
Herramienta automatizada de análisis de binarios ELF para desafíos CTF/PWN. Extrae mitigaciones de seguridad, gadgets ROP, tablas PLT/GOT, y descompila ASM a C usando Radare2 y r2ghidra. Identifica posibles desbordamientos de búfer, cadenas de formato y vulnerabilidades de inyección de comandos.
ELFXtract es una herramienta de análisis automatizado utilizada para enumerar binarios ELF
Desarrollado por Radare2 y r2ghidra
Está especialmente diseñado para desafíos PWN y tiene muchas características automatizadas
Muestra casi todos los detalles del ELF y también descompila su ASM a código C usando r2ghidra
Descompilar ELFs en Ghidra toma más tiempo, pero en elfxtract descompila y muestra en pocos segundos
git clone https://github.com/AidenPearce369/elfxtract
cd elfxtract
chmod +x install.sh
./install.sh
pip install -r requirements.txt
Puedes ejecutar elfxtract con cualquier ELF junto con -a para listar todos los detalles del ELF
ra@ubuntu:~/elfxtract$ python3 main.py --file programvuln -a
_____ _ ________ ___ _
| ___| | | ___\ \ / / | | |
| |__ | | | |_ \ V /| |_ _ __ __ _ ___| |_
| __|| | | _| / \| __| '__/ _` |/ __| __|
| |___| |____| | / /^\ \ |_| | | (_| | (__| |_
\____/\_____/\_| \/ \/\__|_| \__,_|\___|\__|
@aidenpearce369
***************************************************************************
> INFORMACIÓN DEL ARCHIVO :
Nombre ELF : programvuln
Tipo ELF : ELF 64-bit LSB shared object
Arquitectura ELF : x86-64
Hash SHA1 ELF : BuildID[sha1]=cf149d97ad1e895561080b1f5c317bc5bc1e8652
Este binario está enlazado dinámicamente y no está despojado
***************************************************************************
> DEPENDENCIA DE OBJETOS COMPARTIDOS :
linux-vdso.so.1 (0x00007ffd525a4000)
libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007fd610d93000)
/lib64/ld-linux-x86-64.so.2 (0x00007fd610fa1000)
***************************************************************************
> MITIGACIONES DE SEGURIDAD ELF :
RELRO : Full RELRO
STACK CANARY : No se encontró Canary
NX BIT : NX deshabilitado
PIE : PIE habilitado
RPATH : Sin RPATH
RUNPATH : Sin RUNPATH
***************************************************************************
> CADENAS POSIBLES :
nth paddr vaddr len size section type string
―――――――――――――――――――――――――――――――――――――――――――――――――――――――
0 0x00002008 0x00002008 31 32 .rodata ascii You have bypassed this function
1 0x00002028 0x00002028 12 13 .rodata ascii cat flag.txt
2 0x00002035 0x00002035 15 16 .rodata ascii Enter your name
3 0x00002045 0x00002045 13 14 .rodata ascii Your name is
***************************************************************************
> HEXDUMP DE RODATA :
0x00002000 01000200 00000000 596f7520 68617665 ........You have
0x00002010 20627970 61737365 64207468 69732066 bypassed this f
0x00002020 756e6374 696f6e00 63617420 666c6167 unction.cat flag
0x00002030 2e747874 00456e74 65722079 6f757220 .txt.Enter your
0x00002040 6e616d65 00596f75 72206e61 6d652069 name.Your name i
0x00002050 732000 s .
***************************************************************************
> PUNTO DE ENTRADA ELF :
El punto de entrada del ELF está en 0x10c0
***************************************************************************
> MAPA DE MEMORIA DE CABECERA :
Type Offset VirtAddr PhysAddr
FileSiz MemSiz Flags Align
PHDR 0x0000000000000040 0x0000000000000040 0x0000000000000040
0x00000000000002d8 0x00000000000002d8 R 0x8
INTERP 0x0000000000000318 0x0000000000000318 0x0000000000000318
0x000000000000001c 0x000000000000001c R 0x1
[Requesting program interpreter: /lib64/ld-linux-x86-64.so.2]
LOAD 0x0000000000000000 0x0000000000000000 0x0000000000000000
0x00000000000006a8 0x00000000000006a8 R 0x1000
LOAD 0x0000000000001000 0x0000000000001000 0x0000000000001000
0x00000000000002b5 0x00000000000002b5 R E 0x1000
LOAD 0x0000000000002000 0x0000000000002000 0x0000000000002000
0x00000000000001c8 0x00000000000001c8 R 0x1000
LOAD 0x0000000000002da0 0x0000000000003da0 0x0000000000003da0
0x0000000000000270 0x0000000000000278 RW 0x1000
DYNAMIC 0x0000000000002db0 0x0000000000003db0 0x0000000000003db0
0x00000000000001f0 0x00000000000001f0 RW 0x8
NOTE 0x0000000000000338 0x0000000000000338 0x0000000000000338
0x0000000000000020 0x0000000000000020 R 0x8
NOTE 0x0000000000000358 0x0000000000000358 0x0000000000000358
0x0000000000000044 0x0000000000000044 R 0x4
GNU_PROPERTY 0x0000000000000338 0x0000000000000338 0x0000000000000338
0x0000000000000020 0x0000000000000020 R 0x8
GNU_EH_FRAME 0x0000000000002054 0x0000000000002054 0x0000000000002054
0x000000000000004c 0x000000000000004c R 0x4
GNU_STACK 0x0000000000000000 0x0000000000000000 0x0000000000000000
0x0000000000000000 0x0000000000000000 RWE 0x10
GNU_RELRO 0x0000000000002da0 0x0000000000003da0 0x0000000000003da0
0x0000000000000260 0x0000000000000260 R 0x1
***************************************************************************
[*] Loaded 14 cached gadgets for 'programvuln'
> GADGETS ROP :
0x1017 : add esp, 8;ret
0x1016 : add rsp, 8;ret
0x1221 : leave;ret
0x128c : pop r12;pop r13;pop r14;pop r15;ret
0x128e : pop r13;pop r14;pop r15;ret
0x1290 : pop r14;pop r15;ret
0x1292 : pop r15;ret
0x128b : pop rbp;pop r12;pop r13;pop r14;pop r15;ret
0x128f : pop rbp;pop r14;pop r15;ret
0x1193 : pop rbp;ret
0x1293 : pop rdi;ret
0x1291 : pop rsi;pop r15;ret
0x128d : pop rsp;pop r13;pop r14;pop r15;ret
0x101a : ret
***************************************************************************
> TABLA PLT :
__cxa_finalize : 0x1074
puts : 0x1084
system : 0x1094
printf : 0x10a4
gets : 0x10b4
***************************************************************************
> TABLA GOT :
_ITM_deregisterTMCloneTable : 0x3fd8
__libc_start_main : 0x3fe0
__gmon_start__ : 0x3fe8
_ITM_registerTMCloneTable : 0x3ff0
__cxa_finalize : 0x3ff8
puts : 0x3fb8
system : 0x3fc0
printf : 0x3fc8
gets : 0x3fd0
***************************************************************************
> TABLA DE FUNCIONES :