如何在GDB中查找二进制文件里"Hello World"字符串的地址?
如何在GDB中找到puts函数传入的字符串地址?
问题背景
源码
#include <stdio.h> int main(){ printf("Hello World\n"); return 0; }
编译命令
@CTOS:/tmp/mytemp$ gcc helloWorld.c -o helloWorld
GDB反汇编结果
Reading symbols from helloWorld... (No debugging symbols found in helloWorld) (gdb) disassemble main Dump of assembler code for function main: 0x0000000000001149 <+0>: endbr64 0x000000000000114d <+4>: push %rbp 0x000000000000114e <+5>: mov %rsp,%rbp 0x0000000000001151 <+8>: lea 0xeac(%rip),%rax 0x0000000000001158 <+15>: mov %rax,%rdi 0x000000000000115b <+18>: call 0x1050 <puts@plt> 0x0000000000001160 <+23>: mov $0x0,%eax 0x0000000000001165 <+28>: pop %rbp 0x0000000000001166 <+29>: ret End of assembler dump. (gdb) p (char*)0xeac $1 = 0xeac <error: Cannot access memory at address 0xeac>
尝试直接打印0xeac地址失败,需要获取传入puts函数的"Hello World"字符串的实际地址。
解决方法
方法1:手动计算RIP相对地址
lea 0xeac(%rip),%rax使用RIP相对寻址,RIP执行这条指令后会指向下一条指令的地址0x1158。因此字符串的实际地址可通过以下命令计算:
p/x 0x1158 + 0xeac
得到地址后,用x/s [计算出的地址]查看字符串内容。
方法2:通过断点查看寄存器值
直接在lea指令处打断点,运行到该位置后查看rax寄存器的值(lea指令会把计算出的字符串地址存入rax):
b *0x1151 # 在lea指令的地址设置断点 r # 运行程序 p $rax # 打印rax寄存器,即字符串的地址 x/s $rax # 查看字符串内容
方法3:全局搜索字符串
在64位程序中,直接在整个地址空间搜索"Hello World"字符串:
find 0x0, 0xffffffffffffffff, "Hello World"
搜索结果中会显示字符串的地址,再用x/s验证即可。
内容的提问来源于stack exchange,提问作者Swapnil
相关产品推荐
相关产品推荐

