✝️ James 4:13-15 Come now, you who say, “Today or tomorrow we will go to such and such a town and spend a year there, doing business and making money.” Yet you do not even know what tomorrow will bring. What is your life? For you are a mist that appears for a little while and then vanishes. Instead you ought to say, “If the Lord wishes, we will live and do this or that.” ## [Part 1 Reverse engineering](<#Part 1 Reverse engineering>) ## [Part 2 Proof of concept](<#Part 2 Proof of concept>) ## Part 1 Reverse engineering I was bored and decided to mess around with radare2 and I discovered something pretty cool! So uh before we start I want to tell you how I like to do things, IF the code im looking at is not assembly THEN I don't want to engage, but why you may ask, and the answer is cuz I love assembly because I can see how the binary really works and ikik "muh anti RE techniques" but ignore that, so I compiled r2 with legit everything so it is easier to reverse! I will show you the function `cmd_interpret` but I won't explain the whole function but I will send it in full below, I will only talk about the stuff needed. The reason the function gets called is because of `.`. So, strtab can contain newlines and r2 stores it as such. Anyways, I will start here `loc_1058423A4`, so if the zeroth byte of input signed is greater than 9 then we are at bypass, and there and we make a copy of the input and store it in \*(X29 + inp), input-chan for short! We search for the character `~` in input-chan and store a pointer to it in \*(X29 + filter), or fil for short! So, if fil is 0 then we don't store WZR, aka the 32 bit zero register for AARCH64, bytes at fil, we store \*(\*(core + 0x50) + 0x6F3) & 1 at \*(SP + 0xE0 + var\_B1) and store WZR at \*(\*(core + 0x50) + 0x6F3), and call `r_core_cmd_str` with \*(X29 + core) and input-chan, we use the pseudo instruct MOV to make X8 equal to X0 and store that value at \*(X29 + str) and \*(X29 + ptr), also we r gonna call \*(X29 + core) core for short! We store \*(SP + 0xE0 + var\_B1) & 1 at \*(\*(core + 0x50) + 0x6F3), if fil is not 0 then we store `~` at it, we can ignore the `r_cons_break_push` so after that we are at a loop at `loc_1058424E0` and we can ignore `r_cons_is_breaked`, so now we are at `loc_1058424F8` and we find the newline character in pointer at \*(X29 + ptr), pointy for short! So, we store the result in \*(X29 + eol), end for short, and if end is 0 then we don't store WZR at end, if the zeroth byte at pointy is 0 then we don't call `bssl::ext_quic_transport_params_add_serverhello(bssl::SSL_HANDSHAKE *,cbb_st *)` with core and a string with the contents of pointy and fil, appended after pointy. After that, if end is 0 then we exit the loop, else we set pointy to end + 1! and continue the loop! So that was the important part, but what is that `bssl` function you may be asking? The answer is that it just calls `r_core_cmd` AKA treat the string with the contents of pointy and fil appended after the contents of pointy! It is legit treated as an r2 command and ran! Anyways, here are the functions below! `bssl::ext_quic_transport_params_add_serverhello(bssl::SSL_HANDSHAKE *,cbb_st *)`: ``` __text:000000010571C640 __ZN4bsslL41ext_quic_transport_params_add_serverhelloEPNS_13SSL_HANDSHAKEEP6cbb_st_0 __text:000000010571C640 ; CODE XREF: r_main_radare2+8FC↑p __text:000000010571C640 ; r_main_radare2+1364↑p ... __text:000000010571C640 __text:000000010571C640 cstr = -0x10 __text:000000010571C640 core = -8 __text:000000010571C640 var_s0 = 0 __text:000000010571C640 var_s8 = 8 __text:000000010571C640 __text:000000010571C640 SUB SP, SP, #0x20 __text:000000010571C644 STP X29, X30, [SP,#0x10+var_s0] __text:000000010571C648 ADD X29, SP, #0x10 __text:000000010571C64C STR X0, [SP,#0x10+core] __text:000000010571C650 STR X1, [SP,#0x10+cstr] __text:000000010571C654 LDR X0, [SP,#0x10+core] ; core __text:000000010571C658 LDR X1, [SP,#0x10+cstr] ; cstr __text:000000010571C65C MOV W8, #0 __text:000000010571C660 AND W2, W8, #1 ; log __text:000000010571C664 BL r_core_cmd __text:000000010571C668 LDP X29, X30, [SP,#0x10+var_s0] __text:000000010571C66C ADD SP, SP, #0x20 ; ' ' __text:000000010571C670 RET __text:000000010571C670 ; End of function bssl::ext_quic_transport_params_add_serverhello(bssl::SSL_HANDSHAKE *,cbb_st *) ``` `cmd_interpret`: ``` __text:0000000105841CDC ; int __cdecl cmd_interpret(void *data, const char *input) __text:0000000105841CDC cmd_interpret ; DATA XREF: __const:000000010EAAF300↓o __text:0000000105841CDC __text:0000000105841CDC var_E0 = -0xE0 __text:0000000105841CDC var_D8 = -0xD8 __text:0000000105841CDC var_D0 = -0xD0 __text:0000000105841CDC var_C4 = -0xC4 __text:0000000105841CDC var_C0 = -0xC0 __text:0000000105841CDC var_B1 = -0xB1 __text:0000000105841CDC var_B0 = -0xB0 __text:0000000105841CDC v = -0xA8 __text:0000000105841CDC file = -0xA0 __text:0000000105841CDC var_98 = -0x98 __text:0000000105841CDC __s = -0x90 __text:0000000105841CDC __s1 = -0x88 __text:0000000105841CDC cstr = -0x80 __text:0000000105841CDC var_74 = -0x74 __text:0000000105841CDC var_70 = -0x70 __text:0000000105841CDC saddr = -0x68 __text:0000000105841CDC len = -0x60 __text:0000000105841CDC addr = -0x58 __text:0000000105841CDC cmd = -0x50 __text:0000000105841CDC core = -0x48 __text:0000000105841CDC inp = -0x40 __text:0000000105841CDC filter = -0x38 __text:0000000105841CDC eol = -0x30 __text:0000000105841CDC ptr = -0x28 __text:0000000105841CDC str = -0x20 __text:0000000105841CDC input = -0x18 __text:0000000105841CDC data = -0x10 __text:0000000105841CDC var_4 = -4 __text:0000000105841CDC var_s0 = 0 __text:0000000105841CDC __text:0000000105841CDC SUB SP, SP, #0xF0 __text:0000000105841CE0 STP X29, X30, [SP,#0xE0+var_s0] __text:0000000105841CE4 ADD X29, SP, #0xE0 __text:0000000105841CE8 STUR X0, [X29,#data] __text:0000000105841CEC STUR X1, [X29,#input] __text:0000000105841CF0 LDUR X8, [X29,#data] __text:0000000105841CF4 STUR X8, [X29,#core] __text:0000000105841CF8 LDUR X0, [X29,#input] ; __s1 __text:0000000105841CFC ADRL X1, asc_10E016AD4 ; "?" __text:0000000105841D04 BL _strcmp.island __text:0000000105841D08 CBNZ W0, loc_105841D2C __text:0000000105841D0C B loc_105841D10 __text:0000000105841D10 ; --------------------------------------------------------------------------- __text:0000000105841D10 __text:0000000105841D10 loc_105841D10 ; CODE XREF: cmd_interpret+30↑j __text:0000000105841D10 LDUR X8, [X29,#core] __text:0000000105841D14 LDR X0, [X8,#0x50] ; cons __text:0000000105841D18 ADRL X1, help_msg_dot ; help __text:0000000105841D20 BL r_cons_cmd_help __text:0000000105841D24 STUR WZR, [X29,#var_4] __text:0000000105841D28 B loc_1058425A8 __text:0000000105841D2C ; --------------------------------------------------------------------------- __text:0000000105841D2C __text:0000000105841D2C loc_105841D2C ; CODE XREF: cmd_interpret+2C↑j __text:0000000105841D2C LDUR X8, [X29,#input] __text:0000000105841D30 LDRSB W8, [X8] __text:0000000105841D34 STR W8, [SP,#0xE0+var_C4] __text:0000000105841D38 CBZ W8, loc_105841DB0 __text:0000000105841D3C B loc_105841D40 __text:0000000105841D40 ; --------------------------------------------------------------------------- __text:0000000105841D40 __text:0000000105841D40 loc_105841D40 ; CODE XREF: cmd_interpret+60↑j __text:0000000105841D40 LDR W8, [SP,#0xE0+var_C4] __text:0000000105841D44 SUBS W8, W8, #0x20 ; ' ' __text:0000000105841D48 B.EQ loc_105842190 __text:0000000105841D4C B loc_105841D50 __text:0000000105841D50 ; --------------------------------------------------------------------------- __text:0000000105841D50 __text:0000000105841D50 loc_105841D50 ; CODE XREF: cmd_interpret+70↑j __text:0000000105841D50 LDR W8, [SP,#0xE0+var_C4] __text:0000000105841D54 SUBS W8, W8, #0x21 ; '!' __text:0000000105841D58 B.EQ loc_10584234C __text:0000000105841D5C B loc_105841D60 __text:0000000105841D60 ; --------------------------------------------------------------------------- __text:0000000105841D60 __text:0000000105841D60 loc_105841D60 ; CODE XREF: cmd_interpret+80↑j __text:0000000105841D60 LDR W8, [SP,#0xE0+var_C4] __text:0000000105841D64 SUBS W8, W8, #0x27 ; ''' __text:0000000105841D68 B.EQ loc_105841DC0 __text:0000000105841D6C B loc_105841D70 __text:0000000105841D70 ; --------------------------------------------------------------------------- __text:0000000105841D70 __text:0000000105841D70 loc_105841D70 ; CODE XREF: cmd_interpret+90↑j __text:0000000105841D70 LDR W8, [SP,#0xE0+var_C4] __text:0000000105841D74 SUBS W8, W8, #0x28 ; '(' __text:0000000105841D78 B.EQ loc_105842370 __text:0000000105841D7C B loc_105841D80 __text:0000000105841D80 ; --------------------------------------------------------------------------- __text:0000000105841D80 __text:0000000105841D80 loc_105841D80 ; CODE XREF: cmd_interpret+A0↑j __text:0000000105841D80 LDR W8, [SP,#0xE0+var_C4] __text:0000000105841D84 SUBS W8, W8, #0x2A ; '*' __text:0000000105841D88 B.EQ loc_1058420BC __text:0000000105841D8C B loc_105841D90 __text:0000000105841D90 ; --------------------------------------------------------------------------- __text:0000000105841D90 __text:0000000105841D90 loc_105841D90 ; CODE XREF: cmd_interpret+B0↑j __text:0000000105841D90 LDR W8, [SP,#0xE0+var_C4] __text:0000000105841D94 SUBS W8, W8, #0x2D ; '-' __text:0000000105841D98 B.EQ loc_105842138 __text:0000000105841D9C B loc_105841DA0 __text:0000000105841DA0 ; --------------------------------------------------------------------------- __text:0000000105841DA0 __text:0000000105841DA0 loc_105841DA0 ; CODE XREF: cmd_interpret+C0↑j __text:0000000105841DA0 LDR W8, [SP,#0xE0+var_C4] __text:0000000105841DA4 SUBS W8, W8, #0x2E ; '.' __text:0000000105841DA8 B.EQ loc_105841FCC __text:0000000105841DAC B loc_1058423A4 __text:0000000105841DB0 ; --------------------------------------------------------------------------- __text:0000000105841DB0 __text:0000000105841DB0 loc_105841DB0 ; CODE XREF: cmd_interpret+5C↑j __text:0000000105841DB0 LDUR X0, [X29,#core] ; core __text:0000000105841DB4 MOV W1, #0 ; next __text:0000000105841DB8 BL lastcmd_repeat __text:0000000105841DBC B loc_1058425A0 __text:0000000105841DC0 ; --------------------------------------------------------------------------- __text:0000000105841DC0 __text:0000000105841DC0 loc_105841DC0 ; CODE XREF: cmd_interpret+8C↑j __text:0000000105841DC0 LDUR X8, [X29,#input] __text:0000000105841DC4 ADD X8, X8, #1 __text:0000000105841DC8 STUR X8, [X29,#cmd] __text:0000000105841DCC LDUR X8, [X29,#core] __text:0000000105841DD0 LDR X8, [X8,#0x18] __text:0000000105841DD4 STUR X8, [X29,#addr] __text:0000000105841DD8 LDUR X8, [X29,#input] __text:0000000105841DDC LDRSB W8, [X8,#1] __text:0000000105841DE0 SUBS W8, W8, #0x40 ; '@' __text:0000000105841DE4 B.NE loc_105841EA0 __text:0000000105841DE8 B loc_105841DEC __text:0000000105841DEC ; --------------------------------------------------------------------------- __text:0000000105841DEC __text:0000000105841DEC loc_105841DEC ; CODE XREF: cmd_interpret+10C↑j __text:0000000105841DEC LDUR X8, [X29,#input] __text:0000000105841DF0 ADD X0, X8, #1 ; __s __text:0000000105841DF4 MOV W1, #0x27 ; ''' ; __c __text:0000000105841DF8 BL _strchr.island __text:0000000105841DFC STUR X0, [X29,#cmd] __text:0000000105841E00 LDUR X8, [X29,#cmd] __text:0000000105841E04 CBNZ X8, loc_105841E54 __text:0000000105841E08 B loc_105841E0C __text:0000000105841E0C ; --------------------------------------------------------------------------- __text:0000000105841E0C __text:0000000105841E0C loc_105841E0C ; CODE XREF: cmd_interpret+12C↑j __text:0000000105841E0C MOV W0, #1 ; level __text:0000000105841E10 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:0000000105841E18 BL r_log_match __text:0000000105841E1C TBZ W0, #0, loc_105841E4C __text:0000000105841E20 B loc_105841E24 __text:0000000105841E24 ; --------------------------------------------------------------------------- __text:0000000105841E24 __text:0000000105841E24 loc_105841E24 ; CODE XREF: cmd_interpret+144↑j __text:0000000105841E24 MOV W0, #1 ; level __text:0000000105841E28 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:0000000105841E30 ADRL X2, aSourceLibrCore_43 ; "../source/libr/core/cmd.c" __text:0000000105841E38 MOV W3, #0x902 ; line __text:0000000105841E3C ADRL X4, aMissingSeparat ; "Missing ' separator after .'@" __text:0000000105841E44 BL r_log_message __text:0000000105841E48 B loc_105841E4C __text:0000000105841E4C ; --------------------------------------------------------------------------- __text:0000000105841E4C __text:0000000105841E4C loc_105841E4C ; CODE XREF: cmd_interpret+140↑j __text:0000000105841E4C ; cmd_interpret+16C↑j __text:0000000105841E4C STUR WZR, [X29,#var_4] __text:0000000105841E50 B loc_1058425A8 __text:0000000105841E54 ; --------------------------------------------------------------------------- __text:0000000105841E54 __text:0000000105841E54 loc_105841E54 ; CODE XREF: cmd_interpret+128↑j __text:0000000105841E54 LDUR X8, [X29,#cmd] __text:0000000105841E58 LDUR X9, [X29,#input] __text:0000000105841E5C SUBS X8, X8, X9 __text:0000000105841E60 ADD X8, X8, #2 __text:0000000105841E64 STUR X8, [X29,#len] __text:0000000105841E68 LDUR X8, [X29,#input] __text:0000000105841E6C ADD X0, X8, #2 ; ptr __text:0000000105841E70 LDUR X8, [X29,#len] __text:0000000105841E74 MOV X1, X8 ; len __text:0000000105841E78 BL r_str_ndup __text:0000000105841E7C STUR X0, [X29,#saddr] __text:0000000105841E80 LDUR X8, [X29,#core] __text:0000000105841E84 LDR X0, [X8,#0x68] ; s __text:0000000105841E88 LDUR