0Pricing
Reverse Engineering & Binary Analysis Basics · 강의

함수 및 데이터 식별

디스어셈블된 바이너리에서 중요한 함수, 문자열 및 기타 데이터를 찾는 기법을 배웁니다.

함수 및 데이터 식별은(는) CoddyKit의 무료 Reverse Engineering & Binary Analysis Basics 강의입니다. 이것은 4개 중 2번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Reverse Engineering & Binary Analysis Basics 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Reverse Engineering & Binary Analysis Basics 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

Spotting Key Parts of a Binary

Welcome! In reverse engineering, our goal is to understand how a program works without its source code. A critical first step is to identify its core components: functions and data.

These elements are like the building blocks and raw materials of any software. Learning to spot them quickly will significantly speed up your analysis.

Strings: Your First Clues

Strings are often the easiest and most valuable clues in a binary. They can reveal a program's purpose, error messages, user prompts, file paths, network addresses, or API calls.

  • Error messages: "Error: File not found"
  • URLs/Paths: "https://malicious.com/update", "C:\Windows\System32\config.dat"
  • User Prompts: "Enter password:"

Finding them is usually the first step for any analyst.

Locating Strings in Disassemblers

Most disassemblers, like Ghidra or IDA Pro, have a dedicated feature to list all identified strings within a binary. This saves you from manually scanning through raw bytes.

When you find an interesting string, you can usually cross-reference it to see where in the code it's being used. This immediately points you to relevant functions.

Functions: Program's Building Blocks

A function (or subroutine) is a self-contained block of code designed to perform a specific task. Programs are built from many functions calling each other.

Identifying functions helps you break down a complex program into smaller, manageable pieces, making it easier to understand its overall logic and flow.

Recognizing Function Entry Points

Functions often start with a specific sequence of instructions called a prologue. This setup typically prepares the stack for local variables and saves the previous stack frame.

A common x86 prologue looks like this:

push ebp
mov ebp, esp

This sequence pushes the old base pointer onto the stack and sets the current stack pointer as the new base pointer.

Function Exits: Epilogues

Just as functions have entry points, they also have exit points, marked by an epilogue. The epilogue restores the stack to its state before the function call and returns control to the caller.

A typical x86 epilogue might be:

mov esp, ebp
pop ebp
ret

This restores the stack pointer, pops the old base pointer, and returns from the function.

Spotting Common Library Functions

Most programs use functions from system libraries (e.g., for printing to screen, file I/O, network communication). Disassemblers are often smart enough to identify these for you.

They do this by looking at imported symbols (like the Import Address Table in Windows PE files or Procedure Linkage Table in Linux ELF files) or by matching known function signatures.

Where Data Resides: Data Sections

Beyond code, binaries contain various data sections. Understanding these helps you locate global variables, constants, and other program-wide information:

  • .data: Initialized global and static variables.
  • .bss: Uninitialized global and static variables (zeroed out at runtime).
  • .rdata: Read-only data, such as strings and constants.

These sections are usually clearly labeled in disassemblers.

Global vs. Local Variables

Distinguishing between global and local variables is key. Global variables are accessible throughout the program and are usually stored in .data or .bss sections.

Local variables, on the other hand, are created on the stack when a function is called and are only accessible within that function. They are typically referenced relative to the stack frame pointer (e.g., [ebp-0x4]).

Quick Check: Data Clues

You are analyzing a binary and see a reference to an address within the .rdata section. What kind of data is most likely stored at this address?

Key Takeaways

You've learned fundamental techniques for static analysis!

  • Strings offer immediate insights into program functionality.
  • Function prologues and epilogues help define code boundaries.
  • Recognizing library functions speeds up analysis.
  • Understanding data sections (.data, .bss, .rdata) helps locate global variables and constants.

These skills are essential for navigating and understanding disassembled binaries.

자주 묻는 질문

“함수 및 데이터 식별” 강의는 무료인가요?

네 — “함수 및 데이터 식별” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Reverse Engineering & Binary Analysis Basics 강의 전체를 잠금 해제할 수 있습니다. Reverse Engineering & Binary Analysis Basics 강의에는 총 4개의 강의가 포함되어 있습니다.

“함수 및 데이터 식별”에서 뭘 배우나요?

디스어셈블된 바이너리에서 중요한 함수, 문자열 및 기타 데이터를 찾는 기법을 배웁니다. 브라우저에서 직접 실행하는 실습 코드로 Reverse Engineering & Binary Analysis Basics을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

Reverse Engineering & Binary Analysis Basics을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 Reverse Engineering & Binary Analysis Basics은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 2번째 강의입니다.

“함수 및 데이터 식별” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 Reverse Engineering & Binary Analysis Basics 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 Reverse Engineering & Binary Analysis Basics 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. 디스어셈블러 입문
  2. 함수 및 데이터 식별
  3. 제어 흐름 그래프 분석
  4. 문자열과 상호 참조 분석
← Reverse Engineering & Binary Analysis Basics(으)로 돌아가기