
Cisco ASA 펌웨어를 다루기 위한 스크립트 모음 [pack/unpack 등]
예비 참고: asatools의 일부로 사용할 것을 권장하지만, 단독으로도 사용할 수 있습니다.
asafw는 Cisco ASA 펌웨어를 다루는 스크립트 모음입니다. gdb로 디버깅할 때 필요한 펌웨어를 언패킹할 수 있으며, 다음과 같은 기능을 활성화하기 위해 펌웨어를 언패킹/재패킹할 수도 있습니다:
더 유용한 도구는 unpack_repack_bin.sh와 unpack_repack_qcow2.sh입니다. 각각 asa*.bin 및 asav*.qcow2 이미지 형식을 조작할 수 있습니다. 실제로 rootfs를 재패킹할 때 올바른 권한을 유지하려면 두 도구 모두 root로 실행해야 합니다.
먼저 asafw/env.sh를 환경에 맞게 수정해야 합니다. 이 파일을 통해 모든 스크립트에서 사용하는 도구의 경로와 ASA 환경에 맞는 일부 변수를 정의할 수 있습니다. 유사한 asadbg/env.sh도 있지만 두 프로젝트 모두에 필요한 것은 하나만 사용하면 됩니다. 이를 ~/.bashrc에 추가하는 것을 권장합니다:```
source /path/to/asafw/env.sh
# unpack_repack_bin.sh
`unpack_repack_bin.sh`는 `asa*.bin` 이미지를 언팩/리팩하는 데 사용되며, 이 이미지는
실제 Cisco ASA 하드웨어(예: ASA 5500 및 5500-X 시리즈)에 사용됩니다. 전체
사용법은 다음과 같습니다:```
$ unpack_repack_bin.sh -h
Usage:
./unpack_repack_bin.sh -i <firmware_file> -o <out_dir> [-f -g -G -a -A -m -b -r -u -l <linabin_dir> -d -e -k]
-h, --help This help menu
-i, --input <firmware_file> What firmware bin to operate on
-o, --output <out_dir> Where to write new firmware
-f, --free-space Remove space from .bin to ensure injections fit
-g, --enable-gdb Set gdb to start on boot
-G, --disable-gdb Stop gdb from starting on boot
-a, --enable-aslr Turn on ASLR
-A, --disable-aslr Turn off ASLR
-m, --inject-gdb Inject gdbserver to run
-b, --debug-shell Inject ssh-triggered debug shell
-H, --lina-hook Inject hooks for monitor lina heap (requires -b)
-r, --root root the bin to get a rootshell on boot
-c, --custom custom?
-n, --n-custom custom?
-q, --gns3-fixup gns?
-u, --unpack-only unpack the firmware and nothing else
-l, --linabins <linabin_dir> destination folder to save lina binaries
-d, --delete-extracted delete files extracted during modification
-e, --delete-original-bin delete the original firmware being modified
-k, --keep-rootfs keep the extracted rootfs on disk
-s, --simple-name use a simple name for the output .bin with just appended '-repacked'
Examples:
./unpack_repack_bin.sh -i /home/user/firmware -o /home/user/firmware_repacked --free-space --enable-gdb --inject-gdb
./unpack_repack_bin.sh -i /home/user/firmware/asa961-smp-k8.bin -f -g -m
./unpack_repack_bin.sh -u -i /home/user/firmware -l /home/user/linabins
./unpack_repack_bin.sh -u -i /home/user/firmware/asa924-k8.bin -k
이 두 펌웨어가 있다고 가정해 봅시다:``` ~/fw$ ls asa924-k8.bin asa981-smp-k8.bin
펌웨어만 추출하려는 경우, 예를 들어 [asadbg](https://github.com/nccgroup/asadbg)로 디버그하려면, `-u`를 사용하여 압축만 풀고 `-k`를 사용하여 rootfs만 유지하고 binwalk가 추출한 다른 불필요한 파일을 삭제할 수 있습니다. 참고로 출력 폴더는 입력 폴더와 동일합니다. 여기서는 binwalk에 의존하기 때문입니다:```
~/fw$ unpack_repack_bin.sh -i . -k -u
[unpack_repack_bin] Directory of firmware detected: .
