[*] Emulating binary name: portt
[*] Emulator used: qemu-mipsel
[*] Using root directory: /logs/s115_usermode_emulator/firmware/unblob_extracted/firmware_extract/DIR-600_fw_revb5_214b01_ALL_de_20130122/dir600b_v2.14_d1mg.bin_extract/1179788-3612812.squashfs_v4_le_extract (1/1)
[*] Using CPU config: NONE
[*] Emulating binary: /usr/sbin/portt
[*] Emulating binary ./usr/sbin/portt with parameter NONE
[*] Emulating binary ./usr/sbin/portt with parameter -v
[*] Emulating binary ./usr/sbin/portt with parameter -V
Unalbe to bind socket!
portt exit with code 0
[*] Emulating binary ./usr/sbin/portt with parameter -h
./usr/sbin/portt: invalid option -- V
portt version 1
usage: portt [OPTIONS]
-h show this help message.
-v verbose mode.
-d debug mode.
-t {timeout} Timeout in seconds.
-c {chain} Name of the chain.
-s {socket name} specify unix socket name. default is /var/run/portt.unixsocket
[*] Emulating binary ./usr/sbin/portt with parameter -help
portt version 1
usage: portt [OPTIONS]
-h show this help message.
-v verbose mode.
-d debug mode.
-t {timeout} Timeout in seconds.
-c {chain} Name of the chain.
-s {socket name} specify unix socket name. default is /var/run/portt.unixsocket
[*] Emulating binary ./usr/sbin/portt with parameter --help
portt version 1
usage: portt [OPTIONS]
-h show this help message.
-v verbose mode.
-d debug mode.
-t {timeout} Timeout in seconds.
-c {chain} Name of the chain.
-s {socket name} specify unix socket name. default is /var/run/portt.unixsocket
[*] Emulating binary ./usr/sbin/portt with parameter --version
./usr/sbin/portt: invalid option -- -
portt version 1
usage: portt [OPTIONS]
-h show this help message.
-v verbose mode.
-d debug mode.
-t {timeout} Timeout in seconds.
-c {chain} Name of the chain.
-s {socket name} specify unix socket name. default is /var/run/portt.unixsocket
[*] Emulating binary ./usr/sbin/portt with parameter version
./usr/sbin/portt: invalid option -- -
portt version 1
usage: portt [OPTIONS]
-h show this help message.
-v verbose mode.
-d debug mode.
-t {timeout} Timeout in seconds.
-c {chain} Name of the chain.
-s {socket name} specify unix socket name. default is /var/run/portt.unixsocket
For reproducing the EMBA user-mode emulation mechanism, the following commands could be used as starting point:
- Start EMBA docker container with the firmware directory as log directory:
# EMBA="." FIRMWARE="/home/runner/work/emba/emba/DIR-600_fw_revb5_214b01_ALL_de_20130122.zip" LOG="/absolute/path/to/EMBA/log/directory" docker-compose run emba
- Change your working directory to the root directory of your firmware:
# cd /logs/s115_usermode_emulator/firmware/unblob_extracted/firmware_extract/DIR-600_fw_revb5_214b01_ALL_de_20130122/dir600b_v2.14_d1mg.bin_extract/1179788-3612812.squashfs_v4_le_extract
- Copy the static compiled user-mode emulator to your current working directory
# cp $(which qemu-mipsel) .
- Start the emulation with the following command:
# jchroot . -- ./qemu-mipsel ./usr/sbin/portt <parameters like -v or --help>
WARNING: EMBA is doing some more magic in the background. Probably it is not that easy, but give it a try.