Using QEMU-user emulation to reverse engineer binaries
ariadne.space
ariadne.space
This is the most notable manifestation of the general point that QEMU's -d logging is primarily aimed at debugging QEMU itself -- it logs things that are easy to log and interpreting the output requires some understanding of QEMU's internals. The "I want to debug my guest without thinking about QEMU implementation details" interfaces are the gdbstub and more recently the TCG plugin API.
Also, if anyone is interested in using QEMU for whole system reverse engineering, allow me to shill PANDA, which adds a plugin API, record/replay, and a nice Python interface for all of this:
We‘ve been doing that in Debian on m68k and sh4 for quite a while now and it helped finding quite a lot of bugs, both in the target-specific emulation code and in the qemu-user code.
There is still one nasty bug in conjunction with glibc if anyone wants to help:
Note these are QEMU’s micro ops, not real CPU μops are is suggested here.
I believe there is one important caveat here: the OS has to stay the same.
https://superuser.com/questions/1355064/qemu-user-mode-emula...