Skip to content
KitploitKITPLOIT
HerramientasBlog
Log in
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
asafw — Conjunto de scripts para trabajar con el firmware de Cisco ASA [empaquetar/desempaquetar, etc.] | Kitploit
Herramientas/GitHubGitHub/nccgroup/asafw
Seguridad de Sistemas EmbebidosExplotaciónIngeniería InversaDepuradoresSeguridad de HardwareAnálisis de BinariosAnálisis de Firmware
GitHubnccgroup/asafw

asafw

Conjunto de scripts para trabajar con el firmware de Cisco ASA [empaquetar/desempaquetar, etc.]

Ver Repositorio
1073618hace 4 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

asafw

Nota preliminar: recomendamos usarlo como parte de asatools, aunque también puede usarse de forma independiente.

asafw es un conjunto de scripts para trabajar con firmware de Cisco ASA. Permite desempaquetar el firmware necesario para depurar con gdb, así como desempaquetarlo/volver a empaquetarlo para habilitar ciertas funciones como:

  • Habilitar gdb en el arranque
  • Deshabilitar ASLR para facilitar la depuración
  • Inyectar un shell de depuración de Linux que permita usar CTRL^C en gdb cuando se usa con hardware real
  • Obtener root en un firmware (generalmente obsoleto al habilitar gdb en el arranque e inyectar un shell root)
  • etc.

Las herramientas más útiles son unpack_repack_bin.sh y unpack_repack_qcow2.sh. Permiten manipular respectivamente los formatos de imagen asa*.bin y asav*.qcow2. Ambos deben ejecutarse como root al volver a empaquetar el rootfs para conservar los permisos correctos.

Requisitos

  • Solo Python3
  • apt install binwalk qemu-utils
  • Probado exhaustivamente en Linux (pero también podría funcionar en OS X)

Inicialmente debes modificar asafw/env.sh para adaptarlo a tu entorno. Esto te permitirá definir las rutas a las herramientas utilizadas por todos los scripts, así como algunas variables acordes a tu entorno ASA. Ten en cuenta que existe un asadbg/env.sh similar, pero solo se necesita usar uno para ambos proyectos. Recomendamos que lo añadas a tu ~/.bashrc:``` source /path/to/asafw/env.sh

# unpack_repack_bin.sh

`unpack_repack_bin.sh` se utiliza para desempaquetar/reempaquetar imágenes `asa*.bin` que se usan para hardware real de Cisco ASA (como las series ASA 5500 y 5500-X). El uso completo es:```
$ unpack_repack_bin.sh -h
Usage:
./unpack_repack_bin.sh -i <firmware_file> -o <out_dir> [-f -g -G -a -A -m -b -r -u -l <linabin_dir> -d -e -k]
      -h, --help                    This help menu
      -i, --input <firmware_file>   What firmware bin to operate on
      -o, --output  <out_dir>       Where to write new firmware
      -f, --free-space              Remove space from .bin to ensure injections fit
      -g, --enable-gdb              Set gdb to start on boot
      -G, --disable-gdb             Stop gdb from starting on boot
      -a, --enable-aslr             Turn on ASLR
      -A, --disable-aslr            Turn off ASLR
      -m, --inject-gdb              Inject gdbserver to run
      -b, --debug-shell             Inject ssh-triggered debug shell
      -H, --lina-hook               Inject hooks for monitor lina heap (requires -b)
      -r, --root                    root the bin to get a rootshell on boot
      -c, --custom                  custom?
      -n, --n-custom                custom?
      -q, --gns3-fixup              gns?
      -u, --unpack-only             unpack the firmware and nothing else
      -l, --linabins <linabin_dir>  destination folder to save lina binaries
      -d, --delete-extracted        delete files extracted during modification
      -e, --delete-original-bin     delete the original firmware being modified
      -k, --keep-rootfs             keep the extracted rootfs on disk
      -s, --simple-name             use a simple name for the output .bin with just appended '-repacked'
Examples:
 ./unpack_repack_bin.sh -i /home/user/firmware -o /home/user/firmware_repacked --free-space --enable-gdb --inject-gdb
 ./unpack_repack_bin.sh -i /home/user/firmware/asa961-smp-k8.bin -f -g -m
 ./unpack_repack_bin.sh -u -i /home/user/firmware -l /home/user/linabins
 ./unpack_repack_bin.sh -u -i /home/user/firmware/asa924-k8.bin -k

