WINDOWSCE,
OSNAME_WINDRIVERLINUX,
OSNAME_XBOX,
OSNAME_JVM,
OSNAME_MACCATALYST,
OSNAME_MACDRIVERKIT,
OSNAME_MACFIRMWARE,
OSNAME_SEPOS
// TODO more
};
enum ENDIAN {
ENDIAN_UNKNOWN = 0,
ENDIAN_LITTLE,
ENDIAN_BIG
};
struct OSINFO {
OSNAME osName;
QString sOsVersion;
QString sBuild;
QString sArch;
MODE mode;
QString sType;
ENDIAN endian;
bool bIsVM;
};
struct FILEFORMATINFO {
bool bIsValid;
qint64 nSize;
FT fileType;
QString sString;
QString sExt;
QString sVersion;
QString sOptions;
};
struct _MEMORY_MAP {
XADDR nModuleAddress;
qint64 nImageSize;
qint64 nBinarySize;
XADDR nEntryPointAddress;
qint64 nCodeBase; // For MSDOS
qint64 nStartLoadOffset; // For MSDOS
FT fileType;
MODE mode;
ENDIAN endian;
QString sArch;
QString sType;
QList<_MEMORY_RECORD> listRecords;
};
enum SYMBOL_TYPE {
SYMBOL_TYPE_UNKNOWN,
SYMBOL_TYPE_EXPORT = 0x00000001,
SYMBOL_TYPE_IMPORT = 0x00000002,
SYMBOL_TYPE_LABEL = 0x00000004, // DATA
SYMBOL_TYPE_ANSISTRING = 0x00000008,
SYMBOL_TYPE_UNICODESTRING = 0x00000010,
SYMBOL_TYPE_ALL = 0xFFFFFFFF
};
struct SYMBOL_RECORD {
XADDR nAddress;
qint64 nSize;
XADDR nModuleAddress;
SYMBOL_TYPE symbolType;
qint32 nOrdinal; // For Windows OS;
QString sName;
QString sFunction;
};
enum HASH {
HASH_MD4 = 0,
HASH_MD5,
HASH_SHA1,
#ifndef QT_CRYPTOGRAPHICHASH_ONLY_SHA1
#if (QT_VERSION_MAJOR > 4)
HASH_SHA224,
HASH_SHA256,
HASH_SHA384,
HASH_SHA512,
#endif
// TODO Check more
// TODO Check Qt versions!
// HASH_KECCAK_224,
// HASH_KECCAK_256,
// HASH_KECCAK_384,
// HASH_KECCAK_512
#endif
};
enum MS_RECORD_TYPE {
MS_RECORD_TYPE_UNKNOWN = 0,
MS_RECORD_TYPE_STRING_ANSI,
MS_RECORD_TYPE_STRING_UTF8,
MS_RECORD_TYPE_STRING_UNICODE,
MS_RECORD_TYPE_SIGNATURE,
MS_RECORD_TYPE_VALUE
// TODO more PASCAL(A/U)
};
struct MS_RECORD {
qint64 nOffset;
XADDR nAddress;
QString sRegion;
qint64 nSize;
MS_RECORD_TYPE recordType;
QString sString;
QString sInfo;
};
struct OPCODE {
XADDR nAddress;
qint64 nSize;
QString sName;
};
struct MEMORY_REPLACE // For debuggers&breakpoints
{
XADDR nAddress;
qint64 nOffset;
qint64 nSize;
QByteArray baOriginal;
};
// struct XUINT128 {
// quint64 low;
// quint64 high;
// };
struct XVARIANT {
MODE mode;
bool bIsBigEndian;
union DUMMYUNION {
bool v_bool;
quint8 v_uint8;
quint16 v_uint16;
quint32 v_uint32;
quint64 v_uint64;
quint64 v_uint128[2];
quint64 v_uint256[4];
quint8 v_freg[10];
// mb TODO 256/512
} var;
};
struct PDRECORD {
qint64 nCurrent;
qint64 nTotal;
QString sStatus;
// bool bSuccess;
// bool bFinished;
bool bIsValid;
};
const static qint32 N_NUMBER_PDRECORDS = 5;
struct PDSTRUCT {
PDRECORD _pdRecord[N_NUMBER_PDRECORDS];
bool bIsStop;
quint64 nFinished;
// bool bIsDisable;
// QString sStatus;
// bool bErrors;
// bool bSuccess; // TODO important
QString sInfoString;
bool bCriticalError; // TODO !!!
};
private:
enum ST {
ST_COMPAREBYTES = 0,
ST_NOTNULL,
ST_ANSI,
ST_NOTANSI,
ST_NOTANSIANDNULL,
ST_FINDBYTES,
ST_SKIP,
ST_RELOFFSET,
ST_ADDRESS
};
struct SIGNATURE_RECORD {
XADDR nBaseAddress;
ST st;
QByteArray baData;
quint32 nSizeOfAddr;
qint64 nFindDelta;
qint32 nSize;
};
public:
explicit XBinary(QIODevice *pDevice = nullptr, bool bIsImage = false,
XADDR nModuleAddress = -1); // mb TODO parent for signals/slot
XBinary(const QString &sFileName);
~XBinary();
void setData(QIODevice *pDevice = nullptr, bool bIsImage = false, XADDR nModuleAddress = -1);
void setDevice(QIODevice *pDevice);
void setReadWriteMutex(QMutex *pReadWriteMutex);
void setFileName(const QString &sFileName);
qint64 safeReadData(QIODevice *pDevice, qint64 nPos, char *pData, qint64 nMaxLen, PDSTRUCT *pPdStruct);
qint64 safeWriteData(QIODevice *pDevice, qint64 nPos, const char *pData, qint64 nLen, PDSTRUCT *pPdStruct);
qint64 getSize();
static qint64 getSize(QIODevice *pDevice);
static qint64 getSize(const QString &sFileName);
void setMode(MODE mode);
virtual MODE getMode();
void setType(qint32 nType);
virtual qint32 getType();
virtual QString typeIdToString(qint32 nType);
QString getTypeAsString();
void setFileType(FT fileType);
virtual FT getFileType();
static QString modeIdToString(MODE mode);
static QString endianToString(ENDIAN endian);
void setArch(const QString &sArch);
virtual QString getArch();
void setFileFormatName(const QString &sFileFormatString);
virtual QString getFileFormatString();
void setFileFormatExt(const QString &sFileFormatExt);
virtual QString getFileFormatExt();
void setFileFormatSize(qint64 nFileFormatSize);
virtual qint64 getFileFormatSize(PDSTRUCT *pPdStruct);
virtual bool isSigned();
virtual OFFSETSIZE getSignOffsetSize(); // TODO rename
void setOsType(OSNAME osName);
void setOsVersion(const QString &sOsVersion);
virtual OSINFO getOsInfo();
virtual FILEFORMATINFO getFileFormatInfo(PDSTRUCT *pPdStruct);
void setEndian(ENDIAN endian);
virtual ENDIAN getEndian();
bool isPacked(double dEntropy);
enum CRT {
CRT_UNKNOWN = 0,
CRT_ERROR,
CRT_WARNING,
CRT_INFO
};
struct CHECKRECORD {
CRT crt;
qint64 nOffset;
qint64 nSize;
XADDR nAddress;
QString sText;
};
virtual bool checkFileFormat(quint64 nFlags, QList<CHECKRECORD> *pListCheckRecords, PDSTRUCT *pPdStruct);
static quint8 random8();
static quint16 random16();
static quint32 random32();
static quint64 random64();
static quint64 random(quint64 nLimit);
static QString randomString(qint32 nSize);
static QString fileTypeIdToString(FT fileType);
static QString fileTypeIdToExts(FT fileType);
static FT ftStringToFileTypeId(QString sFileType);
static QString fileTypeIdToFtString(FT fileType);
static QString convertFileName(const QString &sFileName);
static QString convertPathName(const QString &sPathName);
OS_STRING getOsAnsiString(qint64 nOffset, qint64 nSize);
struct FFOPTIONS {
QList<QString> *pListFileNames;
bool bSubdirectories;
bool *pbIsStop;
qint32 *pnNumberOfFiles;
// TODO filter
};
static void findFiles(const QString &sDirectoryName, FFOPTIONS *pFFOption, qint32 nLevel = 0);
static void findFiles(const QString &sDirectoryName, QList<QString> *pListFileNames);
static void findFiles(const QString &sDirectoryName, QList<QString> *pListFileNames, bool bSubDirectories, qint32 nLevel, PDSTRUCT *pPdStruct = nullptr);
static QString regExp(const QString &sRegExp, const QString &sString, qint32 nIndex);
static bool isRegExpPresent(const QString &sRegExp, const QString &sString);
static qint32 getRegExpCount(const QString &sRegExp, const QString &sString); // TODO Check!
