hacktricks/reversing/reversing-tools/README.md

132 lines
7.8 KiB
Markdown
Raw Normal View History

2022-04-28 16:01:33 +00:00
<details>
2024-01-09 11:44:36 +00:00
<summary><strong>Learn AWS hacking from zero to hero with</strong> <a href="https://training.hacktricks.xyz/courses/arte"><strong>htARTE (HackTricks AWS Red Team Expert)</strong></a><strong>!</strong></summary>
2022-04-28 16:01:33 +00:00
2024-01-09 11:44:36 +00:00
Other ways to support HackTricks:
2022-04-28 16:01:33 +00:00
2024-01-09 11:44:36 +00:00
* If you want to see your **company advertised in HackTricks** or **download HackTricks in PDF** Check the [**SUBSCRIPTION PLANS**](https://github.com/sponsors/carlospolop)!
* Get the [**official PEASS & HackTricks swag**](https://peass.creator-spring.com)
* Discover [**The PEASS Family**](https://opensea.io/collection/the-peass-family), our collection of exclusive [**NFTs**](https://opensea.io/collection/the-peass-family)
2024-02-09 00:38:08 +00:00
* **Join the** 💬 [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** 🐦 [**@carlospolopm**](https://twitter.com/hacktricks_live)**.**
2024-01-09 11:44:36 +00:00
* **Share your hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
2022-04-28 16:01:33 +00:00
</details>
2024-02-08 21:36:35 +00:00
# Wasm Decompilation and Wat Compilation Guide
2022-04-28 16:01:33 +00:00
2024-02-08 21:36:35 +00:00
In the realm of **WebAssembly**, tools for **decompiling** and **compiling** are essential for developers. This guide introduces some online resources and software for handling **Wasm (WebAssembly binary)** and **Wat (WebAssembly text)** files.
2024-02-08 21:36:35 +00:00
## Online Tools
2021-03-14 09:45:16 +00:00
2024-02-08 21:36:35 +00:00
- To **decompile** Wasm to Wat, the tool available at [Wabt's wasm2wat demo](https://webassembly.github.io/wabt/demo/wasm2wat/index.html) comes in handy.
- For **compiling** Wat back to Wasm, [Wabt's wat2wasm demo](https://webassembly.github.io/wabt/demo/wat2wasm/) serves the purpose.
- Another decompilation option can be found at [web-wasmdec](https://wwwg.github.io/web-wasmdec/).
2021-03-14 09:45:16 +00:00
2024-02-08 21:36:35 +00:00
## Software Solutions
2021-03-14 09:45:16 +00:00
2024-02-08 21:36:35 +00:00
- For a more robust solution, [JEB by PNF Software](https://www.pnfsoftware.com/jeb/demo) offers extensive features.
- The open-source project [wasmdec](https://github.com/wwwg/wasmdec) is also available for decompilation tasks.
2024-02-08 21:36:35 +00:00
# .Net Decompilation Resources
2024-02-08 21:36:35 +00:00
Decompiling .Net assemblies can be accomplished with tools such as:
2024-02-08 21:36:35 +00:00
- [ILSpy](https://github.com/icsharpcode/ILSpy), which also offers a [plugin for Visual Studio Code](https://github.com/icsharpcode/ilspy-vscode), allowing cross-platform usage.
- For tasks involving **decompilation**, **modification**, and **recompilation**, [dnSpy](https://github.com/0xd4d/dnSpy/releases) is highly recommended. **Right-clicking** a method and choosing **Modify Method** enables code changes.
- [JetBrains' dotPeek](https://www.jetbrains.com/es-es/decompiler/) is another alternative for decompiling .Net assemblies.
2024-02-08 21:36:35 +00:00
## Enhancing Debugging and Logging with DNSpy
2024-02-08 21:36:35 +00:00
### DNSpy Logging
To log information to a file using DNSpy, incorporate the following .Net code snippet:
%%%cpp
using System.IO;
path = "C:\\inetpub\\temp\\MyTest2.txt";
File.AppendAllText(path, "Password: " + password + "\n");
2024-02-08 21:36:35 +00:00
%%%
2024-02-08 21:36:35 +00:00
### DNSpy Debugging
For effective debugging with DNSpy, a sequence of steps is recommended to adjust **Assembly attributes** for debugging, ensuring that optimizations that could hinder debugging are disabled. This process includes changing the `DebuggableAttribute` settings, recompiling the assembly, and saving the changes.
2024-02-08 21:36:35 +00:00
Moreover, to debug a .Net application run by **IIS**, executing `iisreset /noforce` restarts IIS. To attach DNSpy to the IIS process for debugging, the guide instructs on selecting the **w3wp.exe** process within DNSpy and starting the debugging session.
2024-02-08 21:36:35 +00:00
For a comprehensive view of loaded modules during debugging, accessing the **Modules** window in DNSpy is advised, followed by opening all modules and sorting assemblies for easier navigation and debugging.
2024-02-08 21:36:35 +00:00
This guide encapsulates the essence of WebAssembly and .Net decompilation, offering a pathway for developers to navigate these tasks with ease.
