
r2frida v6.2.0
Radare2 和 Frida 强强联手。
r2frida
描述
radare2 的自包含插件,内置 frida,允许使用 r2 命令(但不限于)Frida 脚本 来对本地或远程进程进行插桩。
radare 项目提供了一套完整的逆向工程工具链, 它被积极维护,提供维护良好的功能, 并通过其他编程语言和工具扩展其特性。
Frida 是一个动态插桩工具包,通过注入你自己的 JavaScript, 可以轻松检查和操纵正在运行的进程,并且可选地与你的脚本进行通信。
特性
- 运行未经修改的 Frida 脚本(使用
:.命令) - 在任意进程中执行 C、Javascript 或 TypeScript 代码片段
- 可以在本地或远程系统中附加、生成或启动进程
- 列出节、符号、导出、协议、类、方法
- 在 agent 内部或从主机搜索内存中的值
- 用简短命令替换方法实现或创建钩子
- 在目标进程中加载库和框架
- 支持 Dalvik、Java、ObjC、Swift 和 C 接口
- 操纵文件描述符和环境变量
- 向进程发送信号、继续执行、断点
- r2frida io 插件同时也是一个文件系统 fs 和 debug 后端
- 使用 r2pipe 自动化 r2 和 frida
- 读写进程内存
- 调用函数、系统调用和原始代码片段
- 通过 usb 或 tcp/ip 连接到 frida-server
- 枚举应用和进程
- 跟踪寄存器、函数参数
- 已在 Linux、Windows、macOS、iOS 和 Android 的 x64、arm32 和 arm64 上测试
- 不要求在主机上安装 frida(无需 frida-tools)
- 使用在 agent 中运行的插件扩展 r2frida 命令
- 更改页面权限、修补代码和数据
- 按名称或地址解析符号并将其作为标志导入 r2
- 从 agent 在主机中运行 r2 命令
- 使用 r2 api 并在远程目标进程内运行 r2 命令。
- 使用
:dbapi 实现原生断点 - 使用
r_fsapi 访问远程文件系统。
安装
安装 r2frida 的推荐方式是通过 r2pm:
$ r2pm -ci r2frida
无需编译的二进制构建将很快在
r2pm 和 r2env 中得到支持。同时,欢迎从
Releases 页面下载最新的构建。
编译
依赖
- radare2
- pkg-config(在 windows 上不需要)
- curl 或 wget
- make、gcc
- npm、nodejs(将很快移除)
在 GNU/Debian 中,你需要安装以下软件包:
$ sudo apt install -y make gcc libzip-dev nodejs npm curl pkg-config git
说明
$ git clone https://github.com/nowsecure/r2frida.git
$ cd r2frida
$ make
$ make user-install
Windows
- 安装 meson 和 Visual Studio
- 将最新的 radare2 发布 zip 解压到 r2frida 根目录
- 将其重命名为
radare2(而不是 radare2-x.y.z) - 使 VS 编译器在 PATH 中可用(
preconfigure.bat) - 运行
configure.bat,然后运行make.bat
用法
用于测试时,使用 r2 frida://0,因为在 frida 中附加到 pid0 是一个特殊的
会话,在本地运行。现在你可以运行 :? 命令来获取
可用命令的列表。
$ r2 'frida://?'
