Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
rhabdomancer — Vulnerability research assistant that locates calls to potentially insecure API functions in a binary file. | Kitploit
도구/GitHubGitHub/0xdea/rhabdomancer
Static AnalysisVulnerability AnalysisReverse EngineeringBinary Analysis
GitHub0xdea/rhabdomancer

rhabdomancer

Vulnerability research assistant that locates calls to potentially insecure API functions in a binary file.

저장소 보기
13115173일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
웹사이트
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

rhabdomancer

build doc

"The road to exploitable bugs is paved with unexploitable bugs."

-- Mark Dowd

Rhabdomancer is a blazing fast IDA headless plugin that locates calls to potentially insecure API functions in a binary file. Auditors can backtrace from these candidate points to find pathways allowing access to untrusted input.

Features

  • Blazing fast, headless user experience courtesy of IDA 9.x and idalib-rs Rust bindings.
  • Support for C/C++ binary targets compiled for any architecture implemented by IDA.
  • Bad API function call locations are printed to stdout and marked in the IDB.
  • Known bad API functions are grouped in tiers of badness to help prioritize the audit work.
    • [BAD 0] High priority - Functions that are generally considered insecure.
    • [BAD 1] Medium priority - Interesting functions that should be checked for insecure use cases.
    • [BAD 2] Low priority - Code paths involving these functions should be carefully checked.
  • The list of known bad API functions can be easily customized by editing conf/rhabdomancer.toml.

Articles

  • https://hex-rays.com/blog/streamlining-vulnerability-research-idalib-rust-bindings
  • https://hnsecurity.it/blog/streamlining-vulnerability-research-with-ida-pro-and-rust

See also

  • https://github.com/0xdea/ghidra-scripts/blob/main/Rhabdomancer.java
  • https://docs.hex-rays.com/release-notes/9_0#headless-processing-with-idalib
  • https://github.com/idalib-rs/idalib
  • https://books.google.it/books/about/The_Art_of_Software_Security_Assessment.html

Installing

The easiest way to get the latest release is via crates.io:

  1. Download, install, and configure IDA (see https://hex-rays.com/ida-pro).
  2. Install LLVM/Clang (see https://rust-lang.github.io/rust-bindgen/requirements.html).
  3. On Linux/macOS, install as follows:
    export IDADIR=/path/to/ida # if not set, the build script will check common locations
    cargo install rhabdomancer --locked
    
    On Windows, instead, use the following commands:
    $env:LIBCLANG_PATH="\path\to\clang+llvm\bin"
    $env:PATH="\path\to\ida;$env:PATH"
    $env:IDADIR="\path\to\ida" # if not set, the build script will check common locations
    cargo install rhabdomancer --locked
    

Compiling

Alternatively, you can build from source:

  1. Download, install, and configure IDA (see https://hex-rays.com/ida-pro).
  2. Install LLVM/Clang (see https://rust-lang.github.io/rust-bindgen/requirements.html).
  3. On Linux/macOS, compile as follows:
    git clone --depth 1 https://github.com/0xdea/rhabdomancer
    cd rhabdomancer
    export IDADIR=/path/to/ida # if not set, the build script will check common locations
    cargo build --release --locked
    
    On Windows, instead, use the following commands:
    git clone --depth 1 https://github.com/0xdea/rhabdomancer
    cd rhabdomancer
    $env:LIBCLANG_PATH="\path\to\clang+llvm\bin"
    $env:PATH="\path\to\ida;$env:PATH"
    $env:IDADIR="\path\to\ida" # if not set, the build script will check common locations
    cargo build --release --locked
    

Usage

  1. Make sure IDA is properly configured with a valid license.
  2. Optionally customize the list of known bad API functions in conf/rhabdomancer.toml. You can override the default configuration file location by setting the RHABDOMANCER_CONFIG environment variable.
  3. Make sure the IDADIR environment variable is set if your IDA installation is in a non-standard location.
  4. Run as follows:
    rhabdomancer <binary_file>
    
    Any existing .i64 IDB file will be updated; otherwise, a new IDB file will be created.
  5. Open the resulting .i64 IDB file with IDA.
  6. Select View > Open subviews > Bookmarks
  7. Enjoy your results conveniently collected into an IDA window.

[!NOTE] Rhabdomancer also adds comments at marked call locations.

Compatibility

Only the latest IDA release is officially supported, but older versions may work as well. The following table summarizes the latest compatible release for each IDA version:

IDA versionLatest compatible release
v9.0.240925v0.2.4
v9.0.241217v0.3.5
v9.1.250226v0.6.2
v9.2.250908v0.7.6
v9.3.260213v0.8.1
v9.3.260327v0.9.0
v9.3.260421v0.9.3
v9.4.260714current release
v9.4.260915current release

[!NOTE] Check the idalib-rs documentation for additional information.

Credits

This project's development has been supported by the following organizations:

  • HN Security
  • Hex-Rays via their Contributor Program

Changelog

  • CHANGELOG.md

TODO

  • Further enrich the known bad API function list (see https://github.com/0xdea/semgrep-rules).
  • Consider broadening the scope of normalization in normalize_name to account for more cases.
  • Implement serialized output to facilitate automated parsing and analysis.
  • Implement a basic ruleset in the style of VulFi and VulnFanatic.
도구 다운로드