
Radare2 وFrida أفضل معًا.
Radare2 و Frida معًا بشكل أفضل
إضافة (plugin) قائمة بذاتها لـ radare2 تُضمّن frida وتتيح فحص العمليات المحلية أو البعيدة باستخدام أوامر r2 بدلاً من (ولكن ليس مقتصرًا على) سكربتات Frida.
يوفر مشروع radare سلسلة أدوات كاملة للهندسة العكسية، وهو مُصان بشكل نشط ويوفر وظائف جيدة الصيانة ويوسّع ميزاته بلغات برمجة وأدوات أخرى.
Frida هي مجموعة أدوات للفحص الديناميكي (dynamic instrumentation) تسهّل فحص والتلاعب بالعمليات قيد التشغيل عبر حقن JavaScript الخاص بك، واختياريًا أيضًا التواصل مع سكربتاتك.
:.):dbr_fs.الطريقة الموصى بها لتثبيت r2frida هي عبر r2pm:
$ r2pm -ci r2frida
سيتم قريبًا دعم البِناءات الثنائية (binary builds) التي لا تتطلب ترجمة (compilation) في
r2pm و r2env. في غضون ذلك، لا تتردد في تنزيل آخر البِناءات
من صفحة الإصدارات (Releases).
في GNU/Debian ستحتاج إلى تثبيت الحزم التالية:
$ sudo apt install -y make gcc libzip-dev nodejs npm curl pkg-config git
$ git clone https://github.com/nowsecure/r2frida.git
$ cd r2frida
$ make
$ make user-install
radare2 (بدلاً من radare2-x.y.z)preconfigure.bat)configure.bat ثم make.batللاختبار، استخدم r2 frida://0، حيث أن الارتباط بـ pid0 في frida هو جلسة
خاصة تعمل محليًا. الآن يمكنك تشغيل الأمر :? للحصول على قائمة
الأوامر المتاحة.
$ r2 'frida://?'
r2 frida://[action]/[link]/[device]/[target]
* action = list | apps | attach | spawn | launch
* link = local | usb | remote host:port
* device = '' | host:port | device-id
* target = pid | appname | process-name | program-in-path | abspath
Local:
* frida://? # show this help
* frida:// # list local processes
* frida://0 # attach to frida-helper (no spawn needed)
* frida:///usr/local/bin/rax2 # abspath to spawn
* frida://rax2 # same as above, considering local/bin is in PATH
* frida://spawn/$(program) # spawn a new process in the current system
* frida://attach/(target) # attach to target PID in current host
USB:
* frida://list/usb// # list processes in the first usb device
* frida://apps/usb// # list apps in the first usb device
* frida://attach/usb//12345 # attach to given pid in the first usb device
* frida://spawn/usb//appname # spawn an app in the first resolved usb device
* frida://launch/usb//appname # spawn+resume an app in the first usb device
Remote:
* frida://attach/remote/10.0.0.3:9999/558 # attach to pid 558 on tcp remote frida-server
Environment: (Use the `%` command to change the environment at runtime)
R2FRIDA_SAFE_IO=0|1 # Workaround a Frida bug on Android/thumb
R2FRIDA_DEBUG=0|1 # Used to debug argument parsing behaviour
R2FRIDA_COMPILER_DISABLE=0|1 # Disable the new frida typescript compiler (`:. foo.ts`)
R2FRIDA_AGENT_SCRIPT=[file] # path to file of the r2frida agent
$ r2 frida://0 # same as frida -p 0, connects to a local session
يمكنك الارتباط أو إنشاء أو تشغيل أي برنامج بالاسم أو pid، السطر التالي سيرتبط بأول عملية تُسمى rax2 (شغّل rax2 - في طرفية أخرى لاختبار هذا السطر)
$ r2 frida://rax2 # attach to the first process named `rax2`
$ r2 frida://1234 # attach to the given pid
استخدام المسار المطلق لملف ثنائي لإنشائه سيؤدي إلى إنشاء العملية:
$ r2 frida:///bin/ls
[0x00000000]> :dc # continue the execution of the target program
يعمل أيضًا مع المعاملات (arguments):
$ r2 frida://"/bin/ls -al"
لتصحيح تطبيقات iOS/Android عبر USB استخدم هذه الإجراءات. لاحظ أن spawn
يمكن استبداله بـ launch أو attach، ويمكن أن يكون اسم العملية
هو bundleid أو PID.
$ r2 frida://spawn/usb/ # enumerate devices
$ r2 frida://spawn/usb// # enumerate apps in the first iOS device
$ r2 frida://spawn/usb//Weather # Run the weather app
هذه هي الأوامر الأكثر شيوعًا، لذا يجب أن تتعلمها وتضيف إليها اللاحقة ? للحصول على مساعدة الأوامر الفرعية.
:i # get information of the target (pid, name, home, arch, bits, ..)
.:i* # import the target process details into local r2
:? # show all the available commands
:dm # list maps. Use ':dm|head' and seek to the program base address
:iE # list the exports of the current binary (seek)
:dt fread # trace the 'fread' function
:dt-* # delete all traces
تعمل إضافات r2frida في جانب الوكيل (agent side) ويتم تسجيلها باستخدام واجهة r2frida.pluginRegister.
راجع دليل plugins/ لمزيد من الأمثلة على سكربتات الإضافات.
[0x00000000]> cat example.js
r2frida.pluginRegister('test', function(name) {
if (name === 'test') {
return function(args) {
console.log('Hello Args From r2frida plugin', args);
return 'Things Happen';
}
}
});
[0x00000000]> :. example.js # load the plugin script
يعمل الأمر :. مثل الأمر . في r2، لكنه يعمل داخل الوكيل (agent).
:. a.js # run script which registers a plugin
:. # list plugins
:.-test # unload a plugin by name
:.. a.js # eternalize script (keeps running after detach)
إذا كنت ترغب في تثبيت واستخدام r2frida أصلاً (natively) على Android عبر Termux، فهناك بعض التحذيرات المتعلقة بتبعيات المكتبات بسبب بعض عمليات حل الرموز (symbol resolutions). الطريقة لجعل هذا يعمل هي توسيع متغير البيئة LD_LIBRARY_PATH ليشير إلى دليل النظام قبل دليل مكتبات termux.
$ LD_LIBRARY_PATH=/system/lib64:$LD_LIBRARY_PATH r2 frida://...