अपडेट पर वापस जाएँ
New releaseAug 10, 2026

r2frida v6.2.0

Radare2 और Frida एक साथ बेहतर।

साझा करें

r2frida

Radare2 और Frida एक साथ बेहतर ci radare2

विवरण

radare2 के लिए स्व-निहित प्लगइन जो frida को शामिल करता है और स्थानीय या दूरस्थ प्रक्रियाओं को r2 कमांड का उपयोग करके इंस्ट्रुमेंट करने की अनुमति देता है (लेकिन केवल Frida स्क्रिप्ट तक सीमित नहीं)।

radare प्रोजेक्ट रिवर्स इंजीनियरिंग के लिए एक पूर्ण टूलचेन प्रदान करता है, यह सक्रिय रूप से अनुरक्षित है और अच्छी तरह से अनुरक्षित कार्यक्षमताएं प्रदान करता है और अन्य प्रोग्रामिंग भाषाओं और टूल्स के साथ अपनी सुविधाओं का विस्तार करता है।

Frida एक डायनामिक इंस्ट्रुमेंटेशन टूलकिट है जो अपने स्वयं के JavaScript को इंजेक्ट करके चल रही प्रक्रियाओं का निरीक्षण और हेरफेर करना आसान बनाता है, और वैकल्पिक रूप से आपकी स्क्रिप्ट के साथ संवाद भी करता है।

विशेषताएं

  • असंशोधित Frida स्क्रिप्ट चलाएं (:. कमांड का उपयोग करें)
  • किसी भी प्रक्रिया में C, Javascript या TypeScript में स्निपेट निष्पादित करें
  • स्थानीय या दूरस्थ सिस्टम में अटैच, स्पॉन या लॉन्च कर सकते हैं
  • सेक्शन, सिंबल, एक्सपोर्ट, प्रोटोकॉल, क्लास, मेथड की सूची बनाएं
  • एजेंट के अंदर या होस्ट से मेमोरी में मान खोजें
  • मेथड इम्प्लीमेंटेशन को बदलें या छोटे कमांड के साथ हुक बनाएं
  • लक्ष्य प्रक्रिया में लाइब्रेरी और फ्रेमवर्क लोड करें
  • Dalvik, Java, ObjC, Swift और C इंटरफेस का समर्थन करें
  • फाइल डिस्क्रिप्टर और एनवायरनमेंट वेरिएबल में हेरफेर करें
  • प्रक्रिया को सिग्नल भेजें, जारी रखें, ब्रेकपॉइंट
  • r2frida io प्लगइन एक फाइलसिस्टम fs और debug बैकएंड भी है
  • r2pipe का उपयोग करके r2 और frida को स्वचालित करें
  • प्रक्रिया मेमोरी पढ़ें/लिखें
  • फंक्शन, सिसकॉल और रॉ कोड स्निपेट कॉल करें
  • usb या tcp/ip के माध्यम से frida-server से कनेक्ट करें
  • ऐप्स और प्रक्रियाओं की गणना करें
  • रजिस्टर, फंक्शन के आर्गुमेंट को ट्रेस करें
  • Linux, Windows, macOS, iOS और Android के लिए x64, arm32 और arm64 पर परीक्षण किया गया
  • होस्ट में frida इंस्टॉल होने की आवश्यकता नहीं है (frida-tools की आवश्यकता नहीं)
  • एजेंट में चलने वाले प्लगइन के साथ r2frida कमांड का विस्तार करें
  • पेज अनुमतियां बदलें, कोड और डेटा पैच करें
  • नाम या पते से सिंबल को हल करें और उन्हें r2 में फ्लैग के रूप में आयात करें
  • एजेंट से होस्ट में r2 कमांड चलाएं
  • r2 apis का उपयोग करें और दूरस्थ लक्ष्य प्रक्रिया के अंदर r2 कमांड चलाएं।
  • :db api का उपयोग करके नेटिव ब्रेकपॉइंट
  • r_fs api का उपयोग करके दूरस्थ फाइलसिस्टम तक पहुंचें।

इंस्टॉलेशन

r2frida इंस्टॉल करने का अनुशंसित तरीका r2pm के माध्यम से है:

$ r2pm -ci r2frida

संकलन की आवश्यकता नहीं वाले बाइनरी बिल्ड जल्द ही r2pm और r2env में समर्थित होंगे। इस बीच Releases पेज से नवीनतम बिल्ड डाउनलोड करने में संकोच न करें।

संकलन

निर्भरताएं

  • radare2
  • pkg-config (windows पर आवश्यक नहीं)
  • curl या wget
  • make, gcc
  • npm, nodejs (जल्द ही हटा दिया जाएगा)

GNU/Debian में आपको निम्नलिखित पैकेज इंस्टॉल करने होंगे:

$ sudo apt install -y make gcc libzip-dev nodejs npm curl pkg-config git

निर्देश

$ git clone https://github.com/nowsecure/r2frida.git
$ cd r2frida
$ make
$ make user-install

