Pemeriksaan Memori dan Register
Berlatih memeriksa wilayah memori, melihat nilai register, dan mengubah keadaan program selama eksekusi.
Pemeriksaan Memori dan Register adalah pelajaran Reverse Engineering & Binary Analysis Basics gratis di CoddyKit. Ini adalah pelajaran 3 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Reverse Engineering & Binary Analysis Basics, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Reverse Engineering & Binary Analysis Basics mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Debugging's Core: Memory & Registers
When analyzing programs, especially during dynamic analysis, understanding what's happening inside the CPU is key. This means looking at registers and memory.
These are the CPU's direct workspaces, holding data and instructions that are actively being processed.
CPU's Scratchpad: Registers
Registers are tiny, super-fast storage locations directly within the CPU itself. Think of them as the CPU's "scratchpad" where it keeps data it needs immediately.
- They hold temporary values, addresses, and control information.
- Accessing data in registers is much faster than accessing RAM.
- Different architectures (like x86, ARM) have different sets of registers.
Common x86/x64 Registers
While there are many registers, some are crucial for reverse engineering:
- General-Purpose: RAX/EAX, RBX/EBX, RCX/ECX, RDX/EDX (used for data, function arguments, return values).
- Stack Pointer: RSP/ESP (points to the top of the stack).
- Base Pointer: RBP/EBP (points to the base of the current stack frame).
- Instruction Pointer: RIP/EIP (points to the next instruction to execute).
Viewing Registers in GDB
Let's see how to inspect registers using a debugger like GDB. We'll use a simple C program.
First, compile with debug info (-g): gcc -g -o myprog myprog.c
After compiling and starting GDB (e.g., gdb -q ./myprog), you can set a breakpoint (break main), run (run), and then use info registers.
#include <stdio.h>
int main() {
int a = 10;
int b = 20;
int sum = a + b;
printf("Sum: %d\n", sum);
return 0;
}Program's Workspace: Memory
Memory (RAM) is where your program stores larger amounts of data that aren't actively being processed by the CPU. This includes variables, program code, and other resources.
Every byte in memory has a unique address. When a program runs, it gets its own dedicated "virtual" memory space.
Simplified Memory Layout
A program's memory is typically divided into sections:
- Text/Code Segment: Contains the executable instructions.
- Data Segment: Stores global and static variables.
- Heap: Used for dynamically allocated memory (e.g., with
malloc). - Stack: Used for local variables, function arguments, and return addresses.
Viewing Memory in GDB
To inspect memory in GDB, we use the x command (examine memory). It has a flexible syntax:
x /NFS ADDRESS- N: Number of units to display (optional).
- F: Format (e.g.,
xfor hex,dfor decimal,sfor string,ifor instruction). - S: Size (e.g.,
bfor byte,hfor halfword (2 bytes),wfor word (4 bytes),gfor giant (8 bytes)).
Example: Viewing a Stack Variable
Let's use our previous program. Compile it and set a breakpoint before printf. Then, we can find the address of sum and examine its content.
Run this code, then attach GDB (gdb -q ./myprog), set a breakpoint at line 7 (break main.c:7), and run (run).
In GDB: p &sum to get its address. Finally, x /w ADDRESS_OF_SUM to view its 4-byte value.
#include <stdio.h>
int main() {
int a = 10;
int b = 20;
int sum = a + b; // Breakpoint here
printf("Sum: %d\n", sum);
return 0;
}Changing Register Values
A powerful debugging technique is to modify register values on the fly. This can change how a program behaves without altering its code.
In GDB, you can use the set command:
set $rax = 0x1234set $rip = *0x400500(jump to a new address)
This is useful for bypassing checks or redirecting execution flow.
Altering Memory Content
Just like registers, you can also modify memory content while debugging. This allows you to change variable values, strings, or even instructions in memory.
Using GDB's set command:
set var_name = new_value(if the variable is in scope)set {int}0x400000 = 123(change 4 bytes at address 0x400000 to 123)
Be careful, incorrect modifications can crash the program!
Debugger Challenge
You're debugging a program. You want to see the value of a 4-byte integer variable named counter located at memory address 0x7fffffff0000. What GDB command would you use?
Recap: Debugging's Core
Today, we explored how to examine and modify the core components of a running program: registers and memory.
- Registers are CPU's fast storage, viewed with
info registers. - Memory holds larger data, viewed with
x /NFS ADDRESS. - Both can be modified with
setto alter program state dynamically.
These skills are fundamental for understanding program execution and reverse engineering!
Belajar Assembly dengan tutor AI — gratis
Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.
- Kursus
- 12
- Pelajaran
- 48
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Pemeriksaan Memori dan Register” gratis?
Ya — teks lengkap “Pemeriksaan Memori dan Register” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Reverse Engineering & Binary Analysis Basics, upgrade ke CoddyKit PRO. Kursus Reverse Engineering & Binary Analysis Basics mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Pemeriksaan Memori dan Register”?
Berlatih memeriksa wilayah memori, melihat nilai register, dan mengubah keadaan program selama eksekusi. Kamu berlatih Reverse Engineering & Binary Analysis Basics dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai Reverse Engineering & Binary Analysis Basics?
Tidak diperlukan pengalaman sebelumnya. Reverse Engineering & Binary Analysis Basics di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 3 dari 4.
Berapa lama pelajaran “Pemeriksaan Memori dan Register” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran Reverse Engineering & Binary Analysis Basics ini?
Ya. Setiap pelajaran Reverse Engineering & Binary Analysis Basics menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Dasar-Dasar Debugger (GDB, WinDbg)
- Menetapkan Titik Henti dan Melangkah
- Pemeriksaan Memori dan Register
- Melacak API dan Panggilan Sistem Saat Berjalan