Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: 冀云

Rating No ratings yet

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# 逆向分析实战 ## 【One-Line Pitch】 A hands-on, tool-driven introduction to Windows reverse engineering that takes you from raw data representation and x86 assembly through OllyDbg debugging and PE file format mastery, culminating in manually crafting a PE file by hand. Ideal for aspiring malware analysts, software security students, and developers who want to understand what happens beneath the compiler. ## 【Book Arc】 - **Opening (~0%–10%)**: Lays the groundwork with number systems, data width, byte order (big/little endian), and ASCII representation, then shows how to inspect these concepts directly in OllyDbg's memory window. This solves the "where do I even start" problem by grounding everything in how data physically lives in memory. - **Early (~10%–23%)**: Introduces x86 assembly from a reverse engineer's perspective—registers, flags, addressing modes, stack operations, and control flow (call/ret/jmp)—always paired with hands-on OD exercises. The emphasis is on recognizing instruction patterns in a debugger, not writing programs. - **Early (~19%–29%)**: Dives deep into OllyDbg as a tool: window layouts, software/hardware/memory/conditional/message breakpoints, code tracing, and plugin usage (including ODbgScript for automation). This stage turns the reader from a passive observer into someone who can actively control and interrogate a running process. - **Middle (~29%–48%)**: The PE file format core—DOS header, NT headers, optional header, section table, and the three address types (VA, RVA, FOA). Then moves into data directories: import table (INT vs. IAT), export table (by name and by ordinal), and relocation table, with worked examples using Stud_PE, PEiD, LordPE, and C32Asm. - **Late (~48%–end)**: Applies everything in a practical capstone: manually writing a complete PE file byte-by-byte in a hex editor, then performing manual "slimming" (section compression) on an existing PE file. This is where the abstract structures from Chapter 4 become tangible, and where the reader proves they truly understand the format. ## 【Key Takeaways】 - **Data representation is the foundation of all reverse engineering** (Opening): Understanding binary, hex, byte order, and ASCII is non-negotiable—you cannot read memory dumps or patch files without it. The book makes this concrete by having you observe little-endian storage directly in OD's memory window. - **The flag register is your window into CPU state** (Early): OF, SF, ZF, AF, PF, CF, DF, IF, and TF each tell you something specific about the result of an instruction. Mastering these makes conditional jumps and arithmetic operations readable at a glance, which is essential for tracing program logic. - **The stack is a LIFO structure that grows downward** (Early): ESP points to the top, EBP to the base, and PUSH/POP always operate at the ESP end. Understanding stack frames is critical because function calls, local variables, and return addresses all live here—and most malware analysis happens at this level. - **Breakpoints come in multiple flavors for different jobs** (Early): Software breakpoints (F2) are unlimited and code-only; hardware breakpoints use CPU debug registers (max 4) and can watch data; conditional breakpoints pause only when a condition is met; message breakpoints target Windows messages in GUI apps. Choosing the right type saves hours of manual stepping. - **PE files have a dual personality: on disk vs. in memory** (Middle): The DOS header's e_lfanew field points to the PE signature, and the optional header's data directory is "optional" in name only—it's mandatory, though individual directory entries can be zero. The critical insight is that RVA and FOA differ when FileAlignment ≠ SectionAlignment, requiring conversion tools like LordPE. - **INT vs. IAT is the key to understanding imports** (Middle): On disk, OriginalFirstThunk (INT) and FirstThunk (IAT) point to