0Pricing
Reverse Engineering & Binary Analysis Basics · 강의

바이너리 패치 기법

프로그램 동작을 변경하거나 검사를 우회하기 위해 바이너리를 정적으로 수정하고 패치하는 방법을 이해합니다.

바이너리 패치 기법은(는) CoddyKit의 무료 Reverse Engineering & Binary Analysis Basics 강의입니다. 이것은 4개 중 3번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Reverse Engineering & Binary Analysis Basics 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Reverse Engineering & Binary Analysis Basics 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

What is Binary Patching?

Binary patching is the art of modifying a compiled program's machine code directly, without access to its original source code. Think of it as making surgical changes to an executable file.

This technique is crucial in reverse engineering, allowing us to alter program behavior, fix bugs, or even bypass security checks.

Common Patching Uses

Why would you patch a binary?

  • Bug Fixes: Apply urgent fixes without recompiling.
  • Feature Mods: Change how a program works or unlock hidden features.
  • Bypass Checks: Disable license validations or trial limitations.
  • Localization: Change text strings for different languages.

Essential Patching Tools

To patch binaries, you'll primarily use two types of tools:

  • Hex Editors: For direct byte-level modifications. They show the raw hexadecimal and ASCII data.
  • Disassemblers: Like Ghidra or IDA Pro, to understand the assembly code and identify where to patch.

We'll focus on the concepts behind hex editing first.

Using a Hex Editor

A hex editor displays a file's content as hexadecimal (base-16) numbers. Each pair of hex digits represents one byte of data. It also often shows the ASCII representation.

You can navigate by address, search for specific byte sequences or text, and directly modify bytes. Your changes are saved back to the file.

Modify a String (Concept)

Programs often store messages or labels as simple strings of characters. These strings are represented as a sequence of bytes in the binary file.

By finding the byte sequence for a string in a hex editor, you can change it to display a different message when the program runs.

Simple String Program

Consider this simple C program. After compilation, the text "Hello CoddyKit!" will be stored somewhere in its executable as a sequence of ASCII bytes.

You could open the compiled binary in a hex editor, find these bytes, and change them to "Hello Patcher!" for example.

#include <stdio.h>

int main() {
  char message[] = "Hello CoddyKit!";
  printf("%s\n", message);
  return 0;
}

Disabling Code with NOPs

The NOP (No Operation) instruction is like a placeholder. It tells the CPU to do nothing and simply move to the next instruction.

If you want to disable an instruction or a small block of code without causing errors, you can replace its bytes with the NOP instruction's opcode (often 0x90 in x86/x64).

Altering Control Flow

Programs make decisions using conditional jump instructions (e.g., "jump if equal," "jump if not zero"). These determine the program's flow.

By changing a conditional jump to an unconditional jump (e.g., JMP), or vice-versa, you can force a program to always take a certain path, effectively bypassing checks or changing logic.

Bypassing a Check

Imagine a program checks if a variable is zero and exits if it is. The assembly might look like:

TEST EAX, EAX
JE Exit_Func

If we want to prevent the exit, we could change JE (Jump if Equal) to JNE (Jump if Not Equal), or even replace JE Exit_Func with NOPs if Exit_Func is short.

Patching Technique Check

When attempting to disable a specific instruction or a very small block of code in a binary without altering the program's overall structure or causing crashes, which assembly instruction is most commonly used for this purpose?

Binary Patching Recap

In this lesson, we explored binary patching techniques. You learned:

  • What binary patching is and its common applications.
  • The role of hex editors and disassemblers.
  • How to modify data (like strings) and logic (using NOPs and jumps).

Patching requires careful analysis but opens up powerful ways to interact with compiled software!

자주 묻는 질문

“바이너리 패치 기법” 강의는 무료인가요?

네 — “바이너리 패치 기법” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Reverse Engineering & Binary Analysis Basics 강의 전체를 잠금 해제할 수 있습니다. Reverse Engineering & Binary Analysis Basics 강의에는 총 4개의 강의가 포함되어 있습니다.

“바이너리 패치 기법”에서 뭘 배우나요?

프로그램 동작을 변경하거나 검사를 우회하기 위해 바이너리를 정적으로 수정하고 패치하는 방법을 이해합니다. 브라우저에서 직접 실행하는 실습 코드로 Reverse Engineering & Binary Analysis Basics을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

Reverse Engineering & Binary Analysis Basics을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 Reverse Engineering & Binary Analysis Basics은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 3번째 강의입니다.

“바이너리 패치 기법” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 Reverse Engineering & Binary Analysis Basics 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 Reverse Engineering & Binary Analysis Basics 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. IDAPython 및 Ghidra 스크립팅
  2. 데이터 구조 복구 자동화
  3. 바이너리 패치 기법
  4. FLIRT 시그니처와 라이브러리 함수 식별
← Reverse Engineering & Binary Analysis Basics(으)로 돌아가기