{"id":19,"date":"2022-07-17T21:56:32","date_gmt":"2022-07-17T21:56:32","guid":{"rendered":"http:\/\/moveax.me\/?p=19"},"modified":"2022-07-18T00:18:55","modified_gmt":"2022-07-18T00:18:55","slug":"radare2-visual-mode","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/radare2-visual-mode\/","title":{"rendered":"Radare2\u2019s Visual Mode"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">So far, I\u2019ve been using strictly the command line prompt of radare2. I do believe this was the perfect choice to start learning how it works, to learn the basics so I can have a strong base of knowledge in this tool.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But let\u2019s be honest, as you evolve, it become tedious use just the command line and I started to feel this in Crackme0x03 when I needed to debug the shift function. An option, was to put a breakpoint in every instruction, type dc, check the registers\/variables, type dc, check the registers\/variables, typ\u2026 you get the point.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another alternative was to set the first breakpoint and then use \u201cds\u201d which spares us the effort of setting a lot of breakpoints. But we still need to use \u201cafvd\u201d and \u201cdr\u201d every time we make a step.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>We can do better that this!<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">While I was reading&nbsp;<a href=\"https:\/\/radare.gitbooks.io\/radare2book\/content\/\">radare\u2019s manual<\/a>, I discovered the Visual mode. I strongly advise you to take a look in this manual. I\u2019ve been learning to use it, practicing in every crackme and now, I think I\u2019m ready to make a short introduction using crackme0x03.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, to begin using Radare2\u2019s Visual Mode, you can start radare like we did before, using the&nbsp;<em>A<\/em>,&nbsp;<em>d<\/em>&nbsp;or even&nbsp;<em>w flag<\/em>, it doesn\u2019t matter at this point. Then type \u201cV\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first Print Mode (or panel) you see is the HexDump panel and there are 6 more of this panels:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Disassembly panel<\/li><li>Debugger panel<\/li><li>Hexadecimal words dump panel<\/li><li>Hex-less hexdump panel<\/li><li>Op analysis color map panel<\/li><li>Annotated hexdump panel<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">You can cycle through this panels using \u201cp\u201d. In my examples, I\u2019ll probably use the Debugger panel just because I can see the value of all registers in real time.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/01\/Visual-1.png\" alt=\"Visual Mode of radare2\" class=\"wp-image-237\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In the image presented above, notice the \u201ceip\u201d right next to the highlighted address. EIP stands for \u201cExtended Instruction Pointer\u201d which stores in the stack the address of the next instruction to be executed. To start executing instructions type \u201cs\u201d, which will make a single step and you\u2019ll see the EIP register moving down. It basically means that you executed the next instruction. If you type \u201cS\u201d instead, you\u2019ll step over an instruction. But let me give you an example.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At this point, the next instruction to be executed it\u2019s a call to a function. If you type \u201cs\u201d you\u2019ll be redirected to shift function and you\u2019ll be presented with the instructions of that function. On the other hand, if you type \u201cS<em>\u201c<\/em>&nbsp;you\u2019ll step over this call and go right to the jump instruction at 0x08048488. You won\u2019t go inside shift function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From now on, I\u2019ll use both modes, Visual and command prompt<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Key Functions<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some other useful key bindings, but you use&nbsp;\u201c?\u201d to check the available options.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of s\/S you can use F7\/F8, as they are means to the same end.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you feel the need of using the command prompt of radare2 during Visual Mode, type \u201c:\u201d and a little prompt will appear at the end of the screen. There, you can type all the commands learned so far.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To assemble code, you can use \u201ca\u201d which will show you a prompt ready to accept opcodes or you can use \u201cA\u201d to insert instructions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can use the arrow keys to navigate through the code and to set a breakpoint just hit F2.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To quit, just press \u201cq\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other commands used in the video below can be found at&nbsp;<a href=\"radare-basics\/\">Radare Basics<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>So far, I\u2019ve been using strictly the command line prompt of radare2. I do believe this was the perfect choice to start learning how it&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/radare2-visual-mode\/\">Continue reading<span class=\"screen-reader-text\">Radare2\u2019s Visual Mode<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-19","post","type-post","status-publish","format-standard","hentry","category-radare2","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/19","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=19"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/19\/revisions"}],"predecessor-version":[{"id":21,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/19\/revisions\/21"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=19"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=19"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=19"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}