Practical Binary Analysis. Build your own Linux Tools for Binary Instrumentation, Analysis and Disassembly
Book information
Description
Brief Contents......Page 3 Contents......Page 4 Foreword......Page 12 Preface......Page 15 Intro......Page 16 What Is Binary Analysis, and Why Do You Need It?......Page 17 What Makes Binary Analysis Challenging?......Page 18 What's in This Book?......Page 19 Binary Format and Development Platform......Page 21 Code Sample and Virtual Machine......Page 22 Exercises......Page 23 --- Binary Formats......Page 24 1 Anatomy of a Binary......Page 25 The Preprocessing Phase......Page 26 The Compilation Phase......Page 28 The Assembly Phase......Page 30 The Linking Phase......Page 31 Viewing Symbolic Information......Page 32 Another Binary Turns to the Dark Side: Stripping a Binary......Page 34 Looking Inside an Object File......Page 35 Examining a Complete Binary Executable......Page 37 Loading and Executing a Binary......Page 41 Summary......Page 43 2 ELF Format......Page 44 The Executable Header......Page 46 The e_ident Array......Page 47 The e_type, e_machine, and e_version Fields......Page 48 The e_flags Field......Page 49 The e_shstrndx Field......Page 50 Section Headers......Page 51 The sh_type Field......Page 52 The sh_link Field......Page 53 Sections......Page 54 The .text Section......Page 56 The .bss, .data, and .rodata Sections......Page 57 Lazy Binding and the .plt, .got, and .got.plt Sections......Page 58 The .rel.* and .rela.* Sections......Page 61 The .dynamic Section......Page 63 The .init_array and .fini_array Sections......Page 64 Program Headers......Page 65 The p_offset, p_vaddr, p_paddr, p_filesz, and p_memsz Fields......Page 67 Summary......Page 68 3 PE Format - Brief Intro......Page 70 The PE Signature, File Header, and Optional Header......Page 71 The PE File Header......Page 74 The Section Header Table......Page 75 Sections......Page 76 Padding in PE Code Sections......Page 77 Summary......Page 78 4 Building Binary Loader using libbfd......Page 79 A Simple Binary-Loading Interface......Page 80 The Symbol Class......Page 83 Implementing the Binary Loader......Page 84 Initializing libbfd and Opening a Binary......Page 85 Parsing Basic Binary Properties......Page 87 Loading Symbols......Page 90 Loading Sections......Page 93 Testing the Binary Loader......Page 95 Summary......Page 97 --- Binary Analysis Fundamentals......Page 99 5 Basic Binary Analysis in Linux......Page 100 Resolving Identity Crises Using file......Page 101 Using ldd to Explore Dependencies......Page 104 Viewing File Contents with xxd......Page 105 Parsing the Extracted ELF with readelf......Page 107 Parsing Symbols with nm......Page 110 Looking for Hints with strings......Page 113 Tracing System Calls and Library Calls with strace and ltrace......Page 115 Examining Instruction-Level Behavior Using objdump......Page 120 Dumping a Dynamic String Buffer Using gdb......Page 122 Summary......Page 124 6 Disassembly & Binary Analysis Fundamentals......Page 125 Static Disassembly......Page 126 Linear Disassembly......Page 127 Recursive Disassembly......Page 128 Example: Tracing a Binary Execution with gdb......Page 132 Code Coverage Strategies......Page 135 Structuring Code......Page 139 Structuring Data......Page 146 Decompilation......Page 148 Intermediate Representations......Page 149 Fundamental Analysis Methods......Page 151 Binary Analysis Properties......Page 152 Control-Flow Analysis......Page 156 Data-Flow Analysis......Page 158 Effects of Compiler Settings on Disassembly......Page 162 Summary......Page 163 Bare-Metal Binary Modification Using Hex Editing......Page 164 Observing an Off-by-One Bug in Action......Page 165 Fixing the Off-by-One Bug......Page 168 A Heap Overflow Vulnerability......Page 172 Detecting the Heap Overflow......Page 174 Injecting an ELF Section: A High-Level Overview......Page 178 Using elfinject to Inject an ELF Section......Page 180 Calling Injected Code......Page 184 Entry Point Modification......Page 185 Hijacking Constructors and Destructors......Page 188 Hijacking GOT Entries......Page 191 Hijacking PLT Entries......Page 194 Redirecting Direct and Indirect Calls......Page 195 Summary......Page 196 --- Advanced Binary Analysis......Page 197 8 Customizing Disassembly......Page 198 A Case for Custom Disassembly: Obfuscated Code......Page 199 Other Reasons to Write a Custom Disassembler......Page 202 Installing Capstone......Page 203 Linear Disassembly with Capstone......Page 205 Exploring the Capstone C API......Page 210 Recursive Disassembly with Capstone......Page 211 Introduction to Return-Oriented Programming......Page 220 Finding ROP Gadgets......Page 222 Summary......Page 228 9 Binary Instruction......Page 230 Binary Instrumentation APIs......Page 231 Static vs. Dynamic Binary