
Radare2とFridaは一緒に使うとより優れています。
radare2 用の自己完結型プラグインで、 frida を同梱し、Frida スクリプトだけでなく r2 コマンドを使ってローカルまたはリモートのプロセスをインストルメント できるようにします。
radare プロジェクトはリバースエンジニアリングのための完全なツール チェーンを提供しており、活発にメンテナンスされ、よく整備された機能を 提供し、他のプログラミング言語やツールでその機能を拡張しています。
Frida は動的インストルメンテーションツールキットで、独自の JavaScript を注入することで実行中のプロセスを簡単に検査・操作でき、オプションで スクリプトと通信することもできます。
:. コマンドを使用):db API を使用したネイティブブレークポイントr_fs API を使用したリモートファイルシステムへのアクセスr2frida をインストールする推奨方法は r2pm 経由です:
$ r2pm -ci r2frida
コンパイルを必要としないバイナリビルドは、まもなく r2pm と r2env
でサポートされる予定です。それまでの間、Releases ページ
から最新のビルドを自由にダウンロードしてください。
GNU/Debian では以下のパッケージをインストールする必要があります:
$ sudo apt install -y make gcc libzip-dev nodejs npm curl pkg-config git
$ git clone https://github.com/nowsecure/r2frida.git
$ cd r2frida
$ make
$ make user-install
radare2 にリネームする(radare2-x.y.z ではなく)preconfigure.bat)configure.bat を実行し、次に make.bat を実行するテストには r2 frida://0 を使用します。frida で pid0 にアタッチすることは
ローカルで実行される特別なセッションだからです。これで :? コマンドを
実行して利用可能なコマンドの一覧を取得できます。
$ r2 'frida://?'
r2 frida://[action]/[link]/[device]/[target]
* action = list | apps | attach | spawn | launch
* link = local | usb | remote host:port
* device = '' | host:port | device-id
* target = pid | appname | process-name | program-in-path | abspath
Local:
* frida://? # show this help
* frida:// # list local processes
* frida://0 # attach to frida-helper (no spawn needed)
* frida:///usr/local/bin/rax2 # abspath to spawn
* frida://rax2 # same as above, considering local/bin is in PATH
* frida://spawn/$(program) # spawn a new process in the current system
* frida://attach/(target) # attach to target PID in current host
USB:
* frida://list/usb// # list processes in the first usb device
* frida://apps/usb// # list apps in the first usb device
* frida://attach/usb//12345 # attach to given pid in the first usb device
* frida://spawn/usb//appname # spawn an app in the first resolved usb device
* frida://launch/usb//appname # spawn+resume an app in the first usb device
Remote:
* frida://attach/remote/10.0.0.3:9999/558 # attach to pid 558 on tcp remote frida-server
Environment: (Use the `%` command to change the environment at runtime)
R2FRIDA_SAFE_IO=0|1 # Workaround a Frida bug on Android/thumb
R2FRIDA_DEBUG=0|1 # Used to debug argument parsing behaviour
R2FRIDA_COMPILER_DISABLE=0|1 # Disable the new frida typescript compiler (`:. foo.ts`)
R2FRIDA_AGENT_SCRIPT=[file] # path to file of the r2frida agent
$ r2 frida://0 # same as frida -p 0, connects to a local session
任意のプログラムに名前または pid でアタッチ、スポーン、起動できます。
次の行は rax2 という名前の最初のプロセスにアタッチします(この行を
テストするには別のターミナルで rax2 - を実行してください)
$ r2 frida://rax2 # attach to the first process named `rax2`
$ r2 frida://1234 # attach to the given pid
バイナリの絶対パスを使ってスポーンすると、そのプロセスがスポーンされます:
$ r2 frida:///bin/ls
[0x00000000]> :dc # continue the execution of the target program
引数付きでも動作します:
$ r2 frida://"/bin/ls -al"
iOS/Android アプリの USB デバッグにはこれらのアクションを使用します。
spawn は launch または attach に置き換えることができ、プロセス名
には bundleid または PID を指定できることに注意してください。
$ r2 frida://spawn/usb/ # enumerate devices
$ r2 frida://spawn/usb// # enumerate apps in the first iOS device
$ r2 frida://spawn/usb//Weather # Run the weather app
これらは最も頻繁に使用されるコマンドなので、必ず覚えて、サブコマンドの
ヘルプを取得するには ? を付けてください。
:i # get information of the target (pid, name, home, arch, bits, ..)
.:i* # import the target process details into local r2
:? # show all the available commands
:dm # list maps. Use ':dm|head' and seek to the program base address
:iE # list the exports of the current binary (seek)
:dt fread # trace the 'fread' function
:dt-* # delete all traces
r2frida プラグインはエージェント側で動作し、r2frida.pluginRegister API
で登録されます。
その他のプラグインスクリプトの例については plugins/ ディレクトリを
参照してください。
[0x00000000]> cat example.js
r2frida.pluginRegister('test', function(name) {
if (name === 'test') {
return function(args) {
console.log('Hello Args From r2frida plugin', args);
return 'Things Happen';
}
}
});
[0x00000000]> :. example.js # load the plugin script
:. コマンドは r2 の . コマンドのように動作しますが、エージェント内で
実行されます。
:. a.js # run script which registers a plugin
:. # list plugins
:.-test # unload a plugin by name
:.. a.js # eternalize script (keeps running after detach)
Termux 経由で Android 上で r2frida をネイティブにインストールして使用
する場合、シンボル解決のためにライブラリ依存関係に関していくつかの
注意点があります。これを動作させる方法は、termux の libdir の前に
システムディレクトリを指すように LD_LIBRARY_PATH 環境変数を拡張する
ことです。
$ LD_LIBRARY_PATH=/system/lib64:$LD_LIBRARY_PATH r2 frida://...
最新バージョンの r2(できれば最新リリースまたは git)を使用している ことを確認してください。
CI は radare2 6.2.2 リリースと git master をテストしています。 互換性ヘルパーは、古い radare2 ABI での Windows 絶対パス検出と クォートされたスクリプトファイル名を保持します。
r2 -L | grep frida を実行してプラグインがロードされているか確認して
ください。何も出力されない場合は R2_DEBUG=1 環境変数を使用して
デバッグメッセージを取得し、原因を突き止めてください。
r2frida のコンパイルに問題がある場合は、r2env を使用するか、GitHub
のリリースページからリリースビルドを取得できます。MAJOR.MINOR バージョン
のみが一致する必要があることに注意してください。つまり r2-5.7.6 は
5.7.0 から 5.7.8 の間の任意のバージョンでコンパイルされた任意のプラグイン
をロードできます。
+---------+
| radare2 | The radare2 tool, on top of the rest
+---------+
:
+----------+
| io_frida | r2frida io plugin
+----------+
:
+---------+
| frida | Frida host APIs and logic to interact with target
+---------+
:
+-------+
| app | Target process instrumented by Frida with Javascript
+-------+
このプラグインは pancake こと Sergi Alvarez(radare2 の作者)によって NowSecure のために開発されました。
Frida を書いてメンテナンスし、この結合を機能させるために必要なあらゆる ことについて、積極的にバグを修正し技術的な詳細を議論してくれる Ole André に感謝します。Kudos