
Radare2 e Frida meglio insieme.
Radare2 e Frida, meglio insieme
Plugin autonomo per radare2 che include frida e consente di strumentare processi locali o remoti utilizzando comandi r2 invece (ma non solo) di script Frida.
Il progetto radare fornisce una toolchain completa per il reverse engineering, è attivamente mantenuto e offre funzionalità ben mantenute ed estende le sue caratteristiche con altri linguaggi di programmazione e strumenti.
Frida è un toolkit di strumentazione dinamica che semplifica l'ispezione e la manipolazione dei processi in esecuzione iniettando il tuo JavaScript, e opzionalmente comunicando anche con i tuoi script.
:.):dbr_fs.Il modo consigliato per installare r2frida è tramite r2pm:
$ r2pm -ci r2frida
Le build binarie che non richiedono compilazione saranno presto supportate in
r2pm e r2env. Nel frattempo sentiti libero di scaricare le ultime build
dalla pagina delle Release.
Su GNU/Debian dovrai installare i seguenti pacchetti:
$ sudo apt install -y make gcc libzip-dev nodejs npm curl pkg-config git
$ git clone https://github.com/nowsecure/r2frida.git
$ cd r2frida
$ make
$ make user-install
radare2 (invece di radare2-x.y.z)preconfigure.bat)configure.bat e poi make.batPer testare, usa r2 frida://0, poiché l'attach al pid0 in frida è una sessione
speciale che gira in locale. Ora puoi eseguire il comando :? per ottenere la lista
dei comandi disponibili.
$ r2 'frida://?'
r2 frida://[action]/[link]/[device]/[target]
* action = list | apps | attach | spawn | launch
* link = local | usb | remote host:port
* device = '' | host:port | device-id
* target = pid | appname | process-name | program-in-path | abspath
Local:
* frida://? # show this help
* frida:// # list local processes
* frida://0 # attach to frida-helper (no spawn needed)
* frida:///usr/local/bin/rax2 # abspath to spawn
* frida://rax2 # same as above, considering local/bin is in PATH
* frida://spawn/$(program) # spawn a new process in the current system
* frida://attach/(target) # attach to target PID in current host
USB:
* frida://list/usb// # list processes in the first usb device
* frida://apps/usb// # list apps in the first usb device
* frida://attach/usb//12345 # attach to given pid in the first usb device
* frida://spawn/usb//appname # spawn an app in the first resolved usb device
* frida://launch/usb//appname # spawn+resume an app in the first usb device
Remote:
* frida://attach/remote/10.0.0.3:9999/558 # attach to pid 558 on tcp remote frida-server
Environment: (Use the `%` command to change the environment at runtime)
R2FRIDA_SAFE_IO=0|1 # Workaround a Frida bug on Android/thumb
R2FRIDA_DEBUG=0|1 # Used to debug argument parsing behaviour
R2FRIDA_COMPILER_DISABLE=0|1 # Disable the new frida typescript compiler (`:. foo.ts`)
R2FRIDA_AGENT_SCRIPT=[file] # path to file of the r2frida agent
$ r2 frida://0 # same as frida -p 0, connects to a local session
Puoi fare attach, spawn o launch su qualsiasi programma per nome o pid. La riga seguente farà attach al primo processo chiamato rax2 (esegui rax2 - in un altro terminale per testare questa riga)
$ r2 frida://rax2 # attach to the first process named `rax2`
$ r2 frida://1234 # attach to the given pid
Usare il percorso assoluto di un binario per lo spawn avvierà il processo:
$ r2 frida:///bin/ls
[0x00000000]> :dc # continue the execution of the target program
Funziona anche con argomenti:
$ r2 frida://"/bin/ls -al"
Per il debug USB di app iOS/Android usa queste azioni. Nota che spawn
può essere sostituito con launch o attach, e il nome del processo può essere
il bundleid o il PID.
$ r2 frida://spawn/usb/ # enumerate devices
$ r2 frida://spawn/usb// # enumerate apps in the first iOS device
$ r2 frida://spawn/usb//Weather # Run the weather app
Questi sono i comandi più frequenti, quindi devi impararli e aggiungere il suffisso ? per ottenere l'aiuto sui sottocomandi.
:i # get information of the target (pid, name, home, arch, bits, ..)
.:i* # import the target process details into local r2
:? # show all the available commands
:dm # list maps. Use ':dm|head' and seek to the program base address
:iE # list the exports of the current binary (seek)
:dt fread # trace the 'fread' function
:dt-* # delete all traces
I plugin di r2frida girano lato agent e sono registrati con l'API r2frida.pluginRegister.
Vedi la directory plugins/ per altri esempi di script plugin.
[0x00000000]> cat example.js
r2frida.pluginRegister('test', function(name) {
if (name === 'test') {
return function(args) {
console.log('Hello Args From r2frida plugin', args);
return 'Things Happen';
}
}
});
[0x00000000]> :. example.js # load the plugin script
Il comando :. funziona come il comando . di r2, ma gira all'interno dell'agent.
:. a.js # run script which registers a plugin
:. # list plugins
:.-test # unload a plugin by name
:.. a.js # eternalize script (keeps running after detach)