Skip to content

Instantly share code, notes, and snippets.

@yarjor
yarjor / notes.md
Last active September 26, 2018 10:05
[radare2 notes] #r2 #radare2 #cheatsheet #yetanothercheatsheet #rabin2 #rahash2 #ragg2 #rarun2 #rasm2 #radiff2 #rafind2

Useful commandline arguments

  1. -d: Debug the file/pid given
  2. -A: Analyze at load time (should be pretty much always used in small binaries if no problems are expected)
  3. -q: Quiet mode (process commands and quit)
  4. -w: Write mode enabled for patching
  5. -i: Interpret a r2 script
  6. -n: Bare load - do Not load executable
  7. -c [command; command;]: Execute commands (can be paired with -q)
  8. -r [file]: Use rarun2 config file for debugging
  9. -R [directive]: Specify rarun2 directives for debugging
@yarjor
yarjor / hook_endbr.py
Last active September 24, 2018 15:04
[Hook endbr instructions for angr] #angr #r2pipe #ibtprotect #patch #r2 #radare2
import angr
import r2pipe
ENDBR64 = 'f30f1efa'
ENDBR32 = 'f30f1efb'
def endbr(state):
print "Hooked 'endbr' instruction"
p = angr.Project('./simple')
@yarjor
yarjor / crack.sh
Created September 23, 2018 13:05
[ZIP Password Enumeration] #crack #encrypted #zip
crack_zip() {
for i in $(cat /usr/share/dict/cracklib-small); do
unzip -oP $i $1 &> /dev/null && echo $i && break
done
}
crack_zip encrypted.zip
@yarjor
yarjor / r2_compile_x64.bat
Last active November 2, 2018 13:14
[Radare2 Windows compilation] To be used with #anaconda #r2 #meson #compile #radare2
cd /d D:\git\radare2
git clean -xdf
git pull
activate r2
"%ProgramFiles(x86)%\Microsoft Visual Studio\2017\Community\VC\Auxiliary\Build\vcvars64.bat"
meson build --buildtype release --backend vs2017 --prefix %cd%\dest
msbuild build\radare2.sln /p:Configuration=Release /p:Platform=x64 /m
meson install -C build --no-rebuild
@yarjor
yarjor / rotate.py
Last active September 14, 2018 14:29
[ROR & ROL] #re #reverse-engineering #operations #opcode #rotate
def rol(val, r_bits, max_bits):
return (val << r_bits % max_bits) & (2 ** max_bits - 1) | ((val & (2 ** max_bits - 1)) >> (max_bits - (r_bits % max_bits)))
def ror(val, r_bits, max_bits):
return ((val & (2 ** max_bits - 1)) >> r_bits % max_bits) | (val << (max_bits - (r_bits % max_bits)) & (2 ** max_bits - 1))
@yarjor
yarjor / hexrays.c
Last active January 26, 2024 14:58
[Decompiler Comparison] #radare2 #r2 #ida #idapro #retdec #r2dec #radeco #hexrays
int __cdecl main(int argc, const char **argv, const char **envp)
{
char *src; // [esp+Ch] [ebp-Ch]
puts("\n .:: Megabeets ::.\n");
puts("Show me what you got?");
__isoc99_scanf("%ms", &src);
if ( beet(src) )
puts("Success!\n");
else
@yarjor
yarjor / set_lang.ps1
Created June 7, 2018 17:13
[Set Windows Langauges] #windows #language #controlpanel
$1 = New-WinUserLanguageList en-Us
$1.Add("he")
Set-WinUserLanguageList $1
@yarjor
yarjor / attack.py
Last active May 21, 2018 18:31
[Hash length extension attack (MD5)] #hash #crypto #attack #signature #links
from hashlib import md5
import struct
secret = 'secret'
data = 'data'
fullstring = secret + data
signature = md5(fullstring).hexdigest()
# Known are signature and data!
original_padding = 'I' + \
@yarjor
yarjor / git_cat_all.sh
Created May 19, 2018 12:59
[Print all git objects] #git
find .git/objects/ -type f | cut -c14-15,17-20 | xargs -I {} sh -c "echo '\nFor {}:'; git cat-file -p {}"
@yarjor
yarjor / attacker_machine.sh
Last active May 18, 2018 13:23
[Reverse Shell] #netcat #attack
nc -lt -p 4444