static QString getRegExpSection(const QString &sRegExp, const QString &sString, qint32 nStart, qint32 nEnd);
static bool isRegExpValid(const QString &sRegExp);
qint64 read_array(qint64 nOffset, char *pBuffer, qint64 nMaxSize, PDSTRUCT *pPdStruct = nullptr);
QByteArray read_array(qint64 nOffset, qint64 nSize, PDSTRUCT *pPdStruct = nullptr);
qint64 write_array(qint64 nOffset, const char *pBuffer, qint64 nSize, PDSTRUCT *pPdStruct = nullptr);
qint64 write_array(qint64 nOffset, const QByteArray &baData, PDSTRUCT *pPdStruct = nullptr);
static QByteArray read_array(QIODevice *pDevice, qint64 nOffset, qint64 nSize, PDSTRUCT *pPdStruct = nullptr);
static qint64 read_array(QIODevice *pDevice, qint64 nOffset, char *pBuffer, qint64 nSize, PDSTRUCT *pPdStruct = nullptr);
static qint64 write_array(QIODevice *pDevice, qint64 nOffset, char *pBuffer, qint64 nSize, PDSTRUCT *pPdStruct = nullptr);
static qint64 write_array(QIODevice *pDevice, qint64 nOffset, const QByteArray &baData, PDSTRUCT *pPdStruct = nullptr);
quint8 read_uint8(qint64 nOffset);
qint8 read_int8(qint64 nOffset);
quint16 read_uint16(qint64 nOffset, bool bIsBigEndian = false);
qint16 read_int16(qint64 nOffset, bool bIsBigEndian = false);
quint32 read_uint32(qint64 nOffset, bool bIsBigEndian = false);
qint32 read_int32(qint64 nOffset, bool bIsBigEndian = false);
quint64 read_uint64(qint64 nOffset, bool bIsBigEndian = false);
qint64 read_int64(qint64 nOffset, bool bIsBigEndian = false);
float read_float16(qint64 nOffset, bool bIsBigEndian = false); // TODO Check
float read_float(qint64 nOffset, bool bIsBigEndian = false); // TODO Check
double read_double(qint64 nOffset, bool bIsBigEndian = false); // TODO Check
quint32 read_uint24(qint64 nOffset,
bool bIsBigEndian = false); // Uses UPX in header
qint32 read_int24(qint64 nOffset, bool bIsBigEndian = false);
qint64 write_ansiString(qint64 nOffset, const QString &sString, qint64 nMaxSize = -1);
void write_ansiStringFix(qint64 nOffset, qint64 nSize, const QString &sString);
qint64 write_unicodeString(qint64 nOffset, const QString &sString, qint64 nMaxSize = -1, bool bIsBigEndian = false);
QString read_ansiString(qint64 nOffset, qint64 nMaxSize = 256);
QString read_unicodeString(qint64 nOffset, qint64 nMaxSize = 256, bool bIsBigEndian = false);
QString read_ucsdString(qint64 nOffset);
QString read_utf8String(qint64 nOffset, qint64 nMaxSize = 256);
QString _read_utf8String(qint64 nOffset, qint64 nMaxSize = 256);
QString _read_utf8String(char *pData, qint64 nMaxSize);
QString _read_utf8String(qint64 nOffset, char *pData, qint32 nDataSize, qint32 nDataOffset);
QString read_codePageString(qint64 nOffset, qint64 nMaxByteSize = 256, const QString &sCodePage = "System");
bool isUnicodeStringLatin(qint64 nOffset, qint64 nMaxSize = 256, bool bIsBigEndian = false);
void write_uint8(qint64 nOffset, quint8 nValue);
void write_int8(qint64 nOffset, qint8 nValue);
void write_uint16(qint64 nOffset, quint16 nValue, bool bIsBigEndian = false);
void write_int16(qint64 nOffset, qint16 nValue, bool bIsBigEndian = false);
void write_uint32(qint64 nOffset, quint32 nValue, bool bIsBigEndian = false);
void write_int32(qint64 nOffset, qint32 nValue, bool bIsBigEndian = false);
void write_uint64(qint64 nOffset, quint64 nValue, bool bIsBigEndian = false);
void write_int64(qint64 nOffset, qint64 nValue, bool bIsBigEndian = false);
void write_float16(qint64 nOffset, float fValue,
bool bIsBigEndian = false); // TODO Check
void write_float(qint64 nOffset, float fValue,
bool bIsBigEndian = false); // TODO Check
void write_double(qint64 nOffset, double dValue,
bool bIsBigEndian = false); // TODO Check
QString read_UUID_bytes(qint64 nOffset); // uuid [16]
void write_UUID_bytes(qint64 nOffset, const QString &sValue); // uuid [16]
QString read_UUID(qint64 nOffset, bool bIsBigEndian = false);
static quint8 _read_uint8(char *pData);
static qint8 _read_int8(char *pData);
static quint16 _read_uint16(char *pData, bool bIsBigEndian = false);
static qint16 _read_int16(char *pData, bool bIsBigEndian = false);
static quint32 _read_uint32(char *pData, bool bIsBigEndian = false);
static qint32 _read_int32(char *pData, bool bIsBigEndian = false);
static quint64 _read_uint64(char *pData, bool bIsBigEndian = false);
static qint64 _read_int64(char *pData, bool bIsBigEndian = false);
static QString _read_ansiString(char *pData, qint32 nMaxSize = 50);
static QByteArray _read_byteArray(char *pData, qint32 nSize);
static float _read_float(char *pData,
bool bIsBigEndian = false); // TODO Check
static double _read_double(char *pData,
bool bIsBigEndian = false); // TODO Check
static quint64 _read_value(MODE mode, char *pData, bool bIsBigEndian = false);
// TODO read uin64, freg
static quint8 _read_uint8_safe(char *pBuffer, qint32 nBufferSize, qint32 nOffset);
static quint16 _read_uint16_safe(char *pBuffer, qint32 nBufferSize, qint32 nOffset, bool bIsBigEndian = false);
static quint32 _read_uint32_safe(char *pBuffer, qint32 nBufferSize, qint32 nOffset, bool bIsBigEndian = false);
static quint64 _read_uint64_safe(char *pBuffer, qint32 nBufferSize, qint32 nOffset, bool bIsBigEndian = false);
static QString _read_ansiString_safe(char *pBuffer, qint32 nBufferSize, qint32 nOffset, qint32 nMaxSize = 50);
static void _write_uint8(char *pData, quint8 nValue);
static void _write_int8(char *pData, qint8 nValue);
static void _write_uint16(char *pData, quint16 nValue, bool bIsBigEndian = false);
static void _write_int16(char *pData, qint16 nValue, bool bIsBigEndian = false);
static void _write_uint32(char *pData, quint32 nValue, bool bIsBigEndian = false);
static void _write_int32(char *pData, qint32 nValue, bool bIsBigEndian = false);
static void _write_uint64(char *pData, quint64 nValue, bool bIsBigEndian = false);