X1, [X29,#saddr] ; adj __text:0000000105841E8C BL r_num_get __text:0000000105841E90 STUR X0, [X29,#addr] __text:0000000105841E94 LDUR X0, [X29,#saddr] ; void * __text:0000000105841E98 BL _free.island __text:0000000105841E9C B loc_105841EA0 __text:0000000105841EA0 ; --------------------------------------------------------------------------- __text:0000000105841EA0 __text:0000000105841EA0 loc_105841EA0 ; CODE XREF: cmd_interpret+108↑j __text:0000000105841EA0 ; cmd_interpret+1C0↑j __text:0000000105841EA0 LDUR X0, [X29,#core] ; core __text:0000000105841EA4 LDUR X1, [X29,#addr] ; addr __text:0000000105841EA8 LDUR X2, [X29,#cmd] ; cmd __text:0000000105841EAC BL r_core_call_str_at __text:0000000105841EB0 STR X0, [SP,#0xE0+var_70] __text:0000000105841EB4 LDUR X8, [X29,#core] __text:0000000105841EB8 LDR X0, [X8,#0x50] ; cons __text:0000000105841EBC MOV X2, #0 ; user __text:0000000105841EC0 MOV X1, X2 ; cb __text:0000000105841EC4 BL r_cons_break_push __text:0000000105841EC8 LDR X8, [SP,#0xE0+var_70] __text:0000000105841ECC STUR X8, [X29,#ptr] __text:0000000105841ED0 B loc_105841ED4 __text:0000000105841ED4 ; --------------------------------------------------------------------------- __text:0000000105841ED4 __text:0000000105841ED4 loc_105841ED4 ; CODE XREF: cmd_interpret+1F4↑j __text:0000000105841ED4 ; cmd_interpret+2D4↓j __text:0000000105841ED4 LDUR X8, [X29,#core] __text:0000000105841ED8 LDR X0, [X8,#0x50] ; cons __text:0000000105841EDC BL r_cons_is_breaked __text:0000000105841EE0 TBZ W0, #0, loc_105841EEC __text:0000000105841EE4 B loc_105841EE8 __text:0000000105841EE8 ; --------------------------------------------------------------------------- __text:0000000105841EE8 __text:0000000105841EE8 loc_105841EE8 ; CODE XREF: cmd_interpret+208↑j __text:0000000105841EE8 B loc_105841FB4 __text:0000000105841EEC ; --------------------------------------------------------------------------- __text:0000000105841EEC __text:0000000105841EEC loc_105841EEC ; CODE XREF: cmd_interpret+204↑j __text:0000000105841EEC LDUR X0, [X29,#ptr] ; __s __text:0000000105841EF0 MOV W1, #0xA ; __c __text:0000000105841EF4 BL _strchr.island __text:0000000105841EF8 STUR X0, [X29,#eol] __text:0000000105841EFC LDUR X8, [X29,#eol] __text:0000000105841F00 CBZ X8, loc_105841F14 __text:0000000105841F04 B loc_105841F08 __text:0000000105841F08 ; --------------------------------------------------------------------------- __text:0000000105841F08 __text:0000000105841F08 loc_105841F08 ; CODE XREF: cmd_interpret+228↑j __text:0000000105841F08 LDUR X8, [X29,#eol] __text:0000000105841F0C STRB WZR, [X8] __text:0000000105841F10 B loc_105841F14 __text:0000000105841F14 ; --------------------------------------------------------------------------- __text:0000000105841F14 __text:0000000105841F14 loc_105841F14 ; CODE XREF: cmd_interpret+224↑j __text:0000000105841F14 ; cmd_interpret+234↑j __text:0000000105841F14 LDUR X8, [X29,#ptr] __text:0000000105841F18 LDRB W8, [X8] __text:0000000105841F1C CBZ W8, loc_105841F94 __text:0000000105841F20 B loc_105841F24 __text:0000000105841F24 ; --------------------------------------------------------------------------- __text:0000000105841F24 __text:0000000105841F24 loc_105841F24 ; CODE XREF: cmd_interpret+244↑j __text:0000000105841F24 LDUR X0, [X29,#core] ; rnd __text:0000000105841F28 LDUR X1, [X29,#ptr] ; range __text:0000000105841F2C BL r_core_call __text:0000000105841F30 STR W0, [SP,#0xE0+var_74] __text:0000000105841F34 LDR W8, [SP,#0xE0+var_74] __text:0000000105841F38 CBZ W8, loc_105841F90 __text:0000000105841F3C B loc_105841F40 __text:0000000105841F40 ; --------------------------------------------------------------------------- __text:0000000105841F40 __text:0000000105841F40 loc_105841F40 ; CODE XREF: cmd_interpret+260↑j __text:0000000105841F40 MOV W0, #1 ; level __text:0000000105841F44 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:0000000105841F4C BL r_log_match __text:0000000105841F50 TBZ W0, #0, loc_105841F8C __text:0000000105841F54 B loc_105841F58 __text:0000000105841F58 ; --------------------------------------------------------------------------- __text:0000000105841F58 __text:0000000105841F58 loc_105841F58 ; CODE XREF: cmd_interpret+278↑j __text:0000000105841F58 LDUR X8, [X29,#ptr] __text:0000000105841F5C MOV X9, SP __text:0000000105841F60 STR X8, [X9,#0xE0+var_E0] __text:0000000105841F64 MOV W0, #1 ; level __text:0000000105841F68 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:0000000105841F70 ADRL X2, aSourceLibrCore_43 ; "../source/libr/core/cmd.c" __text:0000000105841F78 MOV W3, #0x917 ; line __text:0000000105841F7C ADRL X4, aWrongCommandS ; "Wrong command %s" __text:0000000105841F84 BL r_log_message __text:0000000105841F88 B loc_105841F8C __text:0000000105841F8C ; --------------------------------------------------------------------------- __text:0000000105841F8C __text:0000000105841F8C loc_105841F8C ; CODE XREF: cmd_interpret+274↑j __text:0000000105841F8C ; cmd_interpret+2AC↑j __text:0000000105841F8C B loc_105841FB4 __text:0000000105841F90 ; --------------------------------------------------------------------------- __text:0000000105841F90 __text:0000000105841F90 loc_105841F90 ; CODE XREF: cmd_interpret+25C↑j __text:0000000105841F90 B loc_105841F94 __text:0000000105841F94 ; --------------------------------------------------------------------------- __text:0000000105841F94 __text:0000000105841F94 loc_105841F94 ; CODE XREF: cmd_interpret+240↑j __text:0000000105841F94 ; cmd_interpret:loc_105841F90↑j __text:0000000105841F94 LDUR X8, [X29,#eol] __text:0000000105841F98 CBNZ X8, loc_105841FA4 __text:0000000105841F9C B loc_105841FA0 __text:0000000105841FA0 ; --------------------------------------------------------------------------- __text:0000000105841FA0 __text:0000000105841FA0 loc_105841FA0 ; CODE XREF: cmd_interpret+2C0↑j __text:0000000105841FA0 B loc_105841FB4 __text:0000000105841FA4 ; --------------------------------------------------------------------------- __text:0000000105841FA4 __text:0000000105841FA4 loc_105841FA4 ; CODE XREF: cmd_interpret+2BC↑j __text:0000000105841FA4 LDUR X8, [X29,#eol] __text:0000000105841FA8 ADD X8, X8, #1 __text:0000000105841FAC STUR X8, [X29,#ptr] __text:0000000105841FB0 B loc_105841ED4 __text:0000000105841FB4 ; --------------------------------------------------------------------------- __text:0000000105841FB4 __text:0000000105841FB4 loc_105841FB4 ; CODE XREF: cmd_interpret:loc_105841EE8↑j __text:0000000105841FB4 ; cmd_interpret:loc_105841F8C↑j ... __text:0000000105841FB4 LDUR X8, [X29,#core] __text:0000000105841FB8 LDR X0, [X8,#0x50] ; cons __text:0000000105841FBC BL r_cons_break_pop __text:0000000105841FC0 LDR X0, [SP,#0xE0+var_70] ; void * __text:0000000105841FC4 BL _free.island __text:0000000105841FC8 B loc_1058425A0 __text:0000000105841FCC ; --------------------------------------------------------------------------- __text:0000000105841FCC __text:0000000105841FCC loc_105841FCC ; CODE XREF: cmd_interpret+CC↑j __text:0000000105841FCC LDUR X8, [X29,#input] __text:0000000105841FD0 LDRSB W8, [X8,#1] __text:0000000105841FD4 SUBS W8, W8, #0x2E ; '.' __text:0000000105841FD8 B.NE loc_105841FF0 __text:0000000105841FDC B loc_105841FE0 __text:0000000105841FE0 ; --------------------------------------------------------------------------- __text:0000000105841FE0 __text:0000000105841FE0 loc_105841FE0 ; CODE XREF: cmd_interpret+300↑j __text:0000000105841FE0 LDUR X0, [X29,#core] ; core __text:0000000105841FE4 MOV W1, #1 ; next __text:0000000105841FE8 BL lastcmd_repeat __text:0000000105841FEC B loc_1058420B8 __text:0000000105841FF0 ; --------------------------------------------------------------------------- __text:0000000105841FF0 __text:0000000105841FF0 loc_105841FF0 ; CODE XREF: cmd_interpret+2FC↑j __text:0000000105841FF0 LDUR X8, [X29,#input] __text:0000000105841FF4 LDRSB W8, [X8,#1] __text:0000000105841FF8 SUBS W8, W8, #0x20 ; ' ' __text:0000000105841FFC B.NE loc_105842054 __text:0000000105842000 B loc_105842004 __text:0000000105842004 ; --------------------------------------------------------------------------- __text:0000000105842004 __text:0000000105842004 loc_105842004 ; CODE XREF: cmd_interpret+324↑j __text:0000000105842004 LDUR X8, [X29,#core] __text:0000000105842008 STR X8, [SP,#0xE0+var_D0] __text:000000010584200C LDUR X0, [X29,#input] ; str __text:0000000105842010 BL r_str_trim_head_ro __text:0000000105842014 MOV X1, X0 ; cmd __text:0000000105842018 LDR X0, [SP,#0xE0+var_D0] ; core __text:000000010584201C BL r_core_cmd_str_pipe __text:0000000105842020 STR X0, [SP,#0xE0+cstr] __text:0000000105842024 LDR X8, [SP,#0xE0+cstr] __text:0000000105842028 CBZ X8, loc_105842050 __text:000000010584202C B loc_105842030 __text:0000000105842030 ; --------------------------------------------------------------------------- __text:0000000105842030 __text:0000000105842030 loc_105842030 ; CODE XREF: cmd_interpret+350↑j __text:0000000105842030 LDUR X0, [X29,#core] ; core __text:0000000105842034 LDR X1, [SP,#0xE0+cstr] ; cstr __text:0000000105842038 MOV W8, #0 __text:000000010584203C AND W2, W8, #1 ; log __text:0000000105842040 BL r_core_cmd __text:0000000105842044 LDR X0, [SP,#0xE0+cstr] ; void * __text:0000000105842048 BL _free.island __text:000000010584204C B loc_105842050 __text:0000000105842050 ; --------------------------------------------------------------------------- __text:0000000105842050 __text:0000000105842050 loc_105842050 ; CODE XREF: cmd_interpret+34C↑j __text:0000000105842050 ; cmd_interpret+370↑j __text:0000000105842050 B loc_1058420B4 __text:0000000105842054 ; --------------------------------------------------------------------------- __text:0000000105842054 __text:0000000105842054 loc_105842054 ; CODE XREF: cmd_interpret+320↑j __text:0000000105842054 LDUR X8, [X29,#input] __text:0000000105842058 LDRSB W8, [X8,#1] __text:000000010584205C CBZ W8, loc_105842098 __text:0000000105842060 B loc_105842064 __text:0000000105842064 ; --------------------------------------------------------------------------- __text:0000000105842064 __text:0000000105842064 loc_105842064 ; CODE XREF: cmd_interpret+384↑j __text:0000000105842064 LDUR X8, [X29,#input] __text:0000000105842068 LDRSB W8, [X8,#1] __text:000000010584206C SUBS W8, W8, #0x3F ; '?' __text:0000000105842070 B.EQ loc_105842098 __text:0000000105842074 B loc_105842078 __text:0000000105842078 ; --------------------------------------------------------------------------- __text:0000000105842078 __text:0000000105842078 loc_105842078 ; CODE XREF: cmd_interpret+398↑j __text:0000000105842078 LDUR X0, [X29,#core] ; core __text:000000010584207C LDUR X8, [X29,#input] __text:0000000105842080 MOV X9, SP __text:0000000105842084 STR X8, [X9,#0xE0+var_E0] __text:0000000105842088 ADRL X1, aSS_43 ; "s%s" __text:0000000105842090 BL r_core_cmdf __text:0000000105842094 B loc_1058420B0 __text:0000000105842098 ; --------------------------------------------------------------------------- __text:0000000105842098 __text:0000000105842098 loc_105842098 ; CODE XREF: cmd_interpret+380↑j __text:0000000105842098 ; cmd_interpret+394↑j __text:0000000105842098 LDUR X8, [X29,#core] __text:000000010584209C LDR X0, [X8,#0x50] ; cons __text:00000001058420A0 ADRL X1, help_msg_dot ; help __text:00000001058420A8 BL r_cons_cmd_help __text:00000001058420AC B loc_1058420B0 __text:00000001058420B0 ; --------------------------------------------------------------------------- __text:00000001058420B0 __text:00000001058420B0 loc_1058420B0 ; CODE XREF: cmd_interpret+3B8↑j __text:00000001058420B0 ; cmd_interpret+3D0↑j __text:00000001058420B0 B loc_1058420B4 __text:00000001058420B4 ; --------------------------------------------------------------------------- __text:00000001058420B4 __text:00000001058420B4 loc_1058420B4 ; CODE XREF: cmd_interpret:loc_105842050↑j __text:00000001058420B4 ; cmd_interpret:loc_1058420B0↑j __text:00000001058420B4 B loc_1058420B8 __text:00000001058420B8 ; --------------------------------------------------------------------------- __text:00000001058420B8 __text:00000001058420B8 loc_1058420B8 ; CODE XREF: cmd_interpret+310↑j __text:00000001058420B8 ; cmd_interpret:loc_1058420B4↑j __text:00000001058420B8 B loc_1058425A0 __text:00000001058420BC ; --------------------------------------------------------------------------- __text:00000001058420BC __text:00000001058420BC loc_1058420BC ; CODE XREF: cmd_interpret+AC↑j __text:00000001058420BC LDUR X8, [X29,#input] __text:00000001058420C0 ADD X0, X8, #1 ; str __text:00000001058420C4 BL r_str_trim_head_ro __text:00000001058420C8 STR X0, [SP,#0xE0+__s1] __text:00000001058420CC LDR X0, [SP,#0xE0+__s1] ; __s1 __text:00000001058420D0 BL _strdup.island __text:00000001058420D4 STR X0, [SP,#0xE0+__s] __text:00000001058420D8 LDR X0, [SP,#0xE0+__s] ; __s __text:00000001058420DC MOV W1, #0x20 ; ' ' ; __c __text:00000001058420E0 BL _strchr.island __text:00000001058420E4 STR X0, [SP,#0xE0+var_98] __text:00000001058420E8 LDR X8, [SP,#0xE0+var_98] __text:00000001058420EC CBZ X8, loc_105842100 __text:00000001058420F0 B loc_1058420F4 __text:00000001058420F4 ; --------------------------------------------------------------------------- __text:00000001058420F4 __text:00000001058420F4 loc_1058420F4 ; CODE XREF: cmd_interpret+414↑j __text:00000001058420F4 LDR X8, [SP,#0xE0+var_98] __text:00000001058420F8 STRB WZR, [X8] __text:00000001058420FC B loc_105842100 __text:0000000105842100 ; --------------------------------------------------------------------------- __text:0000000105842100 __text:0000000105842100 loc_105842100 ; CODE XREF: cmd_interpret+410↑j __text:0000000105842100 ; cmd_interpret+420↑j __text:0000000105842100 LDR X8, [SP,#0xE0+__s] __text:0000000105842104 CBZ X8, loc_10584212C __text:0000000105842108 B loc_10584210C __text:000000010584210C ; --------------------------------------------------------------------------- __text:000000010584210C __text:000000010584210C loc_10584210C ; CODE XREF: cmd_interpret+42C↑j __text:000000010584210C LDR X8, [SP,#0xE0+__s] __text:0000000105842110 LDRSB W8, [X8] __text:0000000105842114 CBZ W8, loc_10584212C __text:0000000105842118 B loc_10584211C __text:000000010584211C ; --------------------------------------------------------------------------- __text:000000010584211C __text:000000010584211C loc_10584211C ; CODE XREF: cmd_interpret+43C↑j __text:000000010584211C LDUR X0, [X29,#core] ; core __text:0000000105842120 LDR X1, [SP,#0xE0+__s] ; file __text:0000000105842124 BL r_core_run_script __text:0000000105842128 B loc_10584212C __text:000000010584212C ; --------------------------------------------------------------------------- __text:000000010584212C __text:000000010584212C loc_10584212C ; CODE XREF: cmd_interpret+428↑j __text:000000010584212C ; cmd_interpret+438↑j ... __text:000000010584212C LDR X0, [SP,#0xE0+__s] ; void * __text:0000000105842130 BL _free.island __text:0000000105842134 B loc_1058425A0 __text:0000000105842138 ; --------------------------------------------------------------------------- __text:0000000105842138 __text:0000000105842138 loc_105842138 ; CODE XREF: cmd_interpret+BC↑j __text:0000000105842138 LDUR X8, [X29,#input] __text:000000010584213C LDRSB W8, [X8,#1] __text:0000000105842140 SUBS W8, W8, #0x3F ; '?' __text:0000000105842144 B.NE loc_105842178 __text:0000000105842148 B loc_10584214C __text:000000010584214C ; --------------------------------------------------------------------------- __text:000000010584214C __text:000000010584214C loc_10584214C ; CODE XREF: cmd_interpret+46C↑j __text:000000010584214C LDUR X8, [X29,#core] __text:0000000105842150 LDR X0, [X8,#0x50] ; cons __text:0000000105842154 ADRL X1, help_msg_dot ; help __text:000000010584215C ADRL X2, asc_10E13FE8B ; ".-" __text:0000000105842164 MOV W3, #0 ; spec __text:0000000105842168 MOV W8, #1 __text:000000010584216C AND W4, W8, #1 ; exact __text:0000000105842170 BL r_cons_cmd_help_match __text:0000000105842174 B loc_10584218C __text:0000000105842178 ; --------------------------------------------------------------------------- __text:0000000105842178 __text:0000000105842178 loc_105842178 ; CODE XREF: cmd_interpret+468↑j __text:0000000105842178 LDUR X0, [X29,#core] ; core __text:000000010584217C ADRL X1, asc_10E01725E ; "-" __text:0000000105842184 BL r_core_run_script __text:0000000105842188 B loc_10584218C __text:000000010584218C ; --------------------------------------------------------------------------- __text:000000010584218C __text:000000010584218C loc_10584218C ; CODE XREF: cmd_interpret+498↑j __text:000000010584218C ; cmd_interpret+4AC↑j __text:000000010584218C B loc_1058425A0 __text:0000000105842190 ; --------------------------------------------------------------------------- __text:0000000105842190 __text:0000000105842190 loc_105842190 ; CODE XREF: cmd_interpret+6C↑j __text:0000000105842190 LDUR X8, [X29,#input] __text:0000000105842194 ADD X0, X8, #1 ; str __text:0000000105842198 BL r_str_trim_head_ro __text:000000010584219C STR X0, [SP,#0xE0+file] __text:00000001058421A0 LDR X8, [SP,#0xE0+file] __text:00000001058421A4 LDRSB W8, [X8] __text:00000001058421A8 SUBS W8, W8, #0x24 ; ' __text:00000001058421AC B.NE loc_105842208 __text:00000001058421B0 B loc_1058421B4 __text:00000001058421B4 ; --------------------------------------------------------------------------- __text:00000001058421B4 __text:00000001058421B4 loc_1058421B4 ; CODE XREF: cmd_interpret+4D4↑j __text:00000001058421B4 LDR X8, [SP,#0xE0+file] __text:00000001058421B8 LDRB W8, [X8,#1] __text:00000001058421BC CBNZ W8, loc_105842208 __text:00000001058421C0 B loc_1058421C4 __text:00000001058421C4 ; --------------------------------------------------------------------------- __text:00000001058421C4 __text:00000001058421C4 loc_1058421C4 ; CODE XREF: cmd_interpret+4E4↑j __text:00000001058421C4 MOV W0, #1 ; level __text:00000001058421C8 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:00000001058421D0 BL r_log_match __text:00000001058421D4 TBZ W0, #0, loc_105842204 __text:00000001058421D8 B loc_1058421DC __text:00000001058421DC ; --------------------------------------------------------------------------- __text:00000001058421DC __text:00000001058421DC loc_1058421DC ; CODE XREF: cmd_interpret+4FC↑j __text:00000001058421DC MOV W0, #1 ; level __text:00000001058421E0 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:00000001058421E8 ADRL X2, aSourceLibrCore_43 ; "../source/libr/core/cmd.c" __text:00000001058421F0 MOV W3, #0x94D ; line __text:00000001058421F4 ADRL X4, aNoAliasNameGiv ; "No alias name given" __text:00000001058421FC BL r_log_message __text:0000000105842200 B loc_105842204 __text:0000000105842204 ; --------------------------------------------------------------------------- __text:0000000105842204 __text:0000000105842204 loc_105842204 ; CODE XREF: cmd_interpret+4F8↑j __text:0000000105842204 ; cmd_interpret+524↑j __text:0000000105842204 B loc_105842348 __text:0000000105842208 ; --------------------------------------------------------------------------- __text:0000000105842208 __text:0000000105842208 loc_105842208 ; CODE XREF: cmd_interpret+4D0↑j __text:0000000105842208 ; cmd_interpret+4E0↑j __text:0000000105842208 LDR X8, [SP,#0xE0+file] __text:000000010584220C LDRSB W8, [X8] __text:0000000105842210 SUBS W8, W8, #0x24 ; ' __text:0000000105842214 B.NE loc_1058422BC __text:0000000105842218 B loc_10584221C __text:000000010584221C ; --------------------------------------------------------------------------- __text:000000010584221C __text:000000010584221C loc_10584221C ; CODE XREF: cmd_interpret+53C↑j __text:000000010584221C LDUR X8, [X29,#core] __text:0000000105842220 LDR X0, [X8,#0x80] ; cmd __text:0000000105842224 LDR X8, [SP,#0xE0+file] __text:0000000105842228 ADD X1, X8, #1 ; k __text:000000010584222C BL r_cmd_alias_get __text:0000000105842230 STR X0, [SP,#0xE0+v] __text:0000000105842234 LDR X8, [SP,#0xE0+v] __text:0000000105842238 CBZ X8, loc_105842264 __text:000000010584223C B loc_105842240 __text:0000000105842240 ; --------------------------------------------------------------------------- __text:0000000105842240 __text:0000000105842240 loc_105842240 ; CODE XREF: cmd_interpret+560↑j __text:0000000105842240 LDR X0, [SP,#0xE0+v] ; v __text:0000000105842244 BL r_cmd_alias_val_strdup __text:0000000105842248 