Instrumentation......Page 232 Static Binary Instrumentation......Page 233 The int 3 Approach......Page 234 The Trampoline Approach......Page 235 Architecture of a DBI System......Page 240 Introduction to Pin......Page 242 The Profiler's Data Structures and Setup Code......Page 244 Parsing Function Symbols......Page 247 Instrumenting Basic Blocks......Page 248 Instrumenting Control Flow Instructions......Page 250 Counting Instructions, Control Transfers, and Syscalls......Page 253 Testing the Profiler......Page 254 Introduction to Executable Packers......Page 258 The Unpacker's Data Structures and Setup Code......Page 260 Instrumenting Memory Writes......Page 262 Tracking Memory Writes......Page 263 Detecting the Original Entry Point and Dumping the Unpacked Binary......Page 265 Testing the Unpacker......Page 266 Summary......Page 270 10 Principles of Dynamic Taint Analysis......Page 272 Defining Taint Sources......Page 273 Tracking Taint Propagation......Page 274 A Brief Overview of the Heartbleed Vulnerability......Page 275 Detecting Heartbleed Through Tainting......Page 276 Taint Granularity......Page 278 Taint Colors......Page 279 Taint Propagation Policies......Page 280 Overtainting and Undertainting......Page 281 Control Dependencies......Page 282 Shadow Memory......Page 283 Summary......Page 285 Introducing libdft......Page 286 Internals of libdft......Page 287 Taint Policy......Page 289 Using DTA to Detect Remote Control-Hijacking......Page 290 Checking Taint Information......Page 293 Taint Sources: Tainting Recieved Bytes......Page 295 Taint Sinks: Checking execve Arguments......Page 297 Detecting a Control-Flow Hijacking Attempt......Page 298 Circumventing DTA with Implicit Flows......Page 303 A DTA-Based Data Exfiltration Detector......Page 304 Taint Sources: Tracking Taint for Open Files......Page 306 Taint Sinks: Monitoring Network Sends for Data Exfiltration......Page 310 Detecting a Data Exfiltration Attempt......Page 311 Summary......Page 314 An Overview of Symbolic Execution......Page 315 Symbolic vs. Concrete Execution......Page 316 Variants and Limitations of Symbolic Execution......Page 319 Increasing the Scalability of Symbolic Execution......Page 325 Constraint Solving with Z3......Page 327 Proving Reachability of an Instruction......Page 328 Proving Validity of a Formula......Page 331 Modeling Constraints for Machine Code with Bitvectors......Page 333 Solving an Opaque Predicate Over Bitvectors......Page 335 Summary......Page 336 13 Practical Symbolic Execution with Triton......Page 338 Introduction to Triton......Page 339 Maintaining Symbolic State with Abstract Syntax Trees......Page 340 Backward Slicing with Triton......Page 342 The Symbolic Configuration File......Page 345 Emulating Instructions......Page 347 Setting Triton's Architecture......Page 348 Computing the Backward Slice......Page 349 Using Triton to Increase Code Coverage......Page 351 Finding a Model for a New Path......Page 353 Testing the Code Coverage Tool......Page 357 Automatically Exploiting a Vulnerability......Page 360 The Vulnerable Program......Page 361 Finding the Address of the Vulnerable Call Site......Page 364 Building the Exploit Generator......Page 366 Getting a Root Shell......Page 372 Summary......Page 375 Crash Course on x86 Assembly......Page 376 Assembly Instructions, Directives, Labels, and Comments......Page 377 Separation Between Code and Data......Page 378 Machine-Level Structure of x86 Instructions......Page 379 Register Operands......Page 380 Memory Operands......Page 382 Common x86 Instructions......Page 383 Implementing Conditional Jumps......Page 385 The Stack......Page 386 Function Calls and Function Frames......Page 387 Conditional Branches......Page 391 Loops......Page 392 Implementing PT_NOTE Overwriting using libelf......Page 394 Data Structures Used in elfinject......Page 395 Initializing libelf......Page 396 Getting the Executable Header......Page 400 Finding the PT_NOTE Segment......Page 401 Injecting the Code Bytes......Page 402 Aligning the Load Addess for the Injected Section......Page 403 Overwriting the .note.ABI-tag Section Header......Page 404 Setting the Name of the Injected Section......Page 409 Overwriting the PT_NOTE Program Header......Page 411 Modifying the Entry Point......Page 413 Reading......Page 415 Disassembly Frameworks......Page 417 Binary Analysis Frameworks......Page 418 Standards & References......Page 419 Papers & Articles......Page 420 Books......Page 422 Index......Page 423
Similar books
Practical Binary Analysis: Build Your Own Linux Tools for Binary Instrumentation, Analysis, and Disassembly
2018 · PDF
Practical Binary Analysis. Build Your Own Linux Tools for Binary Instrumentation, Analysis, and Disassembly
2018 · PDF
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF