Linux下使用objdump进行反汇编

objdump命令是Linux下的反汇编目标文件或者可执行文件的命令,它以一种可阅读的格式让你更多地了解二进制文件可能带有的附加信息,下面为大家讲解一下Linux下使用objdump进行反汇编方法。

1 objdump反汇编示例

源文件main.c:

/* main.c */
#include  

void swap(int* first, int* second)
{
   int temp = *first;
   *first = *second;
   *second = temp;
}

int main(void)
{
   int a = 10;
   int b = 20;

   printf("a = %d; b = %d;\n", a, b);
   swap(&a, &b);
   printf("a = %d; b = %d;\n", a, b);

   return 0;
}123456789101112131415161718192021

1.1 显示main.c的汇编代码

gcc -S -o main.s main.c1

汇编文件main.s

   .file   "main.c"
   .text
   .globl  swap
   .type   swap, @function
swap:
.LFB0:
   .cfi_startproc
   pushq   %rbp
   .cfi_def_cfa_offset 16
   .cfi_offset 6, -16
   movq    %rsp, %rbp
   .cfi_def_cfa_register 6
   movq    %rdi, -24(%rbp)
   movq    %rsi, -32(%rbp)
   movq    -24(%rbp), %rax
   ...12345678910111213141516

1.2 目标文件反汇编

gcc -c -o main.o main.c
objdump -s -d main.o > main.o.txt12

目标文件main.o的反汇编结果输出到文件main.o.txt 反汇编同时显示源代码

gcc -g -c -o main.o main.c
objdump -S -d main.o > main.o.txt12

显示源代码同时显示行号

objdump -j .text -ld -C -S main.o > main.o.txt1

1.3 可执行文件反汇编

gcc -o main main.c
objdump -s -d main > main.txt12

反汇编同时显示源代码

gcc -g -o main main.c
objdump -S -d main > main.txt12

1.4 objdump反汇编常用参数

  • objdump -d : 将代码段反汇编;
  • objdump -S : 将代码段反汇编的同时,将反汇编代码与源代码交替显示,编译时需要使用
    -g参数,即需要调试信息;
  • objdump -C : 将C++符号名逆向解析
  • objdump -l : 反汇编代码中插入文件名和行号
  • objdump -j section : 仅反汇编指定的section

2 objdump帮助信息

输出objdump帮助信息: objdump --help 或者 man objdump

Usage: objdump  
   
        Display information from object 
    
     .    At least one of the following switches must be given:    -a, --archive-headers    Display archive header information    -f, --file-headers       Display the contents of the overall file header    -p, --private-headers    Display object format specific file header contents    -P, --private=OPT,OPT... Display object