Skip to content

Instantly share code, notes, and snippets.

@yarjor
Last active September 26, 2018 10:05
Show Gist options
  • Select an option

  • Save yarjor/5c01a65800ec591475b7f377bcab2775 to your computer and use it in GitHub Desktop.

Select an option

Save yarjor/5c01a65800ec591475b7f377bcab2775 to your computer and use it in GitHub Desktop.
[radare2 notes] #r2 #radare2 #cheatsheet #yetanothercheatsheet #rabin2 #rahash2 #ragg2 #rarun2 #rasm2 #radiff2 #rafind2

Useful commandline arguments

  1. -d: Debug the file/pid given
  2. -A: Analyze at load time (should be pretty much always used in small binaries if no problems are expected)
  3. -q: Quiet mode (process commands and quit)
  4. -w: Write mode enabled for patching
  5. -i: Interpret a r2 script
  6. -n: Bare load - do Not load executable
  7. -c [command; command;]: Execute commands (can be paired with -q)
  8. -r [file]: Use rarun2 config file for debugging
  9. -R [directive]: Specify rarun2 directives for debugging

Quick Startup

  1. iI - show binary info (same as rabin2 -I)
  2. il - show the libraries used by the binary
  3. ie - show entry points
  4. iM - show mai function
  5. iz(z) - show strings in data section (or whole binary)
  6. aa(a(a)) - Analyse All (extra a for function renaming and another extra a for expermintal analysis)
  7. fs ('flagspace'; f) - list all flag spaces (and print flags) --> fs resources; f - show resources location
  8. afl - show function list
  9. ii - show imports
  10. ![command] - run command from inside r2 (if run with no arguments, prints history - use extra ! to save hist to file)

Analysis Commands

  1. axt [addr] - xrefs to address (eg. axt @@ str.* - prints all references to strings)
  2. pd(f) - print disassemble (function, otherwise can specify num of bytes)
  3. px? - print hexdump
  4. ?v 'val' - show value (e.g ?v sym.imp.puts, can also calculate arithmetic expressions)
  5. uU - undo/redo (in visual mode it's just u/U for seek history, in cli it's us for seek and uw for write)
  6. pa(d) - (dis)assemble
  7. $dec - use retdec decompiler
  8. pdd - use r2dec decompiler
  9. sf. - seek to beginning of current function
  10. iR - resource info
  11. aap - Find functions by prelude instructions
  12. aac - Identify functions by following calls
  13. aae - emulate code to identify new pointer references
  14. aas - use binary header information to find public functions
  15. aat - assume functions are consecutive

Debugging Commands

  1. doo [args] - reopen in debugger mode
  2. db [addr] - add software breakpont
  3. dcu [addr/loc] - continue executing until reaching loc
  4. dcr - continue until ret
  5. dmi - display symbols of selected library (can be used to find out offset in libc for example)
  6. dmm - list modules and addresses (libs)
  7. dbt [?] - display backtrace
  8. ds, dso - step one, step over
  9. x 16 * 5 @ rsp - display stack pxr 16 * 6 @ esp - better way to do it dereferences pointers and such
  10. pd 10 @ rip - show current code
  11. afvd - show values of current args/vars

Metadata Commands

  1. CC? - Commenting (CCa add comment, CC. show comment, CC! edit comment)
  2. Po, Ps - Project commands (very broken if you want to debug)
  3. afn - rename function
  4. afvn/afvt - change name/type of local variable
  5. afvb? - various variable analysis commands

Exploit Development Commands

  1. wopO [value] - Find [value]'s offset into a De Bruijn Pattern (e.g wopO `dr eip` when testing for return pointer overflow)
  2. /R - search for ROP gadgets
  3. ?v sym.imp.func_name - get address of func_name@plt
  4. ?v reloc.func_name - get address of func_name@got
  5. iS - show sections with permissions
  6. dm. -show map name of the current address

Visual Mode

  1. V - entering visual mode
  2. p/P - change between mode, top of the screen shows the command used to generate the view (1. hexdump, 2. code, 3. debugging code) - can be used in graph mode as well
  3. x/X - list cross references to/from the function respectively. Use the numbers to jump to a reference
  4. ; - edit comments
  5. t/f - in graph mode, used to follow true and false branches
  6. dx - d sthg to interpret section as something else (as string, as code, as byte, rename function..) than radare2 thought
  7. VV (or [space] in visual mode) - toggle Visual graph mode
  8. V! - Visual panels mode
  9. o - seek directly to offset, tag, etc.
  10. e - interactive configuration
  11. -/+/0 - zoom in graph mode
  12. O - toggle pseudo-code
  13. |/= - change command in right/upper column in visual mode
  14. A - visual patching (which is awesome :) )
  15. . - seek to instruction pointer
  16. sS - step one/step over

Patching Commands

  1. w1+20 - Increment current byte by 20

Command Families

  1. i - info, show information about binary (symbols, classes, imports, exports...)
  2. P - Project management (Ps for save, Po for open, Pn for notes...)
  3. C - metadata (comments...)
  4. a - analysis, vars...
  5. p - various prints
  6. / - Search
  7. w - patching
  8. d - debugging
  9. o - file operations
  10. t - types, noreturn, signatures, C parser and more

Other Commandline Tools

  1. rabin2 - allows extracting information from binary files, including sections, headers, imports, strings, entrypoints, etc. It can then export the output in several formats. rabin2 is able to understand many file frmats such as ELF, PE, Mach-O, Java CLASS.... -I: prints binary info such as operating system, language, endianness, arch, mitigations (checksec) etc.
  2. rahash2 - block based hashing utility, also calculate entropy (rahash2 -a entropy [file])
  3. ragg2 - compiles tiny relocatable programs for injecting using its own high-level language (which I haven't found any documentation of...). It can also generate De Bruijn patterns (ragg2 -P [size] -r)
  4. rarun2 - launcher for running programs with different environments, arguments, permissions, directories and overrides the default file descriptors (e.g stdin). Can be used with a configuration file (options are in manpage). Useful when commandline is very long or when inputting through stdin.
  5. rasm2 - Assembler/Disassembler (rasm2 -a arch -b 32 [assembly] / -d [code])
  6. radiff2 - binary diff, function diff...
  7. rafind2 - search in binary files, carving...

Tips and Tricks

  1. @@ - foreach iterator (for example - axt @@ str.* runs axt over all matches to regex)
  2. In visual assembly mode, next to each jump and call there's a number inside square brackets, pressing it will take you to the function/address. Same is for control flow graph, only with letters.
  3. ~ - can be used to grep command results
  4. Searches in default occur in current memory map (db.map), to search in all memory maps: e search.in=db.maps
  5. j - can be appended to commands for json result
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment