Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
asafw — Cisco ASAファームウェアを扱うためのスクリプト集 [パック/アンパックなど] | Kitploit
ツール/GitHubGitHub/nccgroup/asafw
組み込みシステムセキュリティエクスプロイトリバースエンジニアリングデバッガハードウェアセキュリティバイナリ解析ファームウェア解析
GitHubnccgroup/asafw

asafw

Cisco ASAファームウェアを扱うためのスクリプト集 [パック/アンパックなど]

リポジトリを見る
10736184年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

asafw

予備的な注意: これは asatools の一部として使用することをお勧めしますが、スタンドアロンでも使用できます。

asafw は、Cisco ASA ファームウェアを扱うためのスクリプト群です。gdb でのデバッグに必要なファームウェアの展開や、以下のような特定の機能を有効にするための展開/再パックを行うことができます。

  • 起動時に gdb を有効化
  • デバッグを容易にするために ASLR を無効化
  • 実際のハードウェアで使用する際に gdb で CTRL^C を可能にする Linux デバッグシェルを注入
  • ファームウェアの root 化(通常は起動時の gdb 有効化と root シェルの注入によって非推奨)
  • など

より便利なツールは unpack_repack_bin.sh と unpack_repack_qcow2.sh です。これらはそれぞれ asa*.bin および asav*.qcow2 イメージ形式を操作できます。rootfs を実際に再パックする際は、正しいパーミッションを維持するために両方とも root として実行する必要があります。

要件

  • Python3 のみ
  • apt install binwalk qemu-utils
  • Linux で重点的にテスト済み(OS X でも動作する可能性あり)

最初に、環境に合わせて asafw/env.sh を修正する必要があります。これにより、すべてのスクリプトで使用されるツールへのパスと、ASA 環境に一致するいくつかの変数を定義できます。類似した asadbg/env.sh もありますが、両方のプロジェクトで使用するために必要なのは1つだけです。~/.bashrc に追加することをお勧めします:``` source /path/to/asafw/env.sh

# unpack_repack_bin.sh

`unpack_repack_bin.sh` は、実機の Cisco ASA ハードウェア(ASA 5500 や 5500-X シリーズなど)で使用される `asa*.bin` イメージの展開/再パックに使用します。完全な使用方法は次のとおりです。```
$ unpack_repack_bin.sh -h
Usage:
./unpack_repack_bin.sh -i <firmware_file> -o <out_dir> [-f -g -G -a -A -m -b -r -u -l <linabin_dir> -d -e -k]
      -h, --help                    This help menu
      -i, --input <firmware_file>   What firmware bin to operate on
      -o, --output  <out_dir>       Where to write new firmware
      -f, --free-space              Remove space from .bin to ensure injections fit
      -g, --enable-gdb              Set gdb to start on boot
      -G, --disable-gdb             Stop gdb from starting on boot
      -a, --enable-aslr             Turn on ASLR
      -A, --disable-aslr            Turn off ASLR
      -m, --inject-gdb              Inject gdbserver to run
      -b, --debug-shell             Inject ssh-triggered debug shell
      -H, --lina-hook               Inject hooks for monitor lina heap (requires -b)
      -r, --root                    root the bin to get a rootshell on boot
      -c, --custom                  custom?
      -n, --n-custom                custom?
      -q, --gns3-fixup              gns?
      -u, --unpack-only             unpack the firmware and nothing else
      -l, --linabins <linabin_dir>  destination folder to save lina binaries
      -d, --delete-extracted        delete files extracted during modification
      -e, --delete-original-bin     delete the original firmware being modified
      -k, --keep-rootfs             keep the extracted rootfs on disk
      -s, --simple-name             use a simple name for the output .bin with just appended '-repacked'
Examples:
 ./unpack_repack_bin.sh -i /home/user/firmware -o /home/user/firmware_repacked --free-space --enable-gdb --inject-gdb
 ./unpack_repack_bin.sh -i /home/user/firmware/asa961-smp-k8.bin -f -g -m
 ./unpack_repack_bin.sh -u -i /home/user/firmware -l /home/user/linabins
 ./unpack_repack_bin.sh -u -i /home/user/firmware/asa924-k8.bin -k

