
Radare2와 Frida는 함께하면 더 좋습니다.
frida를 포함하는 radare2용 자체 완결형 플러그인으로, Frida 스크립트를 사용하는 대신(또는 그에 국한되지 않고) r2 명령을 사용하여 로컬 또는 원격 프로세스를 계측할 수 있게 해줍니다.
radare 프로젝트는 리버스 엔지니어링을 위한 완전한 툴체인을 제공하며, 활발하게 유지 관리되고 있고, 잘 관리된 기능을 제공하며 다른 프로그래밍 언어와 도구로 기능을 확장합니다.
Frida는 동적 계측 툴킷으로, 자체 JavaScript를 주입하여 실행 중인 프로세스를 쉽게 검사하고 조작할 수 있으며, 선택적으로 스크립트와 통신할 수도 있습니다.
:. 명령 사용):db API를 사용한 네이티브 브레이크포인트r_fs API를 사용한 원격 파일시스템 접근r2frida를 설치하는 권장 방법은 r2pm을 사용하는 것입니다:
$ r2pm -ci r2frida
컴파일이 필요 없는 바이너리 빌드는 곧 r2pm과 r2env에서 지원될 예정입니다. 그동안 Releases 페이지에서 최신 빌드를 자유롭게 다운로드하세요.
GNU/Debian에서는 다음 패키지를 설치해야 합니다:
$ sudo apt install -y make gcc libzip-dev nodejs npm curl pkg-config git
$ git clone https://github.com/nowsecure/r2frida.git
$ cd r2frida
$ make
$ make user-install
radare2로 변경 (radare2-x.y.z 대신)preconfigure.bat)configure.bat을 실행한 다음 make.bat 실행테스트를 위해서는 r2 frida://0을 사용하세요. frida에서 pid0에 attach하는 것은 로컬에서 실행되는 특수 세션이기 때문입니다. 이제 :? 명령을 실행하여 사용 가능한 명령 목록을 얻을 수 있습니다.
$ r2 'frida://?'
r2 frida://[action]/[link]/[device]/[target]
* action = list | apps | attach | spawn | launch
* link = local | usb | remote host:port
* device = '' | host:port | device-id
* target = pid | appname | process-name | program-in-path | abspath
Local:
* frida://? # show this help
* frida:// # list local processes
* frida://0 # attach to frida-helper (no spawn needed)
* frida:///usr/local/bin/rax2 # abspath to spawn
* frida://rax2 # same as above, considering local/bin is in PATH
* frida://spawn/$(program) # spawn a new process in the current system
* frida://attach/(target) # attach to target PID in current host
USB:
* frida://list/usb// # list processes in the first usb device
* frida://apps/usb// # list apps in the first usb device
* frida://attach/usb//12345 # attach to given pid in the first usb device
* frida://spawn/usb//appname # spawn an app in the first resolved usb device
* frida://launch/usb//appname # spawn+resume an app in the first usb device
Remote:
* frida://attach/remote/10.0.0.3:9999/558 # attach to pid 558 on tcp remote frida-server
Environment: (Use the `%` command to change the environment at runtime)
R2FRIDA_SAFE_IO=0|1 # Workaround a Frida bug on Android/thumb
R2FRIDA_DEBUG=0|1 # Used to debug argument parsing behaviour
R2FRIDA_COMPILER_DISABLE=0|1 # Disable the new frida typescript compiler (`:. foo.ts`)
R2FRIDA_AGENT_SCRIPT=[file] # path to file of the r2frida agent
$ r2 frida://0 # same as frida -p 0, connects to a local session
이름이나 pid로 모든 프로그램에 attach, spawn 또는 launch할 수 있습니다. 다음 줄은 rax2라는 이름의 첫 번째 프로세스에 attach합니다 (이 줄을 테스트하려면 다른 터미널에서 rax2 -를 실행하세요)
$ r2 frida://rax2 # attach to the first process named `rax2`
$ r2 frida://1234 # attach to the given pid
바이너리의 절대 경로를 사용하여 spawn하면 프로세스가 생성됩니다:
$ r2 frida:///bin/ls
[0x00000000]> :dc # continue the execution of the target program
인자와 함께 사용할 수도 있습니다:
$ r2 frida://"/bin/ls -al"
iOS/Android 앱의 USB 디버깅에는 다음 action을 사용하세요. spawn은 launch 또는 attach로 대체할 수 있으며, 프로세스 이름은 bundleid 또는 PID가 될 수 있습니다.
