Fundamentos de Depuradores (GDB, WinDbg)
Aprenda as principais funcionalidades de depuradores como GDB e WinDbg, incluindo a conexão a processos e o carregamento de binários.
Fundamentos de Depuradores (GDB, WinDbg) é uma aula grátis de Reverse Engineering & Binary Analysis Basics no CoddyKit. Esta é a aula 1 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de Reverse Engineering & Binary Analysis Basics, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de Reverse Engineering & Binary Analysis Basics inclui 4 aulas no total.
Partes desta aula ainda não foram traduzidas e aparecem em inglês.
Meet Your Debugger!
Welcome to dynamic analysis! Here, we'll learn about debuggers, powerful tools that let you see a program in action.
A debugger allows you to pause a running program, inspect its internal state (like memory and registers), and even change its execution path. It's like having X-ray vision for software!
Why Debuggers for RE?
In reverse engineering, debuggers are crucial for understanding how a program behaves at runtime. While static analysis (looking at code without running it) gives you clues, dynamic analysis shows you the truth.
- See actual data values as they change.
- Observe which code paths are taken.
- Understand interactions with the operating system.
GDB & WinDbg: Your Toolkit
We'll focus on two primary debuggers:
- GDB (GNU Debugger): The standard debugger for Linux, macOS, and other Unix-like systems. It's command-line based and highly versatile.
- WinDbg: A powerful debugger for Windows, often used for kernel-mode debugging and complex user-mode issues. It has both a GUI and a command-line interface.
Core Debugger Actions
Regardless of the debugger, you'll perform a few fundamental actions:
- Loading a Binary: Starting a program directly under the debugger's control.
- Attaching to a Process: Connecting the debugger to a program that is already running.
- Inspecting State: Examining memory, registers, stack, and other program data.
Loading with GDB: Example
To load a program with GDB, you typically specify the executable on the command line. Let's compile a tiny C program first:
#include <stdio.h>
int main() {
printf("Hello from GDB!\n");
return 0;
}Loading and Running in GDB
After compiling the C code (e.g., gcc -o hello hello.c), you can load it into GDB. Then, use the run command to start its execution.
GDB Commands:gdb ./hello(gdb) run
This will execute the program, and GDB will show you its output and then return to the GDB prompt.
Attaching to a Process with GDB
Sometimes, a program is already running, and you need to debug it on the fly. This is where attaching comes in. You'll need the program's Process ID (PID).
First, get the PID (e.g., using ps aux | grep on Linux). Then, use GDB with the -p flag:
#include <stdio.h>
#include <unistd.h>
int main() {
printf("Program running. PID: %d\n", getpid());
sleep(60); // Keep program alive for 60 seconds
printf("Program exiting.\n");
return 0;
}GDB Attach Command
Run the previous C program in a terminal. Note its PID. Then, in another terminal, you can attach GDB to it:
GDB Command:gdb -p <PID_OF_YOUR_PROGRAM>
Once attached, the program will pause. You can then use GDB commands to inspect its state, set breakpoints, and continue execution.
WinDbg: Loading & Attaching
WinDbg offers similar functionalities for Windows. To load a binary, you can launch WinDbg and use File > Open Executable, or use the command line: windbg.exe -o myprogram.exe.
To attach to a running process, navigate to File > Attach to a Process. You'll then see a list of running processes by name and PID, allowing you to select the target.
Quick Check!
You've learned about loading and attaching programs to debuggers. Which GDB command is used to start a program that has already been loaded into GDB?
Recap: Debugger Essentials
Great job! You've grasped the fundamental ways to get a debugger connected to a program:
- Loading: Starting a new program directly under debugger control (e.g.,
gdb ./programthenrun). - Attaching: Connecting to an already active program (e.g.,
gdb -p <PID>).
These techniques are your entry points into dynamic analysis, allowing you to observe and manipulate programs in real-time. Next, we'll explore how to pause execution and step through code!
Perguntas Frequentes
A aula “Fundamentos de Depuradores (GDB, WinDbg)” é grátis?
Sim — o texto completo de “Fundamentos de Depuradores (GDB, WinDbg)” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de Reverse Engineering & Binary Analysis Basics, atualize para CoddyKit PRO. O curso de Reverse Engineering & Binary Analysis Basics inclui 4 aulas no total.
O que vou aprender em “Fundamentos de Depuradores (GDB, WinDbg)”?
Aprenda as principais funcionalidades de depuradores como GDB e WinDbg, incluindo a conexão a processos e o carregamento de binários. Você pratica Reverse Engineering & Binary Analysis Basics com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.
Preciso ter experiência prévia para começar Reverse Engineering & Binary Analysis Basics?
Nenhuma experiência prévia é necessária. Reverse Engineering & Binary Analysis Basics no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 1 de 4.
Quanto tempo leva a aula “Fundamentos de Depuradores (GDB, WinDbg)”?
A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.
Posso escrever e executar código nesta aula de Reverse Engineering & Binary Analysis Basics?
Sim. Cada aula de Reverse Engineering & Binary Analysis Basics inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.
Todas as aulas deste curso
- Fundamentos de Depuradores (GDB, WinDbg)
- Configuração de Pontos de Interrupção e Execução Passo a Passo
- Exame da Memória e dos Registradores
- Rastreamento de APIs e Chamadas do Sistema em Tempo de Execução