Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: [日]爱甲健二

Rating No ratings yet

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# 【One-Line Pitch】 A hands-on, beginner-friendly tour of software security and reverse engineering that teaches you to analyze malware, crack games, exploit buffer overflows, and build your own debugger — perfect for curious programmers who want to understand what happens under the hood of Windows and Linux binaries. # 【Book Arc】 - **Opening (~0%–11%)**: Introduces reverse engineering through practical analysis of a sample "malware" program, covering both dynamic analysis (Process Monitor, Wireshark) and static analysis (IDA, binary editors), then teaches basic x86 assembly reading with push/call/mov/lea patterns. - **Early (~11%–28%)**: Explores game hacking by modifying memory values with a process memory editor, then covers crash debugging with Dr. Watson and just-in-time debugging setup, plus introduces code obfuscation techniques that fool disassemblers. - **Early–Middle (~28%–39%)**: Demonstrates UPX packing and unpacking with OllyDbg and OllyDump, then dives into buffer overflow exploitation on FreeBSD — building a working exploit that overwrites the return address to execute shellcode. - **Middle (~39%–56%)**: Continues exploit development by examining stack layouts in GDB, crafting null-free shellcode (e.g., using `/bin//sh` and xor tricks), and introduces defensive mechanisms like ASLR and other OS/compiler protections. - **Middle–Late (~56%–end)**: Shifts to Windows debugging internals — using CreateProcess with CREATE_SUSPENDED, handling debug events, reading thread contexts with GetThreadContext/SetThreadContext — and covers malware analysis tools (REMnux, ClamAV, Zero Wine Tryouts) plus ROP and EMET anti-exploitation mechanisms. # 【Key Takeaways】 - **Static vs. dynamic analysis is the core dichotomy** (Opening): Static analysis reads code without running it (IDA, string extraction), while dynamic analysis observes behavior at runtime (Process Monitor, Wireshark, debuggers) — choose based on whether you need logic or behavior. - **Basic x86 assembly is surprisingly readable** (Opening): Most code consists of push, call, mov, lea, and conditional jumps via cmp/test + je/jne; understanding these covers 70–80% of typical function logic. - **Memory editing is the simplest "hack"** (Early): Using a process memory editor to change a score value (e.g., 0x1D to 0x2D) demonstrates that game state lives in predictable memory locations — search, modify, repeat. - **Obfuscation exploits linear disassembly** (Early): Inserting bytes like `EB FF` (jmp +1) makes IDA misalign instructions, showing that disassembled code may differ from executed code — a key anti-analysis technique. - **Buffer overflows work by overwriting the return address** (Middle): A 64-byte buffer overflowed with 70 'A's corrupts saved EBP and ret_addr; crafting shellcode plus a correct return address yields arbitrary code execution. - **Shellcode must avoid null bytes** (Middle): Null bytes terminate strings in C, so shellcode uses tricks like `/bin//sh` (8 bytes) and xor-to-zero to eliminate 0x00 from instruction encodings. - **ASLR and compiler defenses mitigate exploitation** (Middle): Address Space Layout Randomization and related mechanisms make classic buffer overflow exploitation unreliable, forcing attackers to develop ROP and other advanced techniques. - **Debuggers are just API consumers** (Middle–Late): A minimal debugger uses CreateProcess with CREATE_SUSPENDED, then DebugEvent loops, OpenThread/GetThreadContext/SetThreadContext to inspect and control a target process. # 【Reading Tips】 - **Skim the game-hacking chapter** (~17–22%): The "兔耳旋风" tool is Japan-only and dated; just grasp the concept of memory scanning and modification, then move on. - **Deep-read the buffer overflow chapters** (~33–50%): Follow along with the FreeBSD examples in a VM — compile the sample C code, run the exploits, and use GDB to inspect stack layouts yourself; this is where the book's real value lies. - **Treat assembly as a pattern language**: Don't memorize every instruction; learn to recognize prologues (push ebp; mov ebp, esp), call conventions (args pushed right-to-left), and the cmp/test + jcc idiom for branches. - **Use the book's toolchain as a starting point**: IDA, OllyDbg, Process Monitor, and Wireshark are still relevant; modern alternatives (Ghidra, x64dbg) work similarly, so transfer the skills rather than the exact tools. - **Skip the dated Windows-specific sections** (EMET, Zero Wine Tryouts) if you're not doing malware analysis; the conceptual explanations (ROP, heuristic detection) remain useful even if the tools are obsolete. # 【Coverage Limits】 The excerpts cover roughly the first 60% of the book (through Chapter 4's debugger implementation); later chapters on ROP, EMET, and malware analysis tools (REMnux, ClamAV) are only partially represented, and the final sections on heuristic detection are mentioned but not detailed. #
Excerpt 1
静态分析:在不运行目标程序的情况下进行分析 动态分析:在运行目标程序的同时进行分析 刚才我们对 sample_mal.exe 进行分析的方法就属于动态分析。相对地, 静态分析主要包括以下方法。 阅读反汇编代码 提取可执行文件中的字符串,分析使用了哪些单词 从广义上来看,用二进制编辑器查看可执行文件的内容也可以算作...
View in text
Excerpt 2
win32 参数将代码汇编为 .obj 文件。 然后,用 ALINK 生成可执行文件。 ←键:向左移动 →键:向右移动 ↑键:填充能量(以当前得分为上限) ↓键:时间停止(消费能量) 用左右键移动,用空格键射击,这些操作和一般的射击游戏一模一样。 通过按上下键可以使用能够让时间停止的特殊能力。 其中↑键用来填充能...
View in text
Excerpt 3
cked.004010FE 在 00401341 这个位置,我们打开 OllyDump,点击 OllyDbg 菜单中的 Plug-in → OllyDump → Dump debugged process。 由于可执行数据还没有解包,因此现在这些数据是无法进行反汇编的。 接下来我们在 00401000 处设置一个...
View in text
Excerpt 4
统 都采用了这些机制,并且取得了不错的效果。下面我们就通过在 Ubuntu 12.04 中的演示来看一看这些安全机制。 首先我们来看看 ASLR(Address Space Layout Randomization,地址空间 布局随机化)。ASLR 是一种对栈、模块、动态分配的内存空间等的地 址(位置)进行随机配...
View in text
Excerpt 5
g, sizeof(asm_string)) == -1) asm_string[0] = '\0'; printf("Exception: %08x (PID:%d, TID:%d)\n", pde->u.Exception.ExceptionRecord.ExceptionAddress, pde->dwPr...
View in text
Excerpt 6
命令就可以了。 Metasploit Auxiliary Module & Exploit Database (DB) http://www.rapid7.com/db/modules/ Adobe Collab.getIcon() Buffer Overflow http://www.rapid7.com/db...
View in text
Excerpt 7
ckn/INSTALL.spidermonkey: OK jsunpackn/INSTALL.spidermonkey.shellcode: OK 省略 jsunpackn/rules: OK jsunpackn/rules.ascii: OK jsunpackn/samples.tgz: Exploit.PDF...
View in text
Excerpt 8
ster's Guide4 http://shop.oreilly.com/product/9781593272883.do 4本书中文版名为《Metasploit 渗透测试指南》,电子工业出版社,2012 年出版。——译者注 兔耳旋风是一个用于查看和修改进程内存空间的工具,它和一般的调试 器在方向性上有些差异。...
View in text
Tags
AI categories
CybersecurityProgramming LanguageOS
ISBN: 7115403996
Publish Year: 2015
Language: English
Pages: 272
File Format: PDF
File Size: 12.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…