Skip to content

0xdea/rhabdomancer

Repository files navigation

rhabdomancer

build doc

"The road to exploitable bugs is paved with unexploitable bugs."

-- Mark Dowd

Rhabdomancer is a blazing fast IDA Pro headless plugin that locates calls to potentially insecure API functions in a binary file. Auditors can backtrace from these candidate points to find pathways allowing access to untrusted input.

Features

  • Blazing fast, headless user experience courtesy of IDA Pro 9.x and Binarly's idalib Rust bindings.
  • Support for C/C++ binary targets compiled for any architecture implemented by IDA Pro.
  • Bad API function call locations are printed to stdout and marked in the IDB.
  • Known bad API functions are grouped in tiers of badness to help prioritize the audit work.
    • [BAD 0] High priority - Functions that are generally considered insecure.
    • [BAD 1] Medium priority - Interesting functions that should be checked for insecure use cases.
    • [BAD 2] Low priority - Code paths involving these functions should be carefully checked.
  • The list of known bad API functions can be easily customized by editing conf/rhabdomancer.toml.

Blog posts

See also

Installing

The easiest way to get the latest release is via crates.io:

  1. Download, install, and configure IDA Pro (see https://hex-rays.com/ida-pro).
  2. Install LLVM/Clang (see https://rust-lang.github.io/rust-bindgen/requirements.html).
  3. On Linux/macOS, install as follows:
    export IDADIR=/path/to/ida # if not set, the build script will check common locations
    cargo install rhabdomancer
    On Windows, instead, use the following commands:
    $env:LIBCLANG_PATH="\path\to\clang+llvm\bin"
    $env:PATH="\path\to\ida;$env:PATH"
    $env:IDADIR="\path\to\ida" # if not set, the build script will check common locations
    cargo install rhabdomancer

Compiling

Alternatively, you can build from source:

  1. Download, install, and configure IDA Pro (see https://hex-rays.com/ida-pro).
  2. Install LLVM/Clang (see https://rust-lang.github.io/rust-bindgen/requirements.html).
  3. On Linux/macOS, compile as follows:
    git clone --depth 1 https://github.com/0xdea/rhabdomancer
    cd rhabdomancer
    export IDADIR=/path/to/ida # if not set, the build script will check common locations
    cargo build --release
    On Windows, instead, use the following commands:
    git clone --depth 1 https://github.com/0xdea/rhabdomancer
    cd rhabdomancer
    $env:LIBCLANG_PATH="\path\to\clang+llvm\bin"
    $env:PATH="\path\to\ida;$env:PATH"
    $env:IDADIR="\path\to\ida" # if not set, the build script will check common locations
    cargo build --release

Usage

  1. Make sure IDA Pro is properly configured with a valid license.
  2. Customize the list of known bad API functions in conf/rhabdomancer.toml if needed. You can override the default configuration file location by setting the RHABDOMANCER_CONFIG environment variable.
  3. Run as follows:
    rhabdomancer <binary_file>
    Any existing .i64 IDB file will be updated; otherwise, a new IDB file will be created.
  4. Open the resulting .i64 IDB file with IDA Pro.
  5. Select View > Open subviews > Bookmarks
  6. Enjoy your results conveniently collected into an IDA Pro window.

Note

Rhabdomancer also adds comments at marked call locations.

Compatibility

IDA Pro version Latest compatible release
v9.0.240925 v0.2.4
v9.0.241217 v0.3.5
v9.1.250226 v0.6.2
v9.2.250908 v0.7.6
v9.3.260213 current release

Note

Check the idalib documentation for additional information.

Changelog

TODO

  • Enrich the known bad API function list (see https://github.com/0xdea/semgrep-rules).
  • Consider converting traverse_xrefs to an iterative walk to avoid potential stack overflows and infinite loops.
  • Consider broadening the scope of normalization in normalize_name to account for more cases.
  • Implement a basic ruleset in the style of VulFi and VulnFanatic.

About

Vulnerability research assistant that locates calls to potentially insecure API functions in a binary file.

Topics

Resources

License

Stars

Watchers

Forks

Packages

 
 
 

Contributors