r2 frida://[action]/[link]/[device]/[target]
* action = list | apps | attach | spawn | launch
* link = local | usb | remote host:port
* device = '' | host:port | device-id
* target = pid | appname | process-name | program-in-path | abspath
Local:
* frida://? # show this help
* frida:// # list local processes
* frida://0 # attach to frida-helper (no spawn needed)
* frida:///usr/local/bin/rax2 # abspath to spawn
* frida://rax2 # same as above, considering local/bin is in PATH
* frida://spawn/$(program) # spawn a new process in the current system
* frida://attach/(target) # attach to target PID in current host
USB:
* frida://list/usb// # list processes in the first usb device
* frida://apps/usb// # list apps in the first usb device
* frida://attach/usb//12345 # attach to given pid in the first usb device
* frida://spawn/usb//appname # spawn an app in the first resolved usb device
* frida://launch/usb//appname # spawn+resume an app in the first usb device
Remote:
* frida://attach/remote/10.0.0.3:9999/558 # attach to pid 558 on tcp remote frida-server
Environment: (Use the `%` command to change the environment at runtime)
R2FRIDA_SAFE_IO=0|1 # Workaround a Frida bug on Android/thumb
R2FRIDA_DEBUG=0|1 # Used to debug argument parsing behaviour
R2FRIDA_COMPILER_DISABLE=0|1 # Disable the new frida typescript compiler (`:. foo.ts`)
R2FRIDA_AGENT_SCRIPT=[file] # path to file of the r2frida agent
示例
$ r2 frida://0 # same as frida -p 0, connects to a local session
你可以按名称或 pid 附加、生成或启动任意程序,以下行将附加到第一个名为 rax2 的进程(在另一个终端中运行 rax2 - 来测试此行)
$ r2 frida://rax2 # attach to the first process named `rax2`
$ r2 frida://1234 # attach to the given pid
使用二进制文件的绝对路径来生成将生成该进程:
$ r2 frida:///bin/ls
[0x00000000]> :dc # continue the execution of the target program
也适用于带参数的情况:
$ r2 frida://"/bin/ls -al"
对于 USB 调试 iOS/Android 应用,请使用这些操作。注意 spawn
可以替换为 launch 或 attach,进程名可以是
bundleid 或 PID。
$ r2 frida://spawn/usb/ # enumerate devices
$ r2 frida://spawn/usb// # enumerate apps in the first iOS device
$ r2 frida://spawn/usb//Weather # Run the weather app
命令
这些是最常用的命令,因此你必须学习它们,并在其后加上 ? 以获取子命令帮助。
:i # get information of the target (pid, name, home, arch, bits, ..)
.:i* # import the target process details into local r2
:? # show all the available commands
:dm # list maps. Use ':dm|head' and seek to the program base address
:iE # list the exports of the current binary (seek)
:dt fread # trace the 'fread' function
:dt-* # delete all traces
插件
r2frida 插件在 agent 端运行,并通过 r2frida.pluginRegister API 注册。
查看 plugins/ 目录以获取更多示例插件脚本。
[0x00000000]> cat example.js
r2frida.pluginRegister('test', function(name) {
if (name === 'test') {
return function(args) {
console.log('Hello Args From r2frida plugin', args);
return 'Things Happen';
}
}
});
[0x00000000]> :. example.js # load the plugin script
:. 命令的工作方式类似于 r2 的 . 命令,但在 agent 内部运行。
:. a.js # run script which registers a plugin
:. # list plugins
:.-test # unload a plugin by name
:.. a.js # eternalize script (keeps running after detach)
Termux
如果你愿意通过 Termux 在 Android 上原生安装和使用 r2frida,由于某些符号解析问题,库依赖方面存在一些注意事项。使其工作的方法是在 termux libdir 之前扩展 LD_LIBRARY_PATH 环境变量以指向系统目录。
$ LD_LIBRARY_PATH=/system/lib64:$LD_LIBRARY_PATH r2 frida://...
故障排除
确保你使用的是现代版本的 r2(最好是最后一个发布版或 git)。
CI 测试 radare2 6.2.2 发布版和 git master。兼容性辅助程序在较旧的 radare2 ABI 上保留 Windows 绝对路径检测和带引号的脚本文件名。
运行 r2 -L | grep frida 来验证插件是否已加载,如果没有打印任何内容,请使用 R2_DEBUG=1 环境变量获取一些调试消息以找出原因。
如果你在编译 r2frida 时遇到问题,可以使用 r2env 或从 GitHub releases 页面获取发布构建,请记住只有 MAJOR.MINOR 版本必须匹配,即 r2-5.7.6 可以加载在 5.7.0 到 5.7.8 之间任何版本上编译的任何插件。
设计
+---------+
| radare2 | The radare2 tool, on top of the rest
+---------+
:
+----------+
| io_frida | r2frida io plugin
+----------+
:
+---------+
| frida | Frida host APIs and logic to interact with target
+---------+
:
+-------+
| app | Target process instrumented by Frida with Javascript
+-------+
致谢
此插件由 pancake 又名 Sergi Alvarez(radare2 的作者) 为 NowSecure 开发。
我要感谢 Ole André 编写和维护 Frida,以及 如此友善地主动修复错误并讨论使这一结合得以工作所需的任何技术细节。Kudos