static void _write_int64(char *pData, qint64 nValue, bool bIsBigEndian = false);
static void _write_float(char *pData, float fValue,
bool bIsBigEndian = false); // TODO Check
static void _write_double(char *pData, double dValue,
bool bIsBigEndian = false); // TODO Check
static void _write_value(MODE mode, char *pData, quint64 nValue, bool bIsBigEndian = false);
// TODO write uin64, freg
quint8 read_bcd_uint8(qint64 nOffset);
quint16 read_bcd_uint16(qint64 nOffset, bool bIsBigEndian = false);
quint16 read_bcd_uint32(qint64 nOffset, bool bIsBigEndian = false);
quint16 read_bcd_uint64(qint64 nOffset, bool bIsBigEndian = false);
quint8 _bcd_decimal(quint8 nValue);
qint64 _find_array(ST st, qint64 nOffset, qint64 nSize, const char *pArray, qint64 nArraySize, PDSTRUCT *pPdStruct = nullptr);
qint64 find_array(qint64 nOffset, qint64 nSize, const char *pArray, qint64 nArraySize, PDSTRUCT *pPdStruct = nullptr);
qint64 find_byteArray(qint64 nOffset, qint64 nSize, const QByteArray &baData, PDSTRUCT *pPdStruct = nullptr);
qint64 find_uint8(qint64 nOffset, qint64 nSize, quint8 nValue, PDSTRUCT *pPdStruct = nullptr);
qint64 find_int8(qint64 nOffset, qint64 nSize, qint8 nValue, PDSTRUCT *pPdStruct = nullptr);
qint64 find_uint16(qint64 nOffset, qint64 nSize, quint16 nValue, bool bIsBigEndian = false, PDSTRUCT *pPdStruct = nullptr);
qint64 find_int16(qint64 nOffset, qint64 nSize, qint16 nValue, bool bIsBigEndian = false, PDSTRUCT *pPdStruct = nullptr);
qint64 find_uint32(qint64 nOffset, qint64 nSize, quint32 nValue, bool bIsBigEndian = false, PDSTRUCT *pPdStruct = nullptr);
qint64 find_int32(qint64 nOffset, qint64 nSize, qint32 nValue, bool bIsBigEndian = false, PDSTRUCT *pPdStruct = nullptr);
qint64 find_uint64(qint64 nOffset, qint64 nSize, quint64 nValue, bool bIsBigEndian = false, PDSTRUCT *pPdStruct = nullptr);
qint64 find_int64(qint64 nOffset, qint64 nSize, qint64 nValue, bool bIsBigEndian = false, PDSTRUCT *pPdStruct = nullptr);
qint64 find_float(qint64 nOffset, qint64 nSize, float fValue, bool bIsBigEndian = false, PDSTRUCT *pPdStruct = nullptr);
qint64 find_double(qint64 nOffset, qint64 nSize, double dValue, bool bIsBigEndian = false, PDSTRUCT *pPdStruct = nullptr);
static void endian_float(float *pValue, bool bIsBigEndian);
static void endian_double(double *pValue, bool bIsBigEndian);
qint64 find_ansiString(qint64 nOffset, qint64 nSize, const QString &sString, PDSTRUCT *pPdStruct = nullptr);
qint64 find_unicodeString(qint64 nOffset, qint64 nSize, const QString &sString, bool bIsBigEndian, PDSTRUCT *pPdStruct = nullptr);
qint64 find_utf8String(qint64 nOffset, qint64 nSize, const QString &sString, PDSTRUCT *pPdStruct = nullptr);
qint64 find_signature(qint64 nOffset, qint64 nSize, const QString &sSignature, qint64 *pnResultSize = 0, PDSTRUCT *pPdStruct = nullptr);
qint64 find_signature(_MEMORY_MAP *pMemoryMap, qint64 nOffset, qint64 nSize, const QString &sSignature, qint64 *pnResultSize = nullptr,
PDSTRUCT *pPdStruct = nullptr);
qint64 find_ansiStringI(qint64 nOffset, qint64 nSize, const QString &sString, PDSTRUCT *pPdStruct = nullptr);
qint64 find_unicodeStringI(qint64 nOffset, qint64 nSize, const QString &sString, bool bIsBigEndian, PDSTRUCT *pPdStruct = nullptr);
qint64 find_utf8StringI(qint64 nOffset, qint64 nSize, const QString &sString, PDSTRUCT *pPdStruct = nullptr);
// TODO find_codePageString
// TODO find_codePageStringI
static quint8 getBits_uint8(quint8 nValue, qint32 nBitOffset, qint32 nBitSize);
static quint16 getBits_uint16(quint16 nValue, qint32 nBitOffset, qint32 nBitSize);
static quint32 getBits_uint32(quint32 nValue, qint32 nBitOffset, qint32 nBitSize);
static quint64 getBits_uint64(quint64 nValue, qint32 nBitOffset, qint32 nBitSize);
struct STRINGSEARCH_OPTIONS {
// TODO more
qint32 nLimit;
qint64 nMinLenght;
qint64 nMaxLenght;
bool bAnsi;
// bool bUTF8;
bool bUnicode;
bool bNullTerminated;
QString sMask;
// QString sANSICodec;
bool bLinks;
};
enum VT {
VT_UNKNOWN = 0,
VT_ANSISTRING,
VT_ANSISTRING_I,
VT_UNICODESTRING,
VT_UNICODESTRING_I,
VT_UTF8STRING,
VT_UTF8STRING_I,
VT_SIGNATURE,
VT_BYTE,
VT_WORD,
VT_DWORD,
VT_QWORD,
VT_CHAR,
VT_UCHAR,
VT_SHORT,
VT_USHORT,
VT_INT,
VT_UINT,
VT_INT64,
VT_UINT64,
VT_DOUBLE,
VT_FLOAT,
// TODO UTF8
// TODO pascal strings(A/U)
};
enum SF {
SF_BEGIN = 0,
SF_CURRENTOFFSET
};
struct SEARCHDATA {
qint64 nResultOffset;
qint64 nResultSize;
qint64 nCurrentOffset;
SF startFrom;
QVariant varValue;
VT valueType;
ENDIAN endian;
bool bIsInit;
};
bool _addMultiSearchStringRecord(QList<MS_RECORD> *pList, MS_RECORD *pRecord, STRINGSEARCH_OPTIONS *pSsOptions);
QList<MS_RECORD> multiSearch_allStrings(_MEMORY_MAP *pMemoryMap, qint64 nOffset, qint64 nSize, STRINGSEARCH_OPTIONS ssOptions, PDSTRUCT *pPdStruct = nullptr);
QList<MS_RECORD> multiSearch_signature(qint64 nOffset, qint64 nSize, qint32 nLimit, const QString &sSignature, const QString &sInfo = "",
PDSTRUCT *pPdStruct = nullptr);
QList<MS_RECORD> multiSearch_signature(_MEMORY_MAP *pMemoryMap, qint64 nOffset, qint64 nSize, qint32 nLimit, const QString &sSignature, const QString &sInfo = "",
PDSTRUCT *pPdStruct = nullptr);
QList<MS_RECORD> multiSearch_value(qint64 nOffset, qint64 nSize, qint32 nLimit, QVariant varValue, VT valueType, bool bIsBigEndian, PDSTRUCT *pPdStruct = nullptr);
QList<MS_RECORD> multiSearch_value(_MEMORY_MAP *pMemoryMap, qint64 nOffset, qint64 nSize, qint32 nLimit, QVariant varValue, VT valueType, bool bIsBigEndian,
PDSTRUCT *pPdStruct = nullptr);
qint64 find_value(_MEMORY_MAP *pMemoryMap, qint64 nOffset, qint64 nSize, QVariant varValue, VT valueType, bool bIsBigEndian, qint64 *pnResultSize,
PDSTRUCT *pPdStruct = nullptr);
static QString msRecordTypeIdToString(MS_RECORD_TYPE msRecordTypeId);
static QString valueTypeToString(VT valueType);
