
idahuntは、IDA Proでバイナリを分析し、IDA Pro内でものを探すためのフレームワークです。

idahunt は、IDA Pro でバイナリを解析し、IDA Pro 内の情報を探すためのフレームワークです。 指定されたフォルダから再帰的にすべての実行可能ファイルを解析するコマンドラインツールです。 バックグラウンドで IDA を実行するため、各ファイルを手動で開く必要はありません。 外部の IDA Python スクリプトの実行にも対応しています。
有用な例としては、以下があります(網羅的ではありません):
IDA Python スクリプトの機能は無限です。既存の IDA Python スクリプトを インポートすることも、独自に作成することもできます。いくつかの例:
idahunt.py: 実行可能ファイルを解析するためのメインツールfilters/: 入力ディレクトリ内のどのファイルを IDA で解析するかを決定する基本的なフィルタを含む
filters/default.py: 何もフィルタリングしないデフォルトの基本フィルタ。デフォルトで使用filters/ciscoasa.py: Cisco ASA ファイアウォールイメージの解析に有用filters/hpilo.py: HP iLO イメージの解析に有用filters/names.py: 名前、名前の長さ、または拡張子に基づく基本フィルタscript_template.py: hello world IDA Python スクリプトを含むC:\idahunt> C:\Python37-x64\python.exe .\idahunt.py -h
usage: idahunt.py [-h] [--inputdir INPUTDIR] [--analyse] [--open]
[--ida-args IDA_ARGS] [--scripts SCRIPTS [SCRIPTS ...]]
[--filter FILTER] [--cleanup] [--temp-cleanup] [--verbose]
[--max-ida MAX_IDA] [--list-only] [--version IDA_VERSION]
optional arguments:
-h, --help show this help message and exit
--inputdir INPUTDIR Input folder to search for files
--analyse, --analyze analyse all files i.e. create .idb for all of them
--open open all files into IDA (debug only)
--ida-args IDA_ARGS Additional arguments to pass to IDA (e.g.
-p<processor> -i<entry_point> -b<load_addr>)
--scripts SCRIPTS [SCRIPTS ...]
List of IDA Python scripts to execute in this order
--filter FILTER External python script with optional arguments
defining a filter for the names of the files to
analyse. See filters/names.py for example
--cleanup Cleanup i.e. remove .asm files that we don't need
--temp-cleanup Cleanup temporary database files i.e. remove .id0,
.id1, .id2, .nam, .dmp files if IDA Pro crashed and
did not delete them
--verbose be more verbose to debug script
--max-ida MAX_IDA Maximum number of instances of IDA to run at a time
(default: 10)
--list-only List only what files would be handled without
executing IDA
--version IDA_VERSION
Override IDA version (e.g. "7.5"). This is used to
find the path of IDA on Windows.
--list-only は、任意のコマンドラインと一緒に使用すると、ツールが実際に実行せずに
何を行うかを一覧表示するだけです。
C:\idahunt>idahunt.py --inputdir C:\re --analyse --filter "filters\names.py -a 32 -v" --list-only
[idahunt] Simulating only...