Extract multiple firmware

Supongamos que tenemos estos dos firmware:``` ~/fw$ ls asa924-k8.bin asa981-smp-k8.bin

Si solo quieres extraer el firmware, p. ej. para depurarlo con
[asadbg](https://github.com/nccgroup/asadbg), puedes usar `-u` para solo desempaquetar
y `-k` para conservar solo el rootfs y eliminar los otros archivos extraídos por binwalk
que no necesitas. Ten en cuenta que la carpeta de salida es la misma que la carpeta de entrada
ya que dependemos de binwalk para esto:```
~/fw$ unpack_repack_bin.sh -i . -k -u
[unpack_repack_bin] Directory of firmware detected: .
[unpack_repack_bin] extract_one: asa924-k8.bin

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
75000         0x124F8         SHA256 hash constants, little endian
144510        0x2347E         gzip compressed data, maximum compression, from Unix, last modified: 2015-07-15 04:53:23
1501296       0x16E870        gzip compressed data, has original file name: "rootfs.img", from Unix, last modified: 2015-07-15 05:19:52
27168620      0x19E8F6C       MySQL ISAM index file Version 4
28192154      0x1AE2D9A       Zip archive data, at least v2.0 to extract, name: com/cisco/webvpn/csvrjavaloader64.dll
28773362      0x1B70BF2       Zip archive data, at least v2.0 to extract, name: AliasHandlerWrapper-win64.dll

[unpack_repack_bin] Extracted firmware to /home/user/fw/_asa924-k8.bin.extracted
[unpack_repack_bin] Firmware uses regular rootfs/ dir
[unpack_repack_bin] Extracting /home/user/fw/_asa924-k8.bin.extracted/rootfs/rootfs.img into /home/user/fw/_asa924-k8.bin.extracted/rootfs
[unpack_repack_bin] Keeping rootfs
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/rootfs.img"
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/2347E"
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/1AE2D9A.zip"
[unpack_repack_bin] extract_one: asa981-smp-k8.bin

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
75264         0x12600         SHA256 hash constants, little endian
133120        0x20800         Microsoft executable, portable (PE)
149183        0x246BF         gzip compressed data, maximum compression, from Unix, last modified: 2017-01-30 19:33:09
3678112       0x381FA0        gzip compressed data, has original file name: "rootfs.img", from Unix, last modified: 2017-05-10 22:42:05
14838307      0xE26A23        MySQL MISAM compressed data file Version 4
87985870      0x53E8ECE       MySQL MISAM compressed data file Version 7
96261881      0x5BCD6F9       Zip archive data, at least v2.0 to extract, name: com/cisco/webvpn/csvrjavaloader64.dll
96890193      0x5C66D51       MySQL ISAM compressed data file Version 5

[unpack_repack_bin] Extracted firmware to /home/user/fw/_asa981-smp-k8.bin.extracted
[unpack_repack_bin] Firmware uses regular rootfs/ dir
[unpack_repack_bin] Extracting /home/user/fw/_asa981-smp-k8.bin.extracted/rootfs/rootfs.img into /home/user/fw/_asa981-smp-k8.bin.extracted/rootfs
[unpack_repack_bin] Keeping rootfs
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/rootfs.img"
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/5BCD6F9.zip"
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/246BF"

Ten en cuenta que los errores como los de abajo que puedas obtener no importan en este caso porque no vas a reempaquetar el firmware:``` cpio: lib/udev/devices/kmem: Function mknod failed: Operation not permitted cpio: lib/udev/devices/net/tun: Function mknod failed: Operation not permitted cpio: lib/udev/devices/loop01: Function mknod failed: Operation not permitted cpio: lib/udev/devices/null: Function mknod failed: Operation not permitted cpio: lib/udev/devices/console: Function mknod failed: Operation not permitted cpio: lib/udev/devices/loop00: Function mknod failed: Operation not permitted 134992 blocks

## Habilitar gdb en el arranque / shell de depuración
Descargar herramienta