
Radare2 und Frida besser zusammen.
Radare2 und Frida besser zusammen
Eigenständiges Plugin für radare2, das frida mitliefert und es ermöglicht, lokale oder entfernte Prozesse mit r2-Befehlen statt (aber nicht beschränkt auf) Frida-Skripten zu instrumentieren.
Das radare-Projekt bietet eine vollständige Toolchain für Reverse Engineering, es wird aktiv gepflegt und stellt gut gewartete Funktionalitäten bereit und erweitert seine Features mit anderen Programmiersprachen und Tools.
Frida ist ein dynamisches Instrumentierungs-Toolkit, das es einfach macht, laufende Prozesse zu inspizieren und zu manipulieren, indem man eigenes JavaScript injiziert und optional auch mit seinen Skripten kommuniziert.
:.-Befehl):db-APIr_fs-API zugreifen.Der empfohlene Weg, r2frida zu installieren, ist über r2pm:
$ r2pm -ci r2frida
Binär-Builds, die keine Kompilierung erfordern, werden bald in
r2pm und r2env unterstützt. In der Zwischenzeit kannst du gerne die letzten Builds
von der Releases-Seite herunterladen.
Unter GNU/Debian musst du die folgenden Pakete installieren:
$ sudo apt install -y make gcc libzip-dev nodejs npm curl pkg-config git
$ git clone https://github.com/nowsecure/r2frida.git
$ cd r2frida
$ make
$ make user-install
radare2 um (statt radare2-x.y.z)preconfigure.bat)configure.bat und dann make.bat ausZum Testen verwende r2 frida://0, denn das Anhängen an die pid0 in frida ist eine spezielle
Sitzung, die lokal läuft. Jetzt kannst du den :?-Befehl ausführen, um die Liste
der verfügbaren Befehle zu erhalten.
$ r2 'frida://?'
r2 frida://[action]/[link]/[device]/[target]
* action = list | apps | attach | spawn | launch
* link = local | usb | remote host:port
* device = '' | host:port | device-id
* target = pid | appname | process-name | program-in-path | abspath
Local:
* frida://? # show this help
* frida:// # list local processes
* frida://0 # attach to frida-helper (no spawn needed)
* frida:///usr/local/bin/rax2 # abspath to spawn
* frida://rax2 # same as above, considering local/bin is in PATH
* frida://spawn/$(program) # spawn a new process in the current system
* frida://attach/(target) # attach to target PID in current host
USB:
* frida://list/usb// # list processes in the first usb device
* frida://apps/usb// # list apps in the first usb device
* frida://attach/usb//12345 # attach to given pid in the first usb device
* frida://spawn/usb//appname # spawn an app in the first resolved usb device
* frida://launch/usb//appname # spawn+resume an app in the first usb device
Remote:
* frida://attach/remote/10.0.0.3:9999/558 # attach to pid 558 on tcp remote frida-server
Environment: (Use the `%` command to change the environment at runtime)
R2FRIDA_SAFE_IO=0|1 # Workaround a Frida bug on Android/thumb
R2FRIDA_DEBUG=0|1 # Used to debug argument parsing behaviour
R2FRIDA_COMPILER_DISABLE=0|1 # Disable the new frida typescript compiler (`:. foo.ts`)
R2FRIDA_AGENT_SCRIPT=[file] # path to file of the r2frida agent
$ r2 frida://0 # same as frida -p 0, connects to a local session
Du kannst an jedes Programm nach Name oder pid anhängen, spawnen oder starten. Die folgende Zeile hängt an den ersten Prozess namens rax2 an (führe rax2 - in einem anderen Terminal aus, um diese Zeile zu testen)
$ r2 frida://rax2 # attach to the first process named `rax2`
$ r2 frida://1234 # attach to the given pid
Die Verwendung des absoluten Pfads einer Binärdatei zum Spawnen wird den Prozess spawnen:
$ r2 frida:///bin/ls
[0x00000000]> :dc # continue the execution of the target program
Funktioniert auch mit Argumenten:
$ r2 frida://"/bin/ls -al"
Für USB-Debugging von iOS/Android-Apps verwende diese Aktionen. Beachte, dass spawn
durch launch oder attach ersetzt werden kann und der Prozessname
die bundleid oder die PID sein kann.
$ r2 frida://spawn/usb/ # enumerate devices
$ r2 frida://spawn/usb// # enumerate apps in the first iOS device
$ r2 frida://spawn/usb//Weather # Run the weather app
Dies sind die häufigsten Befehle, also musst du sie lernen und mit ? ergänzen, um Hilfe zu Unterbefehlen zu erhalten.
:i # get information of the target (pid, name, home, arch, bits, ..)
.:i* # import the target process details into local r2
:? # show all the available commands
:dm # list maps. Use ':dm|head' and seek to the program base address
:iE # list the exports of the current binary (seek)
:dt fread # trace the 'fread' function
:dt-* # delete all traces
r2frida-Plugins laufen auf der Agenten-Seite und werden mit der r2frida.pluginRegister-API registriert.
Siehe das plugins/-Verzeichnis für weitere Beispiel-Plugin-Skripte.
[0x00000000]> cat example.js
r2frida.pluginRegister('test', function(name) {
if (name === 'test') {
return function(args) {
console.log('Hello Args From r2frida plugin', args);
return 'Things Happen';
}
}
});
[0x00000000]> :. example.js # load the plugin script
Der :.-Befehl funktioniert wie der .-Befehl von r2, läuft aber innerhalb des Agenten.