STR X0, [SP,#0xE0+var_B0] __text:000000010584224C LDUR X0, [X29,#core] ; core __text:0000000105842250 LDR X1, [SP,#0xE0+var_B0] ; cmd __text:0000000105842254 BL __ZN4bsslL41ext_quic_transport_params_add_serverhelloEPNS_13SSL_HANDSHAKEEP6cbb_st_0 ; bssl::ext_quic_transport_params_add_serverhello(bssl::SSL_HANDSHAKE *,cbb_st *) __text:0000000105842258 LDR X0, [SP,#0xE0+var_B0] ; void * __text:000000010584225C BL _free.island __text:0000000105842260 B loc_1058422B8 __text:0000000105842264 ; --------------------------------------------------------------------------- __text:0000000105842264 __text:0000000105842264 loc_105842264 ; CODE XREF: cmd_interpret+55C↑j __text:0000000105842264 MOV W0, #1 ; level __text:0000000105842268 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:0000000105842270 BL r_log_match __text:0000000105842274 TBZ W0, #0, loc_1058422B4 __text:0000000105842278 B loc_10584227C __text:000000010584227C ; --------------------------------------------------------------------------- __text:000000010584227C __text:000000010584227C loc_10584227C ; CODE XREF: cmd_interpret+59C↑j __text:000000010584227C LDR X8, [SP,#0xE0+file] __text:0000000105842280 ADD X8, X8, #1 __text:0000000105842284 MOV X9, SP __text:0000000105842288 STR X8, [X9,#0xE0+var_E0] __text:000000010584228C MOV W0, #1 ; level __text:0000000105842290 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:0000000105842298 ADRL X2, aSourceLibrCore_43 ; "../source/libr/core/cmd.c" __text:00000001058422A0 MOV W3, #0x955 ; line __text:00000001058422A4 ADRL X4, aNoSuchAliasS ; "No such alias \"$%s\"" __text:00000001058422AC BL r_log_message __text:00000001058422B0 B loc_1058422B4 __text:00000001058422B4 ; --------------------------------------------------------------------------- __text:00000001058422B4 __text:00000001058422B4 loc_1058422B4 ; CODE XREF: cmd_interpret+598↑j __text:00000001058422B4 ; cmd_interpret+5D4↑j __text:00000001058422B4 B loc_1058422B8 __text:00000001058422B8 ; --------------------------------------------------------------------------- __text:00000001058422B8 __text:00000001058422B8 loc_1058422B8 ; CODE XREF: cmd_interpret+584↑j __text:00000001058422B8 ; cmd_interpret:loc_1058422B4↑j __text:00000001058422B8 B loc_105842344 __text:00000001058422BC ; --------------------------------------------------------------------------- __text:00000001058422BC __text:00000001058422BC loc_1058422BC ; CODE XREF: cmd_interpret+538↑j __text:00000001058422BC LDUR X0, [X29,#core] ; core __text:00000001058422C0 LDR X1, [SP,#0xE0+file] ; file __text:00000001058422C4 BL r_core_run_script __text:00000001058422C8 TBNZ W0, #0, loc_105842330 __text:00000001058422CC B loc_1058422D0 __text:00000001058422D0 ; --------------------------------------------------------------------------- __text:00000001058422D0 __text:00000001058422D0 loc_1058422D0 ; CODE XREF: cmd_interpret+5F0↑j __text:00000001058422D0 MOV W0, #1 ; level __text:00000001058422D4 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:00000001058422DC BL r_log_match __text:00000001058422E0 TBZ W0, #0, loc_10584231C __text:00000001058422E4 B loc_1058422E8 __text:00000001058422E8 ; --------------------------------------------------------------------------- __text:00000001058422E8 __text:00000001058422E8 loc_1058422E8 ; CODE XREF: cmd_interpret+608↑j __text:00000001058422E8 LDR X8, [SP,#0xE0+file] __text:00000001058422EC MOV X9, SP __text:00000001058422F0 STR X8, [X9,#0xE0+var_E0] __text:00000001058422F4 MOV W0, #1 ; level __text:00000001058422F8 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:0000000105842300 ADRL X2, aSourceLibrCore_43 ; "../source/libr/core/cmd.c" __text:0000000105842308 MOV W3, #0x959 ; line __text:000000010584230C ADRL X4, aCannotFindScri ; "Cannot find script '%s'" __text:0000000105842314 BL r_log_message __text:0000000105842318 B loc_10584231C __text:000000010584231C ; --------------------------------------------------------------------------- __text:000000010584231C __text:000000010584231C loc_10584231C ; CODE XREF: cmd_interpret+604↑j __text:000000010584231C ; cmd_interpret+63C↑j __text:000000010584231C LDUR X8, [X29,#core] __text:0000000105842320 LDR X9, [X8,#0x68] __text:0000000105842324 MOV X8, #1 __text:0000000105842328 STR X8, [X9,#0x20] __text:000000010584232C B loc_105842340 __text:0000000105842330 ; --------------------------------------------------------------------------- __text:0000000105842330 __text:0000000105842330 loc_105842330 ; CODE XREF: cmd_interpret+5EC↑j __text:0000000105842330 LDUR X8, [X29,#core] __text:0000000105842334 LDR X8, [X8,#0x68] __text:0000000105842338 STR XZR, [X8,#0x20] __text:000000010584233C B loc_105842340 __text:0000000105842340 ; --------------------------------------------------------------------------- __text:0000000105842340 __text:0000000105842340 loc_105842340 ; CODE XREF: cmd_interpret+650↑j __text:0000000105842340 ; cmd_interpret+660↑j __text:0000000105842340 B loc_105842344 __text:0000000105842344 ; --------------------------------------------------------------------------- __text:0000000105842344 __text:0000000105842344 loc_105842344 ; CODE XREF: cmd_interpret:loc_1058422B8↑j __text:0000000105842344 ; cmd_interpret:loc_105842340↑j __text:0000000105842344 B loc_105842348 __text:0000000105842348 ; --------------------------------------------------------------------------- __text:0000000105842348 __text:0000000105842348 loc_105842348 ; CODE XREF: cmd_interpret:loc_105842204↑j __text:0000000105842348 ; cmd_interpret:loc_105842344↑j __text:0000000105842348 B loc_1058425A0 __text:000000010584234C ; --------------------------------------------------------------------------- __text:000000010584234C __text:000000010584234C loc_10584234C ; CODE XREF: cmd_interpret+7C↑j __text:000000010584234C LDUR X8, [X29,#core] __text:0000000105842350 STR X8, [SP,#0xE0+var_D8] __text:0000000105842354 LDUR X8, [X29,#input] __text:0000000105842358 ADD X0, X8, #1 ; str __text:000000010584235C BL r_str_trim_head_ro __text:0000000105842360 MOV X1, X0 ; command __text:0000000105842364 LDR X0, [SP,#0xE0+var_D8] ; core __text:0000000105842368 BL r_core_cmd_command __text:000000010584236C B loc_1058425A0 __text:0000000105842370 ; --------------------------------------------------------------------------- __text:0000000105842370 __text:0000000105842370 loc_105842370 ; CODE XREF: cmd_interpret+9C↑j __text:0000000105842370 LDUR X8, [X29,#input] __text:0000000105842374 LDRSB W8, [X8,#1] __text:0000000105842378 SUBS W8, W8, #0x2A ; '*' __text:000000010584237C B.NE loc_105842388 __text:0000000105842380 B loc_105842384 __text:0000000105842384 ; --------------------------------------------------------------------------- __text:0000000105842384 __text:0000000105842384 