{"id":6,"date":"2022-07-17T21:42:39","date_gmt":"2022-07-17T21:42:39","guid":{"rendered":"http:\/\/moveax.me\/?p=6"},"modified":"2022-07-17T22:15:24","modified_gmt":"2022-07-17T22:15:24","slug":"radare-basics%ef%bf%bc","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/radare-basics%ef%bf%bc\/","title":{"rendered":"Radare Basics"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">After some googling and testing, I have compiled a list of commands that enabled me to look deeply into the code and get useful information. I intend to update this list while I\u2019m learning new commands.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>r2 -Ad .\/crackme0x01\n<\/strong>Opens r2 in debug mode with the <em>Analyze all<\/em> flag active\nNote: If I hadn't passed <em>A<\/em> flag, <em>aa <\/em>would be the first command to execute after running Radare<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">First of all, let me state that it\u2019s always possible to use ? to list all commands available as well as use it at the end of every command to get more information about it.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>?\n<\/strong>Used alone, lists all the commands available\nUsed at the end of a command, shows a brief description about it (eg. afl?)<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">So, to start exploring an executable is always good idea list all the present functions, using afll. One can also use just afl which is not as verbose as afll.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>afll<\/strong>\nLists all functions and their location in memory<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s possible to use afvd for variables.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>afvd<\/strong>\nShows the content of all local\/args variables<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">When the time to set breakpoints come, one can use db command.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>db 0x12345678<\/strong>\nSets a breakpoint at address 0x12345678. It's possible to set more than one breakpoint<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">To run the executable and stop at a breakpoint, I can use dc.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>dc<\/strong>\nRuns the program until it hits a breakpoint<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the program is stopped at a breakpoint I can use dr to display the registers.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>dr<\/strong>\nShows the content of all registers. Use dr &lt;register&gt; for a specific register<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You can also use the \u201ctelescoping\u201d method.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>drr\n<\/strong>Shows the content of all registers and the registers references.<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">To execute a single instruction, use ds.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>ds<\/strong>\nSteps a single instruction<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If I was looking for the \u201clow hanging fruit\u201d iz would be a good command to start.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>iz<\/strong>\nShows the strings present in the data section\nOne can use izz to see the strings for the entire binary<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">To explore the code of the function that I sought to, I can use pdf which will display the code of that function. You can also use pdf @ sym.main (which means something like \u201cshow me the main function without seek to it\u201d) .<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>pdf\n<\/strong>\"Print Disassembling Function\"<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s also possible to print the content of a memory cell with pf.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>pf<\/strong>\nPrints formatted data. Use pf?? to see available formats and pf??? for examples<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">To see raw data from some memory address, use px.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>px 3 @0x08080808\n<\/strong>Prints hexadecimal dump (3 bytes) from 0x08080808 address.<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Now that the location of all functions is known, I can seek to one of those functions with the s command. It\u2019s always a very good habit to type ? after a command to see all the options available.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>s sym.main\n<\/strong>Seeks to function sym.main. Address in prompt will change<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">To edit the program an write instructions, use wa.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>wa nop @ 0x08080808<\/strong>\nWrites a nop instruction at 0x08080808 address.\nNote: The program must be started with w flag<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of instructions, it\u2019s possible to write opcodes.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>wx 90 @ 0x08080808<\/strong>\nWrites the opcode 90 (nop) at 0x08080808 address.<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The ? command is an interesting feature, I must confess. Apart of all the use described above, one can use it also to convert a value to another base.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>? 0x10<\/strong>\nConverts the number 0x10 to the most common bases<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">With all the previous commands we can perform some basic debugging. Somewhere in time I\u2019ll write a similar post with an introduction for the Visual mode that I ended up discovering. In that mode, one can do all the tasks described previously with much less pain.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After some googling and testing, I have compiled a list of commands that enabled me to look deeply into the code and get useful information.&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/radare-basics%ef%bf%bc\/\">Continue reading<span class=\"screen-reader-text\">Radare Basics<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,1],"tags":[],"class_list":["post-6","post","type-post","status-publish","format-standard","hentry","category-radare2","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/6","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=6"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/6\/revisions"}],"predecessor-version":[{"id":10,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/6\/revisions\/10"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=6"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=6"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=6"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}