Windows

  • meson और Visual Studio इंस्टॉल करें
  • नवीनतम radare2 रिलीज ज़िप को r2frida रूट डायरेक्टरी में अनज़िप करें
  • इसका नाम बदलकर radare2 करें (radare2-x.y.z के बजाय)
  • PATH में VS कंपाइलर उपलब्ध कराने के लिए (preconfigure.bat)
  • configure.bat चलाएं और फिर make.bat

उपयोग

परीक्षण के लिए, r2 frida://0 का उपयोग करें, क्योंकि frida में pid0 से अटैच करना एक विशेष सत्र है जो स्थानीय रूप से चलता है। अब आप उपलब्ध कमांड की सूची प्राप्त करने के लिए :? कमांड चला सकते हैं।

$ r2 'frida://?'
r2 frida://[action]/[link]/[device]/[target]
* action = list | apps | attach | spawn | launch
* link   = local | usb | remote host:port
* device = '' | host:port | device-id
* target = pid | appname | process-name | program-in-path | abspath
Local:
* frida://?                        # show this help
* frida://                         # list local processes
* frida://0                        # attach to frida-helper (no spawn needed)
* frida:///usr/local/bin/rax2      # abspath to spawn
* frida://rax2                     # same as above, considering local/bin is in PATH
* frida://spawn/$(program)         # spawn a new process in the current system
* frida://attach/(target)          # attach to target PID in current host
USB:
* frida://list/usb//               # list processes in the first usb device
* frida://apps/usb//               # list apps in the first usb device
* frida://attach/usb//12345        # attach to given pid in the first usb device
* frida://spawn/usb//appname       # spawn an app in the first resolved usb device
* frida://launch/usb//appname      # spawn+resume an app in the first usb device
Remote:
* frida://attach/remote/10.0.0.3:9999/558 # attach to pid 558 on tcp remote frida-server
Environment: (Use the `%` command to change the environment at runtime)
  R2FRIDA_SAFE_IO=0|1              # Workaround a Frida bug on Android/thumb
  R2FRIDA_DEBUG=0|1                # Used to debug argument parsing behaviour
  R2FRIDA_COMPILER_DISABLE=0|1     # Disable the new frida typescript compiler (`:. foo.ts`)
  R2FRIDA_AGENT_SCRIPT=[file]      # path to file of the r2frida agent

उदाहरण

$ r2 frida://0     # same as frida -p 0, connects to a local session

आप किसी भी प्रोग्राम को नाम या pid से अटैच, स्पॉन या लॉन्च कर सकते हैं, निम्नलिखित पंक्ति पहली rax2 नाम की प्रक्रिया से अटैच होगी (इस पंक्ति का परीक्षण करने के लिए दूसरे टर्मिनल में rax2 - चलाएं)

$ r2 frida://rax2  # attach to the first process named `rax2`
$ r2 frida://1234  # attach to the given pid

स्पॉन करने के लिए बाइनरी के पूर्ण पथ का उपयोग करने से प्रक्रिया स्पॉन होगी:

$ r2 frida:///bin/ls
[0x00000000]> :dc        # continue the execution of the target program

आर्गुमेंट के साथ भी काम करता है:

$ r2 frida://"/bin/ls -al"

USB डिबगिंग iOS/Android ऐप्स के लिए इन क्रियाओं का उपयोग करें। ध्यान दें कि spawn को launch या attach से बदला जा सकता है, और प्रक्रिया का नाम bundleid या PID हो सकता है।

$ r2 frida://spawn/usb/         # enumerate devices
$ r2 frida://spawn/usb//        # enumerate apps in the first iOS device
$ r2 frida://spawn/usb//Weather # Run the weather app

कमांड

ये सबसे अधिक उपयोग किए जाने वाले कमांड हैं, इसलिए आपको इन्हें सीखना चाहिए और सबकमांड सहायता प्राप्त करने के लिए इनके साथ ? लगाना चाहिए।

:i        # get information of the target (pid, name, home, arch, bits, ..)
.:i*      # import the target process details into local r2
:?        # show all the available commands
:dm       # list maps. Use ':dm|head' and seek to the program base address
:iE       # list the exports of the current binary (seek)
:dt fread # trace the 'fread' function
:dt-*     # delete all traces

प्लगइन

r2frida प्लगइन एजेंट साइड में चलते हैं और r2frida.pluginRegister API के साथ पंजीकृत होते हैं।

कुछ और उदाहरण प्लगइन स्क्रिप्ट के लिए plugins/ डायरेक्टरी देखें।

[0x00000000]> cat example.js
r2frida.pluginRegister('test', function(name) {
  if (name === 'test') {
    return function(args) {
      console.log('Hello Args From r2frida plugin', args);
      return 'Things Happen';
    }
  }
});
[0x00000000]> :. example.js   # load the plugin script

:. कमांड r2 के . कमांड की तरह काम करता है, लेकिन एजेंट के अंदर चलता है।

:. a.js  # run script which registers a plugin
:.       # list plugins
:.-test  # unload a plugin by name
:.. a.js # eternalize script (keeps running after detach)

Termux

श्रेणियाँ