identical data (function names/ordinals), but after loading, the IAT is overwritten with actual function addresses. This distinction is why import table reconstruction is a central task in unpacking and patching. - **Relocation is about fixing absolute addresses at load time** (Middle): When a DLL can't load at its preferred ImageBase, every absolute VA reference must be adjusted by the delta (actual load address − preferred base). The book demonstrates this with a concrete two-DLL example, making the concept of "fixups" tangible. - **Hand-writing a PE file is the ultimate test of understanding** (Late): Constructing a minimal EXE byte-by-byte forces you to internalize every header field, section alignment rule, and data directory entry. It's tedious but transformative—after this exercise, PE structure is no longer abstract. ## 【Reading Tips】 - **Skim Chapter 1 if you're comfortable with hex and endianness**, but don't skip the OD memory-window exercises—they establish the tool workflow you'll use everywhere else. - **Chapter 2 is best read with OD open beside you**: type in the sample instructions (mov, push/pop, call/ret) and single-step with F8, watching registers and stack change in real time. This is the fastest way to internalize assembly semantics. - **Chapter 3's breakpoint section is reference material**: read it once for awareness, then return when you need a specific technique (e.g., conditional breakpoints for API tracing). The plugin overview (especially ODbgScript) is worth a deeper read if you plan to automate unpacking. - **Chapter 4 is the heart of the book—do not skim**: follow along with C32Asm and LordPE on a real compiled program. The RVA↔FOA conversion and INT/IAT distinction are the most exam-worthy and practically useful concepts; make sure you can reproduce the conversion logic by hand. - **Chapter 5's hand-written PE is a "prove it" exercise**: attempt it without looking at the solution first, then compare. If you can produce a working MessageBox EXE from raw hex, you've mastered the format. ## 【Coverage Limits】 This guide covers the book's first five chapters (data representation, assembly, OllyDbg, PE format, and PE hand-crafting). The excerpts do not cover later chapters on unpacking/packing automation, script writing in depth, or any content beyond the PE file instance chapter—those sections are not assessed here. ##
Page 6
....................................13 4.1.4 LordPE介绍.......................................................66 4.2 PE文件格式详解.....................................
View in text
Excerpt 2
32 位系统)送入 EIP 寄存器中。一般该指令在过程(函数)需要返回的位置或者是过 言 入 程(函数)的结尾处。 门 call 指令调用过程(函数)时会将 call 指令的下一条指令压入栈顶,当过程(函数)执 行中遇到 ret 指令时,会将 call 指令压入的指令弹出送入 EIP 寄存器中,这样代码的流程就会...
View in text
Excerpt 3
,该字段的所有取值可参考 Winnt.h 头文件。 4.可选头详解——IMAGE_OPTIONAL_HEADER IMAGE_OPTIONAL_HEADER 在几乎所有的参考书中都被称作“可选头”。虽然它被称 作可选头,但是该头部并不是一个可选的头部,而是一个必须存在的头部,不可以没有。该 头被称作“可选头”的原...
View in text
Excerpt 4
后会弹出 MessageBox 对话框,说明前面编写的 DLL 文件的导出 函数是没有问题的。 2.导出函数的查看 导出函数是数据目录中的第一项,导出函数表同样可以使用 PE 解析工具进行查看,这 里笔者还是使用 LordPE 工具进行查看。用 LordPE 打开前面生成的 DLL 文件,然后选择数 据目录的第一...
View in text
Excerpt 5
式 5.2.4 小结 实 例 本节介绍了对 PE 文件格式的压缩,这里的压缩并不是一个压缩算法,而是将没有用的、 可以重叠的、可以删减的 PE 格式中的内容删除掉或重新编排其原来的格式,在保持原功能 不变的情况下,使其在磁盘上的存储更加紧凑。 本小节内容的目的依然是让读者深入地理解 PE 文件格式中的各个结构体,...
View in text
Excerpt 6
后面的章节中,笔者将介绍关于反汇编工具的相关知识。 更多精彩免费电子书尽在www.j9p.com PE 16.1 C32Asm 187 第 6 章 十 六 进 制 编 辑 器 与 图 6-7 输入表调用窗口 图 6-8 调用显示窗口 反 编 3.分析 CrackMe1 的流程 译 工 根据前面章节对于 Crack...
View in text
Excerpt 7
代码逆向基础 235 _mainCRTStartup 是由 VC 插入的函数,该函数是由 VC 编译后的启动函数,双击 _mainCRTStartup 就可以到达启动函数的位置了。在这里说明了在 C 语言中 main()不是程序 第 7 运行的第一个函数,而是程序员编写程序时的第一个函数,main()函数是由启动...
View in text
Excerpt 8
v xxx, xxx ; 比较跳转 cmp xxx, xxx jxx _else_if ; 一系列处理指令 jmp _if_else结束位置 _else_if: mov xxx, xxx ; 比较跳转 cmp xxx, xxx jxx _else ; 一系列处理治理 jmp _if_else结束位置 _else:...
View in text
Tags
AI categories
CybersecurityWindows
Publish Year: 2017
Language: English
Pages: 285
File Format: PDF
File Size: 9.6 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…