複数のファームウェアを抽出する

次の2つのファームウェアがあるとします:``` ~/fw$ ls asa924-k8.bin asa981-smp-k8.bin

ファームウェアを抽出するだけの場合、例えばデバッグするために
[asadbg](https://github.com/nccgroup/asadbg) を使用し、`-u` で展開のみを行い、
`-k` で rootfs だけを保持して、binwalk が抽出した他の不要なファイルを削除できます。
出力フォルダは入力フォルダと同じであることに注意してください。
これは binwalk に依存しているためです:```
~/fw$ unpack_repack_bin.sh -i . -k -u
[unpack_repack_bin] Directory of firmware detected: .
[unpack_repack_bin] extract_one: asa924-k8.bin

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
75000         0x124F8         SHA256 hash constants, little endian
144510        0x2347E         gzip compressed data, maximum compression, from Unix, last modified: 2015-07-15 04:53:23
1501296       0x16E870        gzip compressed data, has original file name: "rootfs.img", from Unix, last modified: 2015-07-15 05:19:52
27168620      0x19E8F6C       MySQL ISAM index file Version 4
28192154      0x1AE2D9A       Zip archive data, at least v2.0 to extract, name: com/cisco/webvpn/csvrjavaloader64.dll
28773362      0x1B70BF2       Zip archive data, at least v2.0 to extract, name: AliasHandlerWrapper-win64.dll

[unpack_repack_bin] Extracted firmware to /home/user/fw/_asa924-k8.bin.extracted
[unpack_repack_bin] Firmware uses regular rootfs/ dir
[unpack_repack_bin] Extracting /home/user/fw/_asa924-k8.bin.extracted/rootfs/rootfs.img into /home/user/fw/_asa924-k8.bin.extracted/rootfs
[unpack_repack_bin] Keeping rootfs
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/rootfs.img"
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/2347E"
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/1AE2D9A.zip"
[unpack_repack_bin] extract_one: asa981-smp-k8.bin

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
75264         0x12600         SHA256 hash constants, little endian
133120        0x20800         Microsoft executable, portable (PE)
149183        0x246BF         gzip compressed data, maximum compression, from Unix, last modified: 2017-01-30 19:33:09
3678112       0x381FA0        gzip compressed data, has original file name: "rootfs.img", from Unix, last modified: 2017-05-10 22:42:05
14838307      0xE26A23        MySQL MISAM compressed data file Version 4
87985870      0x53E8ECE       MySQL MISAM compressed data file Version 7
96261881      0x5BCD6F9       Zip archive data, at least v2.0 to extract, name: com/cisco/webvpn/csvrjavaloader64.dll
96890193      0x5C66D51       MySQL ISAM compressed data file Version 5

[unpack_repack_bin] Extracted firmware to /home/user/fw/_asa981-smp-k8.bin.extracted
[unpack_repack_bin] Firmware uses regular rootfs/ dir
[unpack_repack_bin] Extracting /home/user/fw/_asa981-smp-k8.bin.extracted/rootfs/rootfs.img into /home/user/fw/_asa981-smp-k8.bin.extracted/rootfs
[unpack_repack_bin] Keeping rootfs
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/rootfs.img"
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/5BCD6F9.zip"
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/246BF"

以下のようなエラーが表示されても、この場合は問題ありません。ファームウェアを 再パッケージするわけではないからです:``` cpio: lib/udev/devices/kmem: Function mknod failed: Operation not permitted cpio: lib/udev/devices/net/tun: Function mknod failed: Operation not permitted cpio: lib/udev/devices/loop01: Function mknod failed: Operation not permitted cpio: lib/udev/devices/null: Function mknod failed: Operation not permitted cpio: lib/udev/devices/console: Function mknod failed: Operation not permitted cpio: lib/udev/devices/loop00: Function mknod failed: Operation not permitted 134992 blocks

## 起動時にgdbを有効化 / デバッグシェル
ツールをダウンロード