[*] Emulating binary name: igmpproxy
[*] Emulator used: qemu-mipsel
[*] Using root directory: /logs/s115_usermode_emulator/firmware/unblob_extracted/firmware_extract/DIR-600_fw_revb5_214b01_ALL_de_20130122/dir600b_v2.14_d1mg.bin_extract/1179788-3612812.squashfs_v4_le_extract (1/1)
[*] Using CPU config: NONE
[*] Emulating binary: /usr/sbin/igmpproxy
[*] Emulating binary ./usr/sbin/igmpproxy with parameter NONE
[*] Emulating binary ./usr/sbin/igmpproxy with parameter -v
mmap() failed at phsical address:268435456 Operation not permitted
[*] Emulating binary ./usr/sbin/igmpproxy with parameter -V
IGMP:rt3052_init..
mmap() failed at phsical address:268435456 Operation not permitted
[*] Emulating binary ./usr/sbin/igmpproxy with parameter -h
./usr/sbin/igmpproxy: invalid option -- V
igmpproxy versoin 3.0 beta
Usage: igmpproxy [OPTIONS]
-h show this help message.
-v verbose mode.
-d disable fast leave.
-s specify helper script.
-c specify config file.
[*] Emulating binary ./usr/sbin/igmpproxy with parameter -help
igmpproxy versoin 3.0 beta
Usage: igmpproxy [OPTIONS]
-h show this help message.
-v verbose mode.
-d disable fast leave.
-s specify helper script.
-c specify config file.
[*] Emulating binary ./usr/sbin/igmpproxy with parameter --help
igmpproxy versoin 3.0 beta
Usage: igmpproxy [OPTIONS]
-h show this help message.
-v verbose mode.
-d disable fast leave.
-s specify helper script.
-c specify config file.
[*] Emulating binary ./usr/sbin/igmpproxy with parameter --version
./usr/sbin/igmpproxy: invalid option -- -
igmpproxy versoin 3.0 beta
Usage: igmpproxy [OPTIONS]
-h show this help message.
-v verbose mode.
-d disable fast leave.
-s specify helper script.
-c specify config file.
[*] Emulating binary ./usr/sbin/igmpproxy with parameter version
./usr/sbin/igmpproxy: invalid option -- -
igmpproxy versoin 3.0 beta
Usage: igmpproxy [OPTIONS]
-h show this help message.
-v verbose mode.
-d disable fast leave.
-s specify helper script.
-c specify config file.
mmap() failed at phsical address:268435456 Operation not permitted
For reproducing the EMBA user-mode emulation mechanism, the following commands could be used as starting point:
- Start EMBA docker container with the firmware directory as log directory:
# EMBA="." FIRMWARE="/home/runner/work/emba/emba/DIR-600_fw_revb5_214b01_ALL_de_20130122.zip" LOG="/absolute/path/to/EMBA/log/directory" docker-compose run emba
- Change your working directory to the root directory of your firmware:
# cd /logs/s115_usermode_emulator/firmware/unblob_extracted/firmware_extract/DIR-600_fw_revb5_214b01_ALL_de_20130122/dir600b_v2.14_d1mg.bin_extract/1179788-3612812.squashfs_v4_le_extract
- Copy the static compiled user-mode emulator to your current working directory
# cp $(which qemu-mipsel) .
- Start the emulation with the following command:
# jchroot . -- ./qemu-mipsel ./usr/sbin/igmpproxy <parameters like -v or --help>
WARNING: EMBA is doing some more magic in the background. Probably it is not that easy, but give it a try.