$ r2 frida://spawn/usb/ # enumerate devices
$ r2 frida://spawn/usb// # enumerate apps in the first iOS device
$ r2 frida://spawn/usb//Weather # Run the weather app
다음은 가장 자주 사용되는 명령이므로 반드시 익히고, ?를 붙여 하위 명령 도움말을 확인하세요.
:i # get information of the target (pid, name, home, arch, bits, ..)
.:i* # import the target process details into local r2
:? # show all the available commands
:dm # list maps. Use ':dm|head' and seek to the program base address
:iE # list the exports of the current binary (seek)
:dt fread # trace the 'fread' function
:dt-* # delete all traces
r2frida 플러그인은 에이전트 측에서 실행되며 r2frida.pluginRegister API로 등록됩니다.
더 많은 예제 플러그인 스크립트는 plugins/ 디렉터리를 참조하세요.
[0x00000000]> cat example.js
r2frida.pluginRegister('test', function(name) {
if (name === 'test') {
return function(args) {
console.log('Hello Args From r2frida plugin', args);
return 'Things Happen';
}
}
});
[0x00000000]> :. example.js # load the plugin script
:. 명령은 r2의 . 명령처럼 작동하지만 에이전트 내부에서 실행됩니다.
:. a.js # run script which registers a plugin
:. # list plugins
:.-test # unload a plugin by name
:.. a.js # eternalize script (keeps running after detach)
Termux를 통해 Android에서 r2frida를 네이티브로 설치하고 사용하려는 경우, 일부 심볼 해석 때문에 라이브러리 의존성에 몇 가지 문제가 있습니다. 이를 해결하는 방법은 termux libdir 이전에 시스템 디렉터리를 가리키도록 LD_LIBRARY_PATH 환경 변수를 확장하는 것입니다.
$ LD_LIBRARY_PATH=/system/lib64:$LD_LIBRARY_PATH r2 frida://...
최신 버전의 r2(가급적 최신 릴리스 또는 git)를 사용하고 있는지 확인하세요.
CI는 radare2 6.2.2 릴리스와 git master를 테스트합니다. 호환성 헬퍼는 이전 radare2 ABI에서 Windows 절대 경로 감지와 따옴표로 묶인 스크립트 파일 이름을 보존합니다.
r2 -L | grep frida를 실행하여 플러그인이 로드되었는지 확인하세요. 아무것도 출력되지 않으면 R2_DEBUG=1 환경 변수를 사용하여 디버깅 메시지를 얻어 원인을 찾아보세요.
r2frida 컴파일에 문제가 있으면 r2env를 사용하거나 GitHub 릴리스 페이지에서 릴리스 빌드를 가져올 수 있습니다. MAJOR.MINOR 버전만 일치하면 된다는 점을 명심하세요. 즉, r2-5.7.6은 5.7.0과 5.7.8 사이의 모든 버전에서 컴파일된 플러그인을 로드할 수 있습니다.
+---------+
| radare2 | The radare2 tool, on top of the rest
+---------+
:
+----------+
| io_frida | r2frida io plugin
+----------+
:
+---------+
| frida | Frida host APIs and logic to interact with target
+---------+
:
+-------+
| app | Target process instrumented by Frida with Javascript
+-------+
이 플러그인은 NowSecure를 위해 pancake, 즉 Sergi Alvarez(radare2의 저자)가 개발했습니다.
Frida를 작성하고 유지 관리해 주신 Ole André에게 감사드리며, 이 결합이 작동하도록 하는 데 필요한 모든 것에 대해 버그를 선제적으로 수정하고 기술적 세부 사항을 논의해 주신 친절함에도 감사드립니다. Kudos