0Pricing
Reverse Engineering & Binary Analysis Basics · درس

فحص الذاكرة والسجلات

تدرّبوا على فحص مناطق الذاكرة، وعرض قيم السجلات، وتعديل حالة البرنامج أثناء التنفيذ.

فحص الذاكرة والسجلات درس مجاني في Reverse Engineering & Binary Analysis Basics على CoddyKit. هذا هو الدرس 3 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Reverse Engineering & Binary Analysis Basics، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Reverse Engineering & Binary Analysis Basics 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Debugging's Core: Memory & Registers

When analyzing programs, especially during dynamic analysis, understanding what's happening inside the CPU is key. This means looking at registers and memory.

These are the CPU's direct workspaces, holding data and instructions that are actively being processed.

CPU's Scratchpad: Registers

Registers are tiny, super-fast storage locations directly within the CPU itself. Think of them as the CPU's "scratchpad" where it keeps data it needs immediately.

  • They hold temporary values, addresses, and control information.
  • Accessing data in registers is much faster than accessing RAM.
  • Different architectures (like x86, ARM) have different sets of registers.

Common x86/x64 Registers

While there are many registers, some are crucial for reverse engineering:

  • General-Purpose: RAX/EAX, RBX/EBX, RCX/ECX, RDX/EDX (used for data, function arguments, return values).
  • Stack Pointer: RSP/ESP (points to the top of the stack).
  • Base Pointer: RBP/EBP (points to the base of the current stack frame).
  • Instruction Pointer: RIP/EIP (points to the next instruction to execute).

Viewing Registers in GDB

Let's see how to inspect registers using a debugger like GDB. We'll use a simple C program.

First, compile with debug info (-g): gcc -g -o myprog myprog.c

After compiling and starting GDB (e.g., gdb -q ./myprog), you can set a breakpoint (break main), run (run), and then use info registers.

    #include <stdio.h>

    int main() {
        int a = 10;
        int b = 20;
        int sum = a + b;
        printf("Sum: %d\n", sum);
        return 0;
    }

Program's Workspace: Memory

Memory (RAM) is where your program stores larger amounts of data that aren't actively being processed by the CPU. This includes variables, program code, and other resources.

Every byte in memory has a unique address. When a program runs, it gets its own dedicated "virtual" memory space.

Simplified Memory Layout

A program's memory is typically divided into sections:

  • Text/Code Segment: Contains the executable instructions.
  • Data Segment: Stores global and static variables.
  • Heap: Used for dynamically allocated memory (e.g., with malloc).
  • Stack: Used for local variables, function arguments, and return addresses.

Viewing Memory in GDB

To inspect memory in GDB, we use the x command (examine memory). It has a flexible syntax:

  • x /NFS ADDRESS
  • N: Number of units to display (optional).
  • F: Format (e.g., x for hex, d for decimal, s for string, i for instruction).
  • S: Size (e.g., b for byte, h for halfword (2 bytes), w for word (4 bytes), g for giant (8 bytes)).

Example: Viewing a Stack Variable

Let's use our previous program. Compile it and set a breakpoint before printf. Then, we can find the address of sum and examine its content.

Run this code, then attach GDB (gdb -q ./myprog), set a breakpoint at line 7 (break main.c:7), and run (run).

In GDB: p &sum to get its address. Finally, x /w ADDRESS_OF_SUM to view its 4-byte value.

    #include <stdio.h>

    int main() {
        int a = 10;
        int b = 20;
        int sum = a + b; // Breakpoint here
        printf("Sum: %d\n", sum);
        return 0;
    }

Changing Register Values

A powerful debugging technique is to modify register values on the fly. This can change how a program behaves without altering its code.

In GDB, you can use the set command:

  • set $rax = 0x1234
  • set $rip = *0x400500 (jump to a new address)

This is useful for bypassing checks or redirecting execution flow.

Altering Memory Content

Just like registers, you can also modify memory content while debugging. This allows you to change variable values, strings, or even instructions in memory.

Using GDB's set command:

  • set var_name = new_value (if the variable is in scope)
  • set {int}0x400000 = 123 (change 4 bytes at address 0x400000 to 123)

Be careful, incorrect modifications can crash the program!

Debugger Challenge

You're debugging a program. You want to see the value of a 4-byte integer variable named counter located at memory address 0x7fffffff0000. What GDB command would you use?

Recap: Debugging's Core

Today, we explored how to examine and modify the core components of a running program: registers and memory.

  • Registers are CPU's fast storage, viewed with info registers.
  • Memory holds larger data, viewed with x /NFS ADDRESS.
  • Both can be modified with set to alter program state dynamically.

These skills are fundamental for understanding program execution and reverse engineering!

الأسئلة الشائعة

هل درس «فحص الذاكرة والسجلات» مجاني؟

نعم — نص درس «فحص الذاكرة والسجلات» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Reverse Engineering & Binary Analysis Basics، انتقل إلى CoddyKit PRO. تتضمن دورة Reverse Engineering & Binary Analysis Basics 4 دروس في المجموع.

ماذا ستتعلم في «فحص الذاكرة والسجلات»؟

تدرّبوا على فحص مناطق الذاكرة، وعرض قيم السجلات، وتعديل حالة البرنامج أثناء التنفيذ. تتمرن على Reverse Engineering & Binary Analysis Basics مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Reverse Engineering & Binary Analysis Basics؟

لا تُشترط خبرة سابقة. Reverse Engineering & Binary Analysis Basics على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 3 من أصل 4.

كم من الوقت يستغرق درس «فحص الذاكرة والسجلات»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Reverse Engineering & Binary Analysis Basics هذا؟

نعم. كل درس في Reverse Engineering & Binary Analysis Basics يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. أساسيات مصححات الأخطاء (GDB وWinDbg)
  2. تعيين نقاط التوقف والتنفيذ خطوة بخطوة
  3. فحص الذاكرة والسجلات
  4. تتبّع استدعاءات API والنظام أثناء التشغيل
← العودة إلى Reverse Engineering & Binary Analysis Basics