0Pricing
Reverse Engineering & Binary Analysis Basics · Ders

İkili Dosya Yama Teknikleri

Program davranışını değiştirmek veya denetimleri atlatmak için ikili dosyaların statik olarak nasıl değiştirileceğini ve yamalanacağını anlayın.

İkili Dosya Yama Teknikleri, CoddyKit'te ücretsiz bir Reverse Engineering & Binary Analysis Basics dersidir. Bu, 4 dersinin 3. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Reverse Engineering & Binary Analysis Basics öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Reverse Engineering & Binary Analysis Basics kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

What is Binary Patching?

Binary patching is the art of modifying a compiled program's machine code directly, without access to its original source code. Think of it as making surgical changes to an executable file.

This technique is crucial in reverse engineering, allowing us to alter program behavior, fix bugs, or even bypass security checks.

Common Patching Uses

Why would you patch a binary?

  • Bug Fixes: Apply urgent fixes without recompiling.
  • Feature Mods: Change how a program works or unlock hidden features.
  • Bypass Checks: Disable license validations or trial limitations.
  • Localization: Change text strings for different languages.

Essential Patching Tools

To patch binaries, you'll primarily use two types of tools:

  • Hex Editors: For direct byte-level modifications. They show the raw hexadecimal and ASCII data.
  • Disassemblers: Like Ghidra or IDA Pro, to understand the assembly code and identify where to patch.

We'll focus on the concepts behind hex editing first.

Using a Hex Editor

A hex editor displays a file's content as hexadecimal (base-16) numbers. Each pair of hex digits represents one byte of data. It also often shows the ASCII representation.

You can navigate by address, search for specific byte sequences or text, and directly modify bytes. Your changes are saved back to the file.

Modify a String (Concept)

Programs often store messages or labels as simple strings of characters. These strings are represented as a sequence of bytes in the binary file.

By finding the byte sequence for a string in a hex editor, you can change it to display a different message when the program runs.

Simple String Program

Consider this simple C program. After compilation, the text "Hello CoddyKit!" will be stored somewhere in its executable as a sequence of ASCII bytes.

You could open the compiled binary in a hex editor, find these bytes, and change them to "Hello Patcher!" for example.

#include <stdio.h>

int main() {
  char message[] = "Hello CoddyKit!";
  printf("%s\n", message);
  return 0;
}

Disabling Code with NOPs

The NOP (No Operation) instruction is like a placeholder. It tells the CPU to do nothing and simply move to the next instruction.

If you want to disable an instruction or a small block of code without causing errors, you can replace its bytes with the NOP instruction's opcode (often 0x90 in x86/x64).

Altering Control Flow

Programs make decisions using conditional jump instructions (e.g., "jump if equal," "jump if not zero"). These determine the program's flow.

By changing a conditional jump to an unconditional jump (e.g., JMP), or vice-versa, you can force a program to always take a certain path, effectively bypassing checks or changing logic.

Bypassing a Check

Imagine a program checks if a variable is zero and exits if it is. The assembly might look like:

TEST EAX, EAX
JE Exit_Func

If we want to prevent the exit, we could change JE (Jump if Equal) to JNE (Jump if Not Equal), or even replace JE Exit_Func with NOPs if Exit_Func is short.

Patching Technique Check

When attempting to disable a specific instruction or a very small block of code in a binary without altering the program's overall structure or causing crashes, which assembly instruction is most commonly used for this purpose?

Binary Patching Recap

In this lesson, we explored binary patching techniques. You learned:

  • What binary patching is and its common applications.
  • The role of hex editors and disassemblers.
  • How to modify data (like strings) and logic (using NOPs and jumps).

Patching requires careful analysis but opens up powerful ways to interact with compiled software!

Sıkça Sorulan Sorular

“İkili Dosya Yama Teknikleri” dersi ücretsiz mi?

Evet — “İkili Dosya Yama Teknikleri” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Reverse Engineering & Binary Analysis Basics kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Reverse Engineering & Binary Analysis Basics kursu toplamda 4 dersten oluşur.

“İkili Dosya Yama Teknikleri” dersinde ne öğreneceğim?

Program davranışını değiştirmek veya denetimleri atlatmak için ikili dosyaların statik olarak nasıl değiştirileceğini ve yamalanacağını anlayın. Reverse Engineering & Binary Analysis Basics ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

Reverse Engineering & Binary Analysis Basics öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te Reverse Engineering & Binary Analysis Basics, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 3. dersidir.

“İkili Dosya Yama Teknikleri” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu Reverse Engineering & Binary Analysis Basics dersinde kod yazıp çalıştırabilir miyim?

Evet. Her Reverse Engineering & Binary Analysis Basics dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. IDAPython ve Ghidra Betik Yazımı
  2. Veri Yapısı Kurtarmayı Otomatikleştirme
  3. İkili Dosya Yama Teknikleri
  4. FLIRT İmzaları ve Kütüphane İşlevi Tanımlama
← Reverse Engineering & Binary Analysis Basics Sayfasına Dön