Practical Foundations of Linux Debugging, Disassembling, Reversing
Practical Foundations of Linux Debugging, Disassembling, Reversing
Training Course
About the Book
This training course is a Linux version of the previous Practical Foundations of Windows Debugging, Disassembly, Reversing book. It also complements Accelerated Linux Core Dump Analysis training course.
Although the book skeleton is the same as its Windows predecessor, the content was revised entirely because of a different operating system, debugger (GDB), toolchain (GCC, assembler, linker), application binary interface, and even an assembly language flavor, AT&T.
The course is useful for:
- Software technical support and escalation engineers
- Software engineers coming from JVM background
- Software testers
- Engineers coming from non-Linux environments, for example, Windows or Mac OS X
- Linux C/C++ software engineers without assembly language background
- Security researchers without assembly language background
- Beginners learning Linux software reverse engineering techniques
This book can also be used as x64 assembly language and Linux debugging supplement for relevant undergraduate level courses.
Table of Contents
Contents 4
Preface 9
About the Author 10
Chapter x64.1: Memory, Registers, and Simple Arithmetic 11
Memory and Registers inside an Idealized Computer 11
Memory and Registers inside Intel 64-bit PC 12
“Arithmetic” Project: Memory Layout and Registers 13
“Arithmetic” Project: A Computer Program 14
“Arithmetic” Project: Assigning Numbers to Memory Locations 15
Assigning Numbers to Registers 17
“Arithmetic” Project: Adding Numbers to Memory Cells 18
Incrementing/Decrementing Numbers in Memory and Registers 21
Multiplying Numbers 24
Chapter x64.2: Code Optimization 27
“Arithmetic” Project: C/C++ Program 27
Downloading GDB 28
GDB Disassembly Output – No Optimization 29
GDB Disassembly Output – Optimization 32
Chapter x64.3: Number Representations 33
Numbers and Their Representations 33
Decimal Representation (Base Ten) 34
Ternary Representation (Base Three) 35
Binary Representation (Base Two) 36
Hexadecimal Representation (Base Sixteen) 37
Why are Hexadecimals used? 38
Chapter x64.4: Pointers 41
A Definition 41
“Pointers” Project: Memory Layout and Registers 42
“Pointers” Project: Calculations 43
Using Pointers to Assign Numbers to Memory Cells 44
Adding Numbers Using Pointers 50
Incrementing Numbers Using Pointers 53
Multiplying Numbers Using Pointers 56
Chapter x64.5: Bytes, Words, Double, and Quad Words 61
Using Hexadecimal Numbers 61
Byte Granularity 62
Bit Granularity 63
Memory Layout 64
Chapter x64.6: Pointers to Memory 67
Pointers Revisited 67
Addressing Types 68
Registers Revisited 73
NULL Pointers 74
Invalid Pointers 75
Variables as Pointers 76
Pointer Initialization 77
Initialized and Uninitialized Data 78
More Pseudo Notation 79
“MemoryPointers” Project: Memory Layout 80
Chapter x64.7: Logical Instructions and RIP 89
Instruction Format 89
Logical Shift Instructions 90
Logical Operations 91
Zeroing Memory or Registers 92
Instruction Pointer 93
Code Section 95
Chapter x64.8: Reconstructing a Program with Pointers 97
Example of Disassembly Output: No Optimization 97
Reconstructing C/C++ Code: Part 1 99
Reconstructing C/C++ Code: Part 2 101
Reconstructing C/C++ Code: Part 3 103
Reconstructing C/C++ Code: C/C++ program 104
Example of Disassembly Output: Optimized Program 105
Chapter x64.9: Memory and Stacks 107
Stack: A Definition 107
Stack Implementation in Memory 108
Things to Remember 110
PUSH Instruction 111
POP instruction 112
Register Review 113
Application Memory Simplified 115
Stack Overflow 116
Jumps 117
Calls 119
Call Stack 121
Exploring Stack in GDB 123
Chapter x64.10: Frame Pointer and Local Variables 127
Stack Usage 127
Register Review 128
Addressing Array Elements 129
Stack Structure (No Function Parameters) 130
Function Prolog 131
Raw Stack (No Local Variables and Function Parameters) 132
Function Epilog 134
“Local Variables” Project 135
Disassembly of Optimized Executable 138
Chapter x64.11: Function Parameters 139
“FunctionParameters” Project 139
Stack Structure 140
Function Prolog and Epilog 142
Project Disassembled Code with Comments 144
Parameter Mismatch Problem 147
Chapter x64.12: More Instructions 149
CPU Flags Register 149
The Fast Way to Fill Memory 150
Testing for 0 152
TEST - Logical Compare 153
CMP – Compare Two Operands 154
TEST or CMP? 155
Conditional Jumps 156
The Structure of Registers 157
Function Return Value 158
Using Byte Registers 159
Chapter x64.13: Function Pointer Parameters 161
“FunctionPointerParameters” Project 161
Commented Disassembly 162
Chapter x64.14: Summary of Code Disassembly Patterns 169
Function Prolog / Epilog 169
LEA (Load Effective Address) 171
Passing Parameters 172
Accessing Parameters and Local Variables 173
Other books by this author
Authors have earned$10,098,681writing, publishing and selling on Leanpub, earning 80% royalties while saving up to 25 million pounds of CO2 and up to 46,000 trees.
Learn more about writing on Leanpub
The Leanpub 45-day 100% Happiness Guarantee
Within 45 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
See full terms
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers), EPUB (for phones and tablets) and MOBI (for Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
Learn more about Leanpub's ebook formats and where to read them
Top Books
C++20
Rainer GrimmC++20 is the next big C++ standard after C++11. As C++11 did it, C++20 changes the way we program modern C++. This change is, in particular, due to the big four of C++20: ranges, coroutines, concepts, and modules.
The book is almost daily updated. These incremental updates ease my interaction with the proofreaders.
A Guide to Artificial Intelligence in Healthcare
Dr. Bertalan MeskoCan we stay human in the age of A.I.? To go even further, can we grow in humanity, can we shape a more humane, more equitable and sustainable healthcare? This e-book aims to prepare healthcare and medical professionals for the era of human-machine collaboration. Read our guide to understanding, anticipating and controlling artificial intelligence.
Atomic Kotlin
Bruce Eckel and Svetlana IsakovaFor both beginning and experienced programmers! From the author of the multi-award-winning Thinking in C++ and Thinking in Java together with a member of the Kotlin language team comes a book that breaks the concepts into small, easy-to-digest "atoms," along with exercises supported by hints and solutions directly inside IntelliJ IDEA!
Introducing EventStorming
Alberto BrandoliniThe deepest tutorial and explanation about EventStorming, straight from the inventor.
C++ Best Practices
Jason TurnerLevel up your C++, get the tools working for you, eliminate common problems, and move on to more exciting things!
Ansible for DevOps
Jeff GeerlingAnsible is a simple, but powerful, server and configuration management tool. Learn to use Ansible effectively, whether you manage one server—or thousands.
Everyday Rails - RSpecによるRailsテスト入門
Junichi Ito (伊藤淳一), AKIMOTO Toshiharu, 魚振江, and Aaron SumnerRSpecを使ってRailsアプリケーションに信頼性の高いテストを書く実践的なアドバイスを提供します。詳細で丁寧な説明は本書のオリジナルコンテンツです。また、説明には実際に動かせるサンプルアプリケーションも使用します。本書は2017年版にアップデートされ、RSpec 3.6やRails 5.1といった新しい環境に対応しています!さあ、自信をもってテストできるようになりましょう!
The Hundred-Page Machine Learning Book
Andriy BurkovEverything you really need to know in Machine Learning in a hundred pages.
Composing Software
Eric ElliottAll software design is composition: the act of breaking complex problems down into smaller problems and composing those solutions. Most developers have a limited understanding of compositional techniques. It's time for that to change.
R Programming for Data Science
Roger D. PengThis book brings the fundamentals of R programming to you, using the same material developed as part of the industry-leading Johns Hopkins Data Science Specialization. The skills taught in this book will lay the foundation for you to begin your journey learning data science. Printed copies of this book are available through Lulu.
Top Bundles
- #1
Software Architecture for Developers: Volumes 1 & 2 - Technical leadership and communication
2 Books
"Software Architecture for Developers" is a practical and pragmatic guide to modern, lightweight software architecture, specifically aimed at developers. You'll learn:The essence of software architecture.Why the software architecture role should include coding, coaching and collaboration.The things that you really need to think about before... - #2
All the Books of The Medical Futurist
6 Books
We put together the most popular books from The Medical Futurist to provide a clear picture about the major trends shaping the future of medicine and healthcare. Digital health technologies, artificial intelligence, the future of 20 medical specialties, big pharma, data privacy, digital health investments and how technology giants such as Amazon... - #3
Cisco CCNA 200-301 Complet
4 Books
Ce lot comprend les quatre volumes du guide préparation à l'examen de certification Cisco CCNA 200-301. - #4
Linux Administration Complet
4 Books
Ce lot comprend les quatre volumes du Guide Linux Administration :Linux Administration, Volume 1, Administration fondamentale : Guide pratique de préparation aux examens de certification LPIC 1, Linux Essentials, RHCSA et LFCS. Administration fondamentale. Introduction à Linux. Le Shell. Traitement du texte. Arborescence de fichiers. Sécurité... - #5
Learn Git, Bash, and Terraform the Hard Way
3 Books
Learn Git, Bash and Terraform using the Hard Way method.These technologies are essential tools in the DevOps armoury. These books walk you through their features and subtleties in a simple, gradual way that reinforces learning rather than baffling you with theory. - #6
PowerShell
3 Books
Buy every PowerShell book from Adam Bertram at a 20% discount! - #7
Software Architecture and Beautiful APIs
2 Books
There is no better way to learn how to design good APIs than to look at many existing examples, complementing the Software Architecture theory on API design. - #8
9 Books-Bundle: Shut Up and Code!
9 Books
"Shut up and code." Laughter in the audience. The hacker had just plugged in his notebook and started sharing his screen to present his super-smart Python script. "Shut up and code" The letters written in a white literal coding font on black background was the hackers' home screen background mantra. At the time, I was a first-year computer... - #9
CCDE Practical Studies (All labs)
3 Books
CCDE lab - #10
Modern C++ by Nicolai Josuttis
2 Books