radius2 是一个使用 radare2 的快速二进制模拟和符号执行框架
radius2 is a fast symbolic execution and taint analysis framework using radare2 that is focused on covering many different architectures and executable formats. It also strives to be easy to use and has a CLI tool that makes some reversing tasks as easy as adding a symbolic value and setting a string to reach or avoid. Reversing challenges can be solved as easily as the example below.
$ radius2 -p ais3 -s flag 184 -X sorry
flag : "ais3{I_tak3_g00d_n0t3s}"
Install radare2 with
git clone https://github.com/radareorg/radare2.git
radare2/sys/install.sh
Install radius2 with cargo install radius2 or include radius2 as a dependency using radius2 = "1.0.26"
radius2 also "supports" MIPS, PowerPC, and Gameboy but they are almost entirely untested. Additionally radius2 supports execution of cBPF and eBPF programs.
radius2 can execute Dalvik bytecode only involving static methods and variables.
Finally there is also a varying amount of support for 6502, 8051, AVR, h8300, PIC, RISCV, SH-4, V810, V850, Xtensa.
Also PCode can be translated to ESIL with r2ghidra with pdgp (currently broken, actually maybe fixed now) so potentially more archs could be supported that way.
…
radius2 can also be installed from crates.io and easily included in packages. radius2 also has a CLI tool that can be installed with cargo install radius2
…
This tool can be used to solve the same r100 crackme as above like
$ radius2 -p tests/r100 -a 0x4006fd -x 0x400790 -s flag 96 -S A0 0x100000 64 -S 0x100000 flag 96
flag : "Code_Talkers"
Or even more quickly with strings using
$ radius2 -p tests/r100 -s stdin 96 -X Incorrect
stdin : "Code_Talkers"
暂无开放 Issues,或尚未同步最近议题。