static QString getValueString(QVariant varValue, VT valueType);
static qint32 getValueSize(QVariant varValue, VT valueType);
static VT getValueType(quint64 nValue);
static QByteArray getUnicodeString(const QString &sString, bool bIsBigEndian);
static QByteArray getStringData(MS_RECORD_TYPE msRecordTypeId, const QString &sString, bool bAddNull);
bool isSignaturePresent(_MEMORY_MAP *pMemoryMap, qint64 nOffset, qint64 nSize, const QString &sSignature, PDSTRUCT *pPdStruct = nullptr);
static bool isSignatureValid(const QString &sSignature, PDSTRUCT *pPdStruct = nullptr);
static bool createFile(const QString &sFileName, qint64 nFileSize = 0);
static bool isFileExists(const QString &sFileName, bool bTryToOpen = false);
static bool removeFile(const QString &sFileName);
static bool copyFile(const QString &sSrcFileName, const QString &sDestFileName);
static bool moveFile(const QString &sSrcFileName, const QString &sDestFileName);
static bool moveFileToDirectory(const QString &sSrcFileName, const QString &sDestDirectory);
static QString convertFileNameSymbols(const QString &sFileName);
static QString getBaseFileName(const QString &sFileName);
static bool createDirectory(const QString &sDirectoryName);
static bool isDirectoryExists(const QString &sDirectoryName);
static bool removeDirectory(const QString &sDirectoryName);
static bool isDirectoryEmpty(const QString &sDirectoryName);
static QByteArray readFile(const QString &sFileName, PDSTRUCT *pPdStruct = nullptr);
static bool readFile(const QString &sFileName, char *pBuffer, qint64 nSize, PDSTRUCT *pPdStruct = nullptr);
static void _copyMemory(char *pDest, const char *pSource, qint64 nSize);
static void _zeroMemory(char *pDest, qint64 nSize);
static bool _isMemoryZeroFilled(char *pSource, qint64 nSize);
static bool _isMemoryNotNull(char *pSource, qint64 nSize);
static bool _isMemoryAnsi(char *pSource, qint64 nSize);
static bool _isMemoryNotAnsi(char *pSource, qint64 nSize);
static bool _isMemoryNotAnsiAndNull(char *pSource, qint64 nSize);
static bool copyDeviceMemory(QIODevice *pSourceDevice, qint64 nSourceOffset, QIODevice *pDestDevice, qint64 nDestOffset, qint64 nSize, quint32 nBufferSize = 0x1000);
bool copyMemory(qint64 nSourceOffset, qint64 nDestOffset, qint64 nSize, quint32 nBufferSize = 1, bool bReverse = false);
bool zeroFill(qint64 nOffset, qint64 nSize);
static bool compareMemory(char *pMemory1, const char *pMemory2, qint64 nSize);
// For strings compare
static bool compareMemoryByteI(quint8 *pMemory, const quint8 *pMemoryU, const quint8 *pMemoryL,
qint64 nSize); // Ansi
static bool compareMemoryWordI(quint16 *pMemory, const quint16 *pMemoryU, const quint16 *pMemoryL,
qint64 nSize); // Unicode
bool isOffsetValid(qint64 nOffset);
bool isAddressValid(XADDR nAddress);
bool isRelAddressValid(qint64 nRelAddress);
bool isAddressPhysical(XADDR nAddress);
XADDR offsetToAddress(qint64 nOffset);