Foundations of Linux Debugging, Disassembling, and Reversing: Analyze Binary Code, Understand Stack Memory Usage, and Reconstruct C/C++ Code with Inte

Vostokov, Dmitry

  • 出版商: Apress
  • 出版日期: 2023-01-31
  • 定價: $1,800
  • 售價: 9.5$1,710
  • 貴賓價: 9.0$1,620
  • 語言: 英文
  • 頁數: 190
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1484291522
  • ISBN-13: 9781484291528
  • 相關分類: C++ 程式語言Linux
  • 立即出貨 (庫存=1)

商品描述

Review topics ranging from Intel x64 assembly language instructions and writing programs in assembly language, to pointers, live debugging, and static binary analysis of compiled C and C++ code. This book is ideal for Linux desktop and cloud developers.

Using the latest version of Debian, you'll focus on the foundations of the diagnostics of core memory dumps, live and postmortem debugging of Linux applications, services, and systems, memory forensics, malware, and vulnerability analysis. This requires an understanding of x64 Intel assembly language and how C and C++ compilers generate code, including memory layout and pointers.

This book provides the back-ground knowledge and practical foundations you'll need in order to master internal Linux program structure and behavior. It consists of practical step-by-step exercises of increasing complexity with explanations and ample diagrams. You'll also work with the GDB debugger and use it for disassembly and reversing.

By the end of the book, you will have a solid understanding of how Linux C and C++ compilers generate binary code. In addition, you will be able to analyze such code confidently, understand stack memory usage, and reconstruct original C/C++ code. Foundations of Linux Debugging, Disassembling, and Reversing is the perfect companion to Foundations of ARM64 Linux Debugging, Disassembling, and Reversing for readers interested in the cloud or cybersecurity.


What You'll Learn

  • Review the basics of x64 assembly language
  • Examine the essential GDB debugger commands for debugging and binary analysis
  • Study C and C++ compiler code generation with and without compiler optimizations
  • Look at binary code disassembly and reversing patterns
  • See how pointers in C and C++ are implemented and used

Who This Book Is For

Software support and escalation engineers, cloud security engineers, site reliability engineers, DevSecOps, platform engineers, software testers, Linux C/C++ software engineers and security researchers without Intel x64 assembly language background, beginners learning Linux software reverse engineering techniques, and engineers coming from non-Linux environments.

 

商品描述(中文翻譯)

本書涵蓋了從Intel x64組合語言指令和編寫組合語言程式,到指標、即時調試和靜態二進制分析編譯的C和C++代碼等各種主題。這本書非常適合Linux桌面和雲端開發人員。

使用最新版本的Debian,你將專注於核心內存轉儲的診斷基礎、Linux應用程序、服務和系統的即時和事後調試、內存取證、惡意軟件和漏洞分析。這需要對x64 Intel組合語言以及C和C++編譯器生成代碼的理解,包括內存佈局和指標。

本書提供了你掌握內部Linux程序結構和行為所需的背景知識和實踐基礎。它由一系列漸進複雜的實踐步驟練習組成,並附有解釋和豐富的圖表。你還將使用GDB調試器進行反彙編和反向工程。

通過閱讀本書,你將對Linux C和C++編譯器如何生成二進制代碼有深入的理解。此外,你還將能夠自信地分析這樣的代碼,理解堆棧內存使用情況,並重構原始的C/C++代碼。《Linux調試、反彙編和反向工程基礎》是《ARM64 Linux調試、反彙編和反向工程基礎》的完美伴侶,適合對雲端或網絡安全感興趣的讀者。

你將學到什麼:

- 回顧x64組合語言的基礎知識
- 檢查GDB調試器的基本命令,用於調試和二進制分析
- 研究帶有和不帶有編譯器優化的C和C++編譯器代碼生成
- 查看二進制代碼的反彙編和反向工程模式
- 瞭解C和C++中指標的實現和使用方式

本書適合軟件支持和升級工程師、雲安全工程師、網站可靠性工程師、DevSecOps、平台工程師、軟件測試人員、Linux C/C++軟件工程師和沒有Intel x64組合語言背景的安全研究人員,以及從非Linux環境轉入的工程師。

作者簡介

Dmitry Vostokov is an internationally recognized expert, speaker, educator, scientist, inventor, and author. He is the founder of the pattern-oriented software diagnostics, forensics, and prognostics discipline (Systematic Software Diagnostics), and Software Diagnostics Institute (DA+TA: DumpAnalysis.org + TraceAnalysis.org). Vostokov has also authored books on software diagnostics, anomaly detection and analysis, software and memory forensics, root cause analysis and problem solving, memory dump analysis, debugging, software trace and log analysis, reverse engineering, and malware analysis. He has over 25 years of experience in software architecture, design, development, and maintenance in various industries, including leadership, technical, and people management roles. In his spare time, he presents various topics on Debugging.TV and explores Software Narratology, its further development as Narratology of Things and Diagnostics of Things (DoT), Software Pathology, and Quantum Software Diagnostics. His current interest areas are theoretical software diagnostics and its mathematical and computer science foundations, application of formal logic, artificial intelligence, machine learning, and data mining to diagnostics and anomaly detection, software diagnostics engineering and diagnostics-driven development, diagnostics workflow, and interaction. Recent interest areas also include cloud native computing, security, automation, functional programming, and applications of category theory to software development and big data. He is based out of Dublin, Ireland.

作者簡介(中文翻譯)

Dmitry Vostokov是一位國際知名的專家、演講者、教育家、科學家、發明家和作家。他是模式導向軟體診斷、取證和預測學科(系統化軟體診斷)以及軟體診斷研究所(DA+TA: DumpAnalysis.org + TraceAnalysis.org)的創始人。Vostokov還撰寫了關於軟體診斷、異常檢測和分析、軟體和記憶體取證、根本原因分析和問題解決、記憶體轉儲分析、除錯、軟體追蹤和日誌分析、逆向工程和惡意軟體分析的書籍。他在軟體架構、設計、開發和維護等各個行業擁有超過25年的經驗,包括領導、技術和人員管理角色。在閒暇時間,他在Debugging.TV上演講各種主題,並探索軟體敘事學、其作為事物敘事學和診斷事物(DoT)、軟體病理學和量子軟體診斷的進一步發展。他目前的興趣領域包括理論軟體診斷及其數學和計算機科學基礎、形式邏輯、人工智慧、機器學習和數據挖掘在診斷和異常檢測中的應用、軟體診斷工程和診斷驅動開發、診斷工作流程和互動。最近的興趣領域還包括原生雲計算、安全性、自動化、函數式編程以及範疇理論在軟體開發和大數據中的應用。他的基地位於愛爾蘭都柏林。