[idahunt] ANALYSING FILES
[idahunt] Analysing C:\re\cves\cve-2014-4076.dll
[idahunt] Analysing C:\re\cves\cve-2014-4076.exe
[idahunt] Analysing C:\re\DownloadExecute.exe
[idahunt] Analysing C:\re\ReverseShell.exe
ここでは初期解析を開始します。数秒で完了します:
C:\idahunt>idahunt.py --inputdir C:\re --analyse --filter "filters\names.py -a 32 -v"
[idahunt] ANALYSING FILES
[idahunt] Analysing C:\re\cves\cve-2014-4076.dll
[idahunt] Analysing C:\re\cves\cve-2014-4076.exe
[idahunt] Analysing C:\re\DownloadExecute.exe
[idahunt] Analysing C:\re\ReverseShell.exe
[idahunt] Waiting on remaining 4 IDA instances
ここでは、初期解析で作成された一時的な .asm ファイルをクリーンアップします:
C:\idahunt>idahunt.py --inputdir C:\re --cleanup
[idahunt] Deleting C:\re\cves\cve-2014-4076.asm
[idahunt] Deleting C:\re\DownloadExecute.asm
[idahunt] Deleting C:\re\ReverseShell.asm
生成された .idb と、IDA Pro の出力ウィンドウの内容を含む .log ファイルも確認できます。
C:\idahunt>tree /f C:\re
Folder PATH listing
Volume serial number is XXXX-XXXX
C:\RE
│ DownloadExecute.exe
│ DownloadExecute.idb
│ DownloadExecute.log
│ ReverseShell.exe
│ ReverseShell.idb
│ ReverseShell.log
│
└───cves
cve-2014-4076.dll
cve-2014-4076.exe
cve-2014-4076.idb
cve-2014-4076.log
ここでは、IDA Pro の出力ウィンドウに
[script_template] I execute in IDA, yay! と表示する基本的な IDA Python スクリプトを実行します。
C:\idahunt>idahunt.py --inputdir C:\re --filter "filters\names.py -a 32 -v" --scripts C:\idahunt\script_template.py
[idahunt] EXECUTE SCRIPTS
[idahunt] Executing script C:\idahunt\script_template.py for C:\re\cves\cve-2014-4076.dll
[idahunt] Executing script C:\idahunt\script_template.py for C:\re\cves\cve-2014-4076.exe
[idahunt] Executing script C:\idahunt\script_template.py for C:\re\DownloadExecute.exe
[idahunt] Executing script C:\idahunt\script_template.py for C:\re\ReverseShell.exe
[idahunt] Waiting on remaining 4 IDA instances
これは .log ファイルに保存されるため、正常に実行されたことを確認できます:
Autoanalysis subsystem has been initialized.
Database for file 'ReverseShell.exe' has been loaded.
Compiling file 'C:\Program Files (x86)\IDA 6.95\idc\ida.idc'...
Executing function 'main'...
[script_template] I execute in IDA, yay!
idahunt は、この PR 以降、diaphora と見事に連携してバイナリ差分を実行できます。
同じファイル名の異なるバージョンを持つフォルダ階層が必要です。例:
C:\> tree C:\tests\ /F
C:\tests
├───patch
│ tm.sys
│
└───vuln
tm.sys
まだ完了していない場合は、IDB を作成するための初期 IDA 解析を実行する必要があります。
C:\idahunt> python idahunt.py --inputdir C:\tests\ --analyse --verbose
[idahunt] IDA32 = C:\Program Files\IDA Core 8.1\ida.exe
[idahunt] IDA64 = C:\Program Files\IDA Core 8.1\ida64.exe
[idahunt] ANALYSING FILES
[idahunt] Analysing C:\tests\patch\tm.sys
[idahunt] C:\Program Files\IDA Core 8.1\ida64.exe -B -oC:\tests\patch\tm.i64 -LC:\tests\patch\tm.log C:\tests\patch\tm.sys
[idahunt] Analysing C:\tests\vuln\tm.sys
[idahunt] C:\Program Files\IDA Core 8.1\ida64.exe -B -oC:\tests\vuln\tm.i64 -LC:\tests\vuln\tm.log C:\tests\vuln\tm.sys
[idahunt] Executed IDA 2/2 times IDA instances
[idahunt] Took 0:00:15.03 to execute this
C:\> tree C:\tests\ /F
C:\tests
├───patch
│ tm.i64
│ tm.log
│ tm.sys
│
└───vuln
tm.i64
tm.log
tm.sys
これは diaphora を使用して、各ファイルの差分エクスポートを行い(<filename>.sqlite sqlite3 データベースを作成)、その後バージョン間の差分を実行します(<filename>.diaphora sqlite3 データベースを作成)。