2024-02-08 21:36:35 +00:00
## **Java Decompiler**
To decompile Java bytecode, these tools can be very helpful:
- [jadx](https://github.com/skylot/jadx)
- [JD-GUI](https://github.com/java-decompiler/jd-gui/releases)
2024-02-08 21:36:35 +00:00
## **Debugging DLLs**
### Using IDA
- **Rundll32** is loaded from specific paths for 64-bit and 32-bit versions.
- **Windbg** is selected as the debugger with the option to suspend on library load/unload enabled.
- Execution parameters include the DLL path and function name. This setup halts execution upon each DLL's loading.
2024-02-08 21:36:35 +00:00
### Using x64dbg/x32dbg
- Similar to IDA, **rundll32** is loaded with command line modifications to specify the DLL and function.
- Settings are adjusted to break on DLL entry, allowing breakpoint setting at the desired DLL entry point.
2024-02-08 21:36:35 +00:00
### Images
- Execution stopping points and configurations are illustrated through screenshots.
2024-02-08 21:36:35 +00:00
## **ARM & MIPS**
- For emulation, [arm_now](https://github.com/nongiach/arm_now) is a useful resource.
2024-02-08 21:36:35 +00:00
## **Shellcodes**
### Debugging Techniques
- **Blobrunner** and **jmp2it** are tools for allocating shellcodes in memory and debugging them with Ida or x64dbg.
- Blobrunner [releases](https://github.com/OALabs/BlobRunner/releases/tag/v0.0.5)
- jmp2it [compiled version](https://github.com/adamkramer/jmp2it/releases/)
- **Cutter** offers GUI-based shellcode emulation and inspection, highlighting differences in shellcode handling as a file versus direct shellcode.
2024-02-08 21:36:35 +00:00
### Deobfuscation and Analysis
- **scdbg** provides insights into shellcode functions and deobfuscation capabilities.
%%%bash
scdbg.exe -f shellcode # Basic info
scdbg.exe -f shellcode -r # Analysis report
scdbg.exe -f shellcode -i -r # Interactive hooks
scdbg.exe -f shellcode -d # Dump decoded shellcode
scdbg.exe -f shellcode /findsc # Find start offset
scdbg.exe -f shellcode /foff 0x0000004D # Execute from offset
%%%
2024-02-08 21:36:35 +00:00
- **CyberChef** for disassembling shellcode: [CyberChef recipe](https://gchq.github.io/CyberChef/#recipe=To_Hex%28'Space',0%29Disassemble_x86%28'32','Full%20x86%20architecture',16,0,true,true%29)
2024-02-08 21:36:35 +00:00
## **Movfuscator**
- An obfuscator that replaces all instructions with `mov`.
- Useful resources include a [YouTube explanation](https://www.youtube.com/watch?v=2VF_wPkiBJY) and [PDF slides](https://github.com/xoreaxeaxeax/movfuscator/blob/master/slides/domas_2015_the_movfuscator.pdf).
- **demovfuscator** might reverse movfuscator's obfuscation, requiring dependencies like `libcapstone-dev` and `libz3-dev`, and installing [keystone](https://github.com/keystone-engine/keystone/blob/master/docs/COMPILE-NIX.md).
2024-02-08 21:36:35 +00:00
## **Delphi**
- For Delphi binaries, [IDR](https://github.com/crypto2011/IDR) is recommended.
2020-12-08 17:57:54 +00:00
2022-05-01 12:49:36 +00:00
# Courses
* [https://github.com/0xZ0F/Z0FCourse\_ReverseEngineering](https://github.com/0xZ0F/Z0FCourse_ReverseEngineering)
* [https://github.com/malrev/ABD](https://github.com/malrev/ABD) \(Binary deobfuscation\)
2022-04-28 16:01:33 +00:00
<details>
2024-01-09 11:44:36 +00:00
<summary><strong>Learn AWS hacking from zero to hero with</strong> <a href="https://training.hacktricks.xyz/courses/arte"><strong>htARTE (HackTricks AWS Red Team Expert)</strong></a><strong>!</strong></summary>
2022-04-28 16:01:33 +00:00
2024-01-09 11:44:36 +00:00
Other ways to support HackTricks:
2022-04-28 16:01:33 +00:00
2024-01-09 11:44:36 +00:00
* If you want to see your **company advertised in HackTricks** or **download HackTricks in PDF** Check the [**SUBSCRIPTION PLANS**](https://github.com/sponsors/carlospolop)!
* Get the [**official PEASS & HackTricks swag**](https://peass.creator-spring.com)
* Discover [**The PEASS Family**](https://opensea.io/collection/the-peass-family), our collection of exclusive [**NFTs**](https://opensea.io/collection/the-peass-family)
2024-02-09 00:38:08 +00:00
* **Join the** 💬 [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** 🐦 [**@carlospolopm**](https://twitter.com/hacktricks_live)**.**
2024-01-09 11:44:36 +00:00
* **Share your hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
2022-04-28 16:01:33 +00:00
</details>