mirror of
https://github.com/mytechnotalent/Embedded-Hacking.git
synced 2026-10-04 15:06:57 +02:00
Week 4-BN: add the BN console flash option to Steps 5, 6, and 22
Every flash step now has the terminal form and the console form (pkill/taskkill, then Popen flash.sh/.ps1 into flash.log), matching Steps 10/21/29. Steps 5/6 note they need a database open to derive the repo root.
This commit is contained in:
1 parent
ef2bf0eb71
commit
5225f47ecf
2 files changed
+87
No files matched your search
@@ -256,6 +256,35 @@ A `.bin` has no headers, so OpenOCD must be told the base address `0x10000000`.
|
|||||||
.\flash.ps1 -Bin 0x0005_intro-to-variables\build\0x0005_intro-to-variables.bin
|
.\flash.ps1 -Bin 0x0005_intro-to-variables\build\0x0005_intro-to-variables.bin
|
||||||
```
|
```
|
||||||
|
|
||||||
|
**Or flash from the Binary Ninja console** (with a database open, so the repo root is taken from it — otherwise use the terminal form above):
|
||||||
|
|
||||||
|
**macOS Apple Silicon / Linux x64:**
|
||||||
|
|
||||||
|
```python
|
||||||
|
import os, subprocess
|
||||||
|
root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename))) # <repo>
|
||||||
|
bin_path = os.path.join(root, "0x0005_intro-to-variables", "build", "0x0005_intro-to-variables.bin")
|
||||||
|
log = os.path.join(os.path.dirname(bin_path), "flash.log")
|
||||||
|
subprocess.run(["pkill", "-TERM", "-f", "openocd"]) # free the probe first
|
||||||
|
subprocess.Popen([os.path.join(root, "flash.sh"), bin_path],
|
||||||
|
stdout=open(log, "w"), stderr=subprocess.STDOUT, start_new_session=True)
|
||||||
|
print("flashing in the background; log:", log)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Windows x64:**
|
||||||
|
|
||||||
|
```python
|
||||||
|
import os, subprocess
|
||||||
|
root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename))) # <repo>
|
||||||
|
bin_path = os.path.join(root, "0x0005_intro-to-variables", "build", "0x0005_intro-to-variables.bin")
|
||||||
|
log = os.path.join(os.path.dirname(bin_path), "flash.log")
|
||||||
|
subprocess.run(["taskkill", "/F", "/IM", "openocd.exe"]) # free the probe first
|
||||||
|
subprocess.Popen(["powershell", "-ExecutionPolicy", "Bypass", "-File",
|
||||||
|
os.path.join(root, "flash.ps1"), "-Bin", bin_path],
|
||||||
|
stdout=open(log, "w"), stderr=subprocess.STDOUT)
|
||||||
|
print("flashing in the background; log:", log)
|
||||||
|
```
|
||||||
|
|
||||||
Wait for `wrote 15292 bytes ...` and `** Verified OK **`. Open a serial monitor at **115200** baud:
|
Wait for `wrote 15292 bytes ...` and `** Verified OK **`. Open a serial monitor at **115200** baud:
|
||||||
|
|
||||||
- **Windows x64:** PuTTY -> Connection type **Serial**, the Pico's COM port, speed `115200`.
|
- **Windows x64:** PuTTY -> Connection type **Serial**, the Pico's COM port, speed `115200`.