[unpack_repack_bin] extract_one: asa924-k8.bin
DECIMAL HEXADECIMAL DESCRIPTION
--------------------------------------------------------------------------------
75000 0x124F8 SHA256 hash constants, little endian
144510 0x2347E gzip compressed data, maximum compression, from Unix, last modified: 2015-07-15 04:53:23
1501296 0x16E870 gzip compressed data, has original file name: "rootfs.img", from Unix, last modified: 2015-07-15 05:19:52
27168620 0x19E8F6C MySQL ISAM index file Version 4
28192154 0x1AE2D9A Zip archive data, at least v2.0 to extract, name: com/cisco/webvpn/csvrjavaloader64.dll
28773362 0x1B70BF2 Zip archive data, at least v2.0 to extract, name: AliasHandlerWrapper-win64.dll
[unpack_repack_bin] Extracted firmware to /home/user/fw/_asa924-k8.bin.extracted
[unpack_repack_bin] Firmware uses regular rootfs/ dir
[unpack_repack_bin] Extracting /home/user/fw/_asa924-k8.bin.extracted/rootfs/rootfs.img into /home/user/fw/_asa924-k8.bin.extracted/rootfs
[unpack_repack_bin] Keeping rootfs
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/rootfs.img"
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/2347E"
[unpack_repack_bin] Deleting "/home/user/fw/_asa924-k8.bin.extracted/1AE2D9A.zip"
[unpack_repack_bin] extract_one: asa981-smp-k8.bin
DECIMAL HEXADECIMAL DESCRIPTION
--------------------------------------------------------------------------------
75264 0x12600 SHA256 hash constants, little endian
133120 0x20800 Microsoft executable, portable (PE)
149183 0x246BF gzip compressed data, maximum compression, from Unix, last modified: 2017-01-30 19:33:09
3678112 0x381FA0 gzip compressed data, has original file name: "rootfs.img", from Unix, last modified: 2017-05-10 22:42:05
14838307 0xE26A23 MySQL MISAM compressed data file Version 4
87985870 0x53E8ECE MySQL MISAM compressed data file Version 7
96261881 0x5BCD6F9 Zip archive data, at least v2.0 to extract, name: com/cisco/webvpn/csvrjavaloader64.dll
96890193 0x5C66D51 MySQL ISAM compressed data file Version 5
[unpack_repack_bin] Extracted firmware to /home/user/fw/_asa981-smp-k8.bin.extracted
[unpack_repack_bin] Firmware uses regular rootfs/ dir
[unpack_repack_bin] Extracting /home/user/fw/_asa981-smp-k8.bin.extracted/rootfs/rootfs.img into /home/user/fw/_asa981-smp-k8.bin.extracted/rootfs
[unpack_repack_bin] Keeping rootfs
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/rootfs.img"
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/5BCD6F9.zip"
[unpack_repack_bin] Deleting "/home/user/fw/_asa981-smp-k8.bin.extracted/246BF"
아래와 같은 오류가 발생해도 이 경우에는 문제가 되지 않습니다. 왜냐하면 펌웨어를 다시 패킹하지 않을 것이기 때문입니다:``` cpio: lib/udev/devices/kmem: Function mknod failed: Operation not permitted cpio: lib/udev/devices/net/tun: Function mknod failed: Operation not permitted cpio: lib/udev/devices/loop01: Function mknod failed: Operation not permitted cpio: lib/udev/devices/null: Function mknod failed: Operation not permitted cpio: lib/udev/devices/console: Function mknod failed: Operation not permitted cpio: lib/udev/devices/loop00: Function mknod failed: Operation not permitted 134992 blocks
## 부팅 시 gdb 활성화 / 디버그 셸