逆向工程基础技术
运用调试和反汇编技能分析简单的二进制文件、识别函数,并在没有源代码的情况下理解程序逻辑。
逆向工程基础技术 是 CoddyKit 上的免费 Assembly Language & x86 Low-Level Systems Programming 课时。 这是第 3 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Assembly Language & x86 Low-Level Systems Programming 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Assembly Language & x86 Low-Level Systems Programming 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
What is Reverse Engineering?
Reverse engineering (RE) is the process of analyzing software to understand its inner workings without having access to its original source code. Think of it as being a detective for programs!
It involves taking a compiled program (a binary) and working backward to figure out what it does, how it does it, and sometimes, why.
Your RE Toolkit
To reverse engineer, you'll primarily use two types of tools:
- Disassemblers: These tools convert machine code (the raw bytes of a program) back into human-readable assembly language. Popular examples include
objdump, IDA Pro, and Ghidra. They are your 'eyes' into the program's instructions. - Debuggers: Tools like GDB (GNU Debugger) allow you to run a program step-by-step, pause its execution, and inspect the contents of registers and memory at any point. They are your 'hands' for interacting with the live program.
Meet Our Target Program
For this lesson, we'll analyze a simple x86 assembly program. Imagine you only have its compiled version and need to figure out its logic!
This program simulates a basic 'password check' by comparing two hardcoded values and printing a message based on the result.
section .data
msg_access db "Access granted!", 0xA
len_access equ $ - msg_access
msg_denied db "Access denied.", 0xA
len_denied equ $ - msg_denied
section .text
global _start
_start:
; Simulate checking a "password" value
mov eax, 1234 ; Our "secret" password value
mov ebx, 5678 ; A "user-provided" value
cmp eax, ebx ; Compare secret with user input
je .access_granted ; If equal, jump to access granted
.access_denied:
mov eax, 4 ; sys_write
mov ebx, 1 ; stdout
mov ecx, msg_denied
mov edx, len_denied
int 0x80
jmp .exit
.access_granted:
mov eax, 4 ; sys_write
mov ebx, 1 ; stdout
mov ecx, msg_access
mov edx, len_access
int 0x80
.exit:
mov eax, 1 ; sys_exit
mov ebx, 0 ; Exit code 0
int 0x80Compiling & Disassembling
First, we'd compile our assembly program into an executable. On Linux, this typically involves an assembler (like NASM) and a linker (like LD).
nasm -f elf32 program.asm -o program.old -m elf_i386 program.o -o program
Then, we use a disassembler like objdump to see the machine code converted back into assembly:
objdump -d program
Here's a snippet of what you might see:
08048060 <_start>:
8048060: b8 d2 04 00 00 mov $0x4d2,%eax
8048065: bb 36 16 00 00 mov $0x1636,%ebx
804806a: 39 d8 cmp %ebx,%eax
804806c: 74 1c je 804808a <.access_granted>
Identifying Entry Points
When reverse engineering, one of the first things you look for is the program's entry point. This is where execution begins.
For Linux executables compiled from assembly, the entry point is often labeled _start. In our disassembled output, you can see the <_start> label at address 08048060.
This tells you exactly where the CPU starts executing instructions when the program is loaded.
Tracing Program Flow & Jumps
To understand a program's logic, you need to trace its flow of execution. Conditional jump instructions are key to understanding decision-making (like if/else statements).
In our example, after comparing eax and ebx with cmp %ebx,%eax, we see je 804808a <.access_granted>.
cmp: Compares two values and sets CPU flags.je(Jump if Equal): If the comparison result was equal, execution jumps to the address0804808a(our.access_grantedblock).- If not equal, execution continues to the next instruction in sequence (the
.access_deniedblock).
Understanding System Calls
Programs interact with the operating system through system calls. On Linux x86 (32-bit), these are typically invoked using the int 0x80 instruction.
Before int 0x80, specific registers are loaded with values:
eax: Contains the system call number (e.g.,4forsys_write,1forsys_exit).ebx, ecx, edx: Hold arguments for the system call (e.g., file descriptor, buffer address, length forsys_write).
By observing these patterns, you can identify actions like writing to the console or exiting the program.
Extracting Strings and Data
Messages and other static data are stored in data sections of the binary. You can often view these using objdump -s -j .data program or objdump -s -j .rodata program.
In the assembly, you'll see instructions that load the address of these strings into a register (e.g., mov ecx, 0x8049080 where 0x8049080 points to a string).
For our example, the messages "Access granted!" and "Access denied." would be found in the .data section, and their addresses are passed to sys_write.
Reconstructing the Original Logic
By combining all these observations, we can reconstruct the program's original logic:
- It starts at
_start. - It loads two specific integer values into
eaxandebx. - It compares these two values.
- If they are equal, it jumps to a section that prints "Access granted!" to the console.
- If they are not equal, it falls through to a section that prints "Access denied." to the console.
- After printing, the program exits gracefully.
This is the essence of reverse engineering: understanding the program's intent and behavior from its compiled form.
Quick Check
Consider the following disassembled x86 snippet. Assume 0x402000 holds the string "Yes\n" and 0x402008 holds "No\n".
0x401000: mov eax, 0x5
0x401005: mov ebx, 0x5
0x40100a: cmp eax, ebx
0x40100c: jne 0x401018
0x40100e: mov edi, 0x402000 ; "Yes\n"
0x401013: call 0x401040 <puts@plt>
0x401018: mov edi, 0x402008 ; "No\n"
0x40101d: call 0x401040 <puts@plt>
Lesson Recap
In this lesson, you've learned the fundamental techniques of basic reverse engineering:
- Understanding what RE is and its importance.
- Identifying key tools like disassemblers (
objdump) and debuggers (GDB). - Locating the program's entry point (
_start). - Tracing program flow using conditional jumps (
cmp,je). - Recognizing system calls (
int 0x80) and their parameters. - Extracting meaningful strings and data from the binary.
By applying these techniques, you can begin to reconstruct the logic and behavior of programs even without their original source code!
常见问题解答
「逆向工程基础技术」课时是免费的吗?
是的 — 「逆向工程基础技术」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Assembly Language & x86 Low-Level Systems Programming 课程的其余内容,请升级到 CoddyKit PRO。 Assembly Language & x86 Low-Level Systems Programming 课程共包含 4 节课。
「逆向工程基础技术」这节课中我会学到什么?
运用调试和反汇编技能分析简单的二进制文件、识别函数,并在没有源代码的情况下理解程序逻辑。 你通过在浏览器中直接运行的动手代码来练习 Assembly Language & x86 Low-Level Systems Programming,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Assembly Language & x86 Low-Level Systems Programming 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Assembly Language & x86 Low-Level Systems Programming 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 3 节课,共 4 节。
「逆向工程基础技术」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Assembly Language & x86 Low-Level Systems Programming 课中编写并运行代码吗?
能。每节 Assembly Language & x86 Low-Level Systems Programming 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。