|
||||||
@@ -280,6 +309,35 @@ age: 43
|
|||||||
.\flash.ps1 -Bin 0x0008_uninitialized-variables\build\0x0008_uninitialized-variables.bin
|
.\flash.ps1 -Bin 0x0008_uninitialized-variables\build\0x0008_uninitialized-variables.bin
|
||||||
```
|
```
|
||||||
|
|
||||||
|
**Or flash from the Binary Ninja console** (same form as Step 5, pointing at the Project 2 `.bin`):
|
||||||
|
|
||||||
|
**macOS / Linux:**
|
||||||
|
|
||||||
|
```python
|
||||||
|
import os, subprocess
|
||||||
|
root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename))) # <repo>
|
||||||
|
bin_path = os.path.join(root, "0x0008_uninitialized-variables", "build", "0x0008_uninitialized-variables.bin")
|
||||||
|
log = os.path.join(os.path.dirname(bin_path), "flash.log")
|
||||||
|
subprocess.run(["pkill", "-TERM", "-f", "openocd"])
|
||||||
|
subprocess.Popen([os.path.join(root, "flash.sh"), bin_path],
|
||||||
|
stdout=open(log, "w"), stderr=subprocess.STDOUT, start_new_session=True)
|
||||||
|
print("flashing in the background; log:", log)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Windows:**
|
||||||
|
|
||||||
|
```python
|
||||||
|
import os, subprocess
|
||||||
|
root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename))) # <repo>
|
||||||
|
bin_path = os.path.join(root, "0x0008_uninitialized-variables", "build", "0x0008_uninitialized-variables.bin")
|
||||||
|
log = os.path.join(os.path.dirname(bin_path), "flash.log")
|
||||||
|
subprocess.run(["taskkill", "/F", "/IM", "openocd.exe"])
|
||||||
|
subprocess.Popen(["powershell", "-ExecutionPolicy", "Bypass", "-File",
|
||||||
|
os.path.join(root, "flash.ps1"), "-Bin", bin_path],
|
||||||
|
stdout=open(log, "w"), stderr=subprocess.STDOUT)
|
||||||
|
print("flashing in the background; log:", log)
|
||||||
|
```
|
||||||
|
|
||||||
Wait for `wrote 15668 bytes ...`. The serial monitor shows:
|
Wait for `wrote 15668 bytes ...`. The serial monitor shows:
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -976,6 +1034,35 @@ Part 4 left the Pico running the patched Project 1 image. Put the original Proje
|
|||||||
.\flash.ps1 -Bin 0x0008_uninitialized-variables\build\0x0008_uninitialized-variables.bin
|
.\flash.ps1 -Bin 0x0008_uninitialized-variables\build\0x0008_uninitialized-variables.bin
|
||||||
```
|
```
|
||||||
|
|
||||||
|
**Or do steps 1–2 from the Binary Ninja console** (the active view is still Project 1, so take the repo root from it and point at the Project 2 `.bin`):
|
||||||
|
|
||||||
|
**macOS / Linux:**
|
||||||
|
|
||||||
|
```python
|
||||||
|
import os, subprocess
|
||||||
|
root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename))) # <repo>
|
||||||
|
bin_path = os.path.join(root, "0x0008_uninitialized-variables", "build", "0x0008_uninitialized-variables.bin")
|
||||||
|
log = os.path.join(os.path.dirname(bin_path), "flash.log")
|
||||||
|
subprocess.run(["pkill", "-TERM", "-f", "openocd"]) # free the probe first
|
||||||
|
subprocess.Popen([os.path.join(root, "flash.sh"), bin_path],
|
||||||
|
stdout=open(log, "w"), stderr=subprocess.STDOUT, start_new_session=True)
|
||||||
|
print("flashing Project 2 in the background; log:", log)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Windows:**
|
||||||
|
|
||||||
|
```python
|
||||||
|
import os, subprocess
|
||||||
|
root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename))) # <repo>
|
||||||
|
bin_path = os.path.join(root, "0x0008_uninitialized-variables", "build", "0x0008_uninitialized-variables.bin")
|
||||||
|
log = os.path.join(os.path.dirname(bin_path), "flash.log")
|
||||||
|
subprocess.run(["taskkill", "/F", "/IM", "openocd.exe"]) # free the probe first
|
||||||
|
subprocess.Popen(["powershell", "-ExecutionPolicy", "Bypass", "-File",
|
||||||
|
os.path.join(root, "flash.ps1"), "-Bin", bin_path],
|
||||||
|
stdout=open(log, "w"), stderr=subprocess.STDOUT)
|
||||||
|
print("flashing Project 2 in the background; log:", log)
|
||||||
|
```
|
||||||
|
|
||||||
3. Start the debug server again (Step 10) and wait for `Listening on port 3333`.
|
3. Start the debug server again (Step 10) and wait for `Listening on port 3333`.
|
||||||
4. Open `0x0008_uninitialized-variables/build/0x0008_uninitialized-variables.bin` with options (`thumb2`, `thumb2`, `0x10000000`) and save a `.bndb`.
|
4. Open `0x0008_uninitialized-variables/build/0x0008_uninitialized-variables.bin` with options (`thumb2`, `thumb2`, `0x10000000`) and save a `.bndb`.
|
||||||
5. Connect Binary Ninja again (Step 11): adapter **GDB MI**, IP `127.0.0.1`, port `3333`.
|
5. Connect Binary Ninja again (Step 11): adapter **GDB MI**, IP `127.0.0.1`, port `3333`.
|
||||||
|
|||||||
Binary file not shown.
Reference in new issue
Block a user