Theodosius  v3.0
Jit linker, mapper, obfuscator, and mutator
next_inst_pass.hpp
Go to the documentation of this file.
1 // Copyright (c) 2022, _xeroxz
2 // All rights reserved.
3 //
4 // Redistribution and use in source and binary forms, with or without
5 // modification, are permitted provided that the following conditions are met:
6 //
7 // 1. Redistributions of source code must retain the above copyright notice,
8 // this list of conditions and the following disclaimer.
9 //
10 // 2. Redistributions in binary form must reproduce the above copyright notice,
11 // this list of conditions and the following disclaimer in the documentation
12 // and/or other materials provided with the distribution.
13 //
14 // 3. Neither the name of the copyright holder nor the names of its
15 // contributors may be used to endorse or promote products derived from
16 // this software without specific prior written permission.
17 //
18 // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
19 // AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
20 // IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
21 // ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
22 // LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
23 // CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
24 // SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
25 // INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
26 // CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
27 // ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
28 // POSSIBILITY OF SUCH DAMAGE.
29 //
30 
31 #pragma once
32 #include <obf/pass.hpp>
33 
34 namespace theo::obf {
85 class next_inst_pass_t : public pass_t {
87  xed_state_t istate{XED_MACHINE_MODE_LONG_64, XED_ADDRESS_WIDTH_64b};
88  xed_decoded_inst_zero_set_mode(&m_tmp_inst, &istate);
89  xed_decode(&m_tmp_inst, m_type_inst_bytes, sizeof(m_type_inst_bytes));
90  };
91 
92  public:
93  static next_inst_pass_t* get();
94  void run(decomp::symbol_t* sym);
95 
96  private:
97  std::optional<recomp::reloc_t*> has_next_inst_reloc(decomp::symbol_t*);
98  xed_decoded_inst_t m_tmp_inst;
99  std::uint8_t m_type_inst_bytes[9] = {0x48, 0xC7, 0x44, 0x24, 0x08,
100  0x44, 0x33, 0x22, 0x11};
101 };
102 } // namespace theo::obf
symbol_t is an abstraction upon the coff symbol. this allows for easier manipulation of the symbol....
Definition: symbol.hpp:53
This pass is used to generate transformations and jmp code to change RIP to the next instruction.
static next_inst_pass_t * get()
void run(decomp::symbol_t *sym)
virtual method which must be implimented by the pass that inherits this class.
the pass_t class is a base clase for all passes made. you must override the pass_t::run virtual funct...
Definition: pass.hpp:55
pass_t(decomp::sym_type_t sym_type)
the explicit constructor of the pass_t base class.
Definition: pass.hpp:63
this is the main namespace for obfuscation related things.
Definition: engine.hpp:36