loc_105842384 ; CODE XREF: cmd_interpret+6A4↑j __text:0000000105842384 B bypass __text:0000000105842388 ; --------------------------------------------------------------------------- __text:0000000105842388 __text:0000000105842388 loc_105842388 ; CODE XREF: cmd_interpret+6A0↑j __text:0000000105842388 LDUR X8, [X29,#core] __text:000000010584238C LDR X8, [X8,#0x80] __text:0000000105842390 ADD X0, X8, #0x820 ; mac __text:0000000105842394 LDUR X8, [X29,#input] __text:0000000105842398 ADD X1, X8, #1 ; name __text:000000010584239C BL r_cmd_macro_call __text:00000001058423A0 B loc_1058425A0 __text:00000001058423A4 ; --------------------------------------------------------------------------- __text:00000001058423A4 __text:00000001058423A4 loc_1058423A4 ; CODE XREF: cmd_interpret+D0↑j __text:00000001058423A4 LDUR X8, [X29,#input] __text:00000001058423A8 LDRSB W8, [X8] __text:00000001058423AC TBNZ W8, #0x1F, loc_10584240C __text:00000001058423B0 B loc_1058423B4 __text:00000001058423B4 ; --------------------------------------------------------------------------- __text:00000001058423B4 __text:00000001058423B4 loc_1058423B4 ; CODE XREF: cmd_interpret+6D4↑j __text:00000001058423B4 LDUR X8, [X29,#input] __text:00000001058423B8 LDRSB W8, [X8] __text:00000001058423BC SUBS W8, W8, #9 __text:00000001058423C0 B.GT loc_10584240C __text:00000001058423C4 B loc_1058423C8 __text:00000001058423C8 ; --------------------------------------------------------------------------- __text:00000001058423C8 __text:00000001058423C8 loc_1058423C8 ; CODE XREF: cmd_interpret+6E8↑j __text:00000001058423C8 MOV W0, #1 ; level __text:00000001058423CC ADRL X1, aCmdInterpret ; "cmd_interpret" __text:00000001058423D4 BL r_log_match __text:00000001058423D8 TBZ W0, #0, loc_105842408 __text:00000001058423DC B loc_1058423E0 __text:00000001058423E0 ; --------------------------------------------------------------------------- __text:00000001058423E0 __text:00000001058423E0 loc_1058423E0 ; CODE XREF: cmd_interpret+700↑j __text:00000001058423E0 MOV W0, #1 ; level __text:00000001058423E4 ADRL X1, aCmdInterpret ; "cmd_interpret" __text:00000001058423EC ADRL X2, aSourceLibrCore_43 ; "../source/libr/core/cmd.c" __text:00000001058423F4 MOV W3, #0x96C ; line __text:00000001058423F8 ADRL X4, aNo09ToAvoidInf ; "No .[0..9] to avoid infinite loops" __text:0000000105842400 BL r_log_message __text:0000000105842404 B loc_105842408 __text:0000000105842408 ; --------------------------------------------------------------------------- __text:0000000105842408 __text:0000000105842408 loc_105842408 ; CODE XREF: cmd_interpret+6FC↑j __text:0000000105842408 ; cmd_interpret+728↑j __text:0000000105842408 B loc_1058425A0 __text:000000010584240C ; --------------------------------------------------------------------------- __text:000000010584240C __text:000000010584240C loc_10584240C ; CODE XREF: cmd_interpret+6D0↑j __text:000000010584240C ; cmd_interpret+6E4↑j __text:000000010584240C B bypass __text:0000000105842410 ; --------------------------------------------------------------------------- __text:0000000105842410 __text:0000000105842410 bypass ; CODE XREF: cmd_interpret:loc_105842384↑j __text:0000000105842410 ; cmd_interpret:loc_10584240C↑j __text:0000000105842410 LDUR X0, [X29,#input] ; __s1 __text:0000000105842414 BL _strdup.island __text:0000000105842418 STUR X0, [X29,#inp] __text:000000010584241C LDUR X0, [X29,#inp] ; __s __text:0000000105842420 MOV W1, #0x7E ; '~' ; __c __text:0000000105842424 BL _strchr.island __text:0000000105842428 STUR X0, [X29,#filter] __text:000000010584242C LDUR X8, [X29,#filter] __text:0000000105842430 CBZ X8, loc_105842444 __text:0000000105842434 B loc_105842438 __text:0000000105842438 ; --------------------------------------------------------------------------- __text:0000000105842438 __text:0000000105842438 loc_105842438 ; CODE XREF: cmd_interpret+758↑j __text:0000000105842438 LDUR X8, [X29,#filter] __text:000000010584243C STRB WZR, [X8] __text:0000000105842440 B loc_105842444 __text:0000000105842444 ; --------------------------------------------------------------------------- __text:0000000105842444 __text:0000000105842444 loc_105842444 ; CODE XREF: cmd_interpret+754↑j __text:0000000105842444 ; cmd_interpret+764↑j __text:0000000105842444 LDUR X8, [X29,#core] __text:0000000105842448 LDR X8, [X8,#0x50] __text:000000010584244C LDR X8, [X8] __text:0000000105842450 LDRB W8, [X8,#0x6F3] __text:0000000105842454 MOV W9, #1 __text:0000000105842458 AND W8, W8, W9 __text:000000010584245C STRB W8, [SP,#0xE0+var_B1] __text:0000000105842460 LDUR X8, [X29,#core] __text:0000000105842464 LDR X8, [X8,#0x50] __text:0000000105842468 LDR X8, [X8] __text:000000010584246C STRB WZR, [X8,#0x6F3] __text:0000000105842470 LDUR X0, [X29,#core] ; core __text:0000000105842474 LDUR X1, [X29,#inp] ; cmd __text:0000000105842478 BL r_core_cmd_str __text:000000010584247C MOV X8, X0 __text:0000000105842480 STUR X8, [X29,#str] __text:0000000105842484 STUR X0, [X29,#ptr] __text:0000000105842488 LDRB W8, [SP,#0xE0+var_B1] __text:000000010584248C LDUR X9, [X29,#core] __text:0000000105842490 LDR X9, [X9,#0x50] __text:0000000105842494 LDR X9, [X9] __text:0000000105842498 AND W8, W8, #1 __text:000000010584249C STRB W8, [X9,#0x6F3] __text:00000001058424A0 LDUR X8, [X29,#filter] __text:00000001058424A4 CBZ X8, loc_1058424BC __text:00000001058424A8 B loc_1058424AC __text:00000001058424AC ; --------------------------------------------------------------------------- __text:00000001058424AC __text:00000001058424AC loc_1058424AC ; CODE XREF: cmd_interpret+7CC↑j __text:00000001058424AC LDUR X9, [X29,#filter] __text:00000001058424B0 MOV W8, #0x7E ; '~' __text:00000001058424B4 STRB W8, [X9] __text:00000001058424B8 B loc_1058424BC __text:00000001058424BC ; --------------------------------------------------------------------------- __text:00000001058424BC __text:00000001058424BC loc_1058424BC ; CODE XREF: cmd_interpret+7C8↑j __text:00000001058424BC ; cmd_interpret+7DC↑j __text:00000001058424BC LDUR X8, [X29,#core] __text:00000001058424C0 LDR X0, [X8,#0x50] ; cons __text:00000001058424C4 MOV X2, #0 ; user __text:00000001058424C8 MOV X1, X2 ; cb __text:00000001058424CC BL r_cons_break_push __text:00000001058424D0 LDUR X8, [X29,#ptr] __text:00000001058424D4 CBZ X8, loc_105842580 __text:00000001058424D8 B loc_1058424DC __text:00000001058424DC ; --------------------------------------------------------------------------- __text:00000001058424DC __text:00000001058424DC loc_1058424DC ; CODE XREF: cmd_interpret+7FC↑j __text:00000001058424DC B loc_1058424E0 __text:00000001058424E0 ; --------------------------------------------------------------------------- __text:00000001058424E0 __text:00000001058424E0 loc_1058424E0 ; CODE XREF: cmd_interpret:loc_1058424DC↑j __text:00000001058424E0 ; cmd_interpret+89C↓j __text:00000001058424E0 LDUR X8, [X29,#core] __text:00000001058424E4 LDR X0, [X8,#0x50] ; cons __text:00000001058424E8 BL r_cons_is_breaked __text:00000001058424EC TBZ W0, #0, loc_1058424F8 __text:00000001058424F0 B loc_1058424F4 __text:00000001058424F4 ; --------------------------------------------------------------------------- __text:00000001058424F4 __text:00000001058424F4 loc_1058424F4 ; CODE XREF: cmd_interpret+814↑j __text:00000001058424F4 B loc_10584257C __text:00000001058424F8 ; --------------------------------------------------------------------------- __text:00000001058424F8 __text:00000001058424F8 loc_1058424F8 ; CODE XREF: cmd_interpret+810↑j __text:00000001058424F8 LDUR X0, [X29,#ptr] ; __s __text:00000001058424FC MOV W1, #0xA ; __c __text:0000000105842500 BL _strchr.island __text:0000000105842504 STUR X0, [X29,#eol] __text:0000000105842508 LDUR X8, [X29,#eol] __text:000000010584250C CBZ X8, loc_105842520 __text:0000000105842510 B loc_105842514 __text:0000000105842514 ; --------------------------------------------------------------------------- __text:0000000105842514 __text:0000000105842514 loc_105842514 ; CODE XREF: cmd_interpret+834↑j __text:0000000105842514 LDUR X8, [X29,#eol] __text:0000000105842518 STRB WZR, [X8] __text:000000010584251C B loc_105842520 __text:0000000105842520 ; --------------------------------------------------------------------------- __text:0000000105842520 __text:0000000105842520 loc_105842520 ; CODE XREF: cmd_interpret+830↑j __text:0000000105842520 ; cmd_interpret+840↑j __text:0000000105842520 LDUR X8, [X29,#ptr] __text:0000000105842524 LDRB W8, [X8] __text:0000000105842528 CBZ W8, loc_10584255C __text:000000010584252C B loc_105842530 __text:0000000105842530 ; --------------------------------------------------------------------------- __text:0000000105842530 __text:0000000105842530 loc_105842530 ; CODE XREF: cmd_interpret+850↑j __text:0000000105842530 LDUR X0, [X29,#ptr] ; __s1 __text:0000000105842534 BL _strdup.island __text:0000000105842538 LDUR X1, [X29,#filter] ; string __text:000000010584253C BL r_str_append __text:0000000105842540 STR X0, [SP,#0xE0+var_C0] __text:0000000105842544 LDUR X0, [X29,#core] ; core __text:0000000105842548 LDR X1, [SP,#0xE0+var_C0] ; cmd __text:000000010584254C BL __ZN4bsslL41ext_quic_transport_params_add_serverhelloEPNS_13SSL_HANDSHAKEEP6cbb_st_0 ; bssl::ext_quic_transport_params_add_serverhello(bssl::SSL_HANDSHAKE *,cbb_st *) __text:0000000105842550 LDR X0, [SP,#0xE0+var_C0] ; void * __text:0000000105842554 BL _free.island __text:0000000105842558 B loc_10584255C __text:000000010584255C ; --------------------------------------------------------------------------- __text:000000010584255C __text:000000010584255C loc_10584255C ; CODE XREF: cmd_interpret+84C↑j __text:000000010584255C ; cmd_interpret+87C↑j __text:000000010584255C LDUR X8, [X29,#eol] __text:0000000105842560 CBNZ X8, loc_10584256C __text:0000000105842564 B loc_105842568 __text:0000000105842568 ; --------------------------------------------------------------------------- __text:0000000105842568 __text:0000000105842568 loc_105842568 ; CODE XREF: cmd_interpret+888↑j __text:0000000105842568 B loc_10584257C __text:000000010584256C ; --------------------------------------------------------------------------- __text:000000010584256C __text:000000010584256C loc_10584256C ; CODE XREF: cmd_interpret+884↑j __text:000000010584256C LDUR X8, [X29,#eol] __text:0000000105842570 ADD X8, X8, #1 __text:0000000105842574 STUR X8, [X29,#ptr] __text:0000000105842578 B loc_1058424E0 __text:000000010584257C ; --------------------------------------------------------------------------- __text:000000010584257C __text:000000010584257C loc_10584257C ; CODE XREF: cmd_interpret:loc_1058424F4↑j __text:000000010584257C ; cmd_interpret:loc_105842568↑j __text:000000010584257C B loc_105842580 __text:0000000105842580 ; --------------------------------------------------------------------------- __text:0000000105842580 __text:0000000105842580 loc_105842580 ; CODE XREF: cmd_interpret+7F8↑j __text:0000000105842580 ; cmd_interpret:loc_10584257C↑j __text:0000000105842580 LDUR X8, [X29,#core] __text:0000000105842584 LDR X0, [X8,#0x50] ; cons __text:0000000105842588 BL r_cons_break_pop __text:000000010584258C LDUR X0, [X29,#str] ; void * __text:0000000105842590 BL _free.island __text:0000000105842594 LDUR X0, [X29,#inp] ; void * __text:0000000105842598 BL _free.island __text:000000010584259C B loc_1058425A0 __text:00000001058425A0 ; --------------------------------------------------------------------------- __text:00000001058425A0 __text:00000001058425A0 loc_1058425A0 ; CODE XREF: cmd_interpret+E0↑j __text:00000001058425A0 ; cmd_interpret+2EC↑j ... __text:00000001058425A0 STUR WZR, [X29,#var_4] __text:00000001058425A4 B loc_1058425A8 __text:00000001058425A8 ; --------------------------------------------------------------------------- __text:00000001058425A8 __text:00000001058425A8 loc_1058425A8 ; CODE XREF: cmd_interpret+4C↑j __text:00000001058425A8 ; cmd_interpret+174↑j ... __text:00000001058425A8 LDUR W0, [X29,#var_4] __text:00000001058425AC LDP X29, X30, [SP,#0xE0+var_s0] __text:00000001058425B0 ADD SP, SP, #0xF0 __text:00000001058425B4 RET __text:00000001058425B4 ; End of function cmd_interpret ``` ## Part 2 Proof of concept So, here is a proof of concept that this works as of r2 version... ``` r2 -v radare2 6.2.4 +0 abi:152 @ darwin-arm_64 birth: git.6.2.4 2026-10-05__18:21:19 commit: 6.2.4 options: gpl release -Os cs:5 cl:2 make ``` So, as an example the test binary has newlines in strtab and like .is and .fn calls `cmd_interpret` with is or fn as input and the output of them gets treated like an r2 command Anyways, here is proof: ![[r2_proof_of_concept.mov]] So in the video I show that I am reading `/var/log/nginx/access.log` from my server and I am only showing stuff with `AARCH64_ASSEMBLY_IS_BETTER_THAN_AMD64_ASSEMBLY`. I then switch to another terminal tab where I run the commands `cat r2_poc;./r2_poc` and I show that I don't even need any r2 config nor do I need any analysis to be done, so one of the commands in r2_poc is `r2 -qc ".is" ~/radare2_fun` and when I do that it treats the output of `is` as a command and since I had the newline character in the symbols, I was able to run what I want as an r2 command that was able to connect to my server and download a binary into `/tmp`, `chmod +x` it, and `run` it. I was also able to do the same with `.fn` , I then display some stats of the binary via normal r2 and show the disasm of the downloaded binary and at the end of the video I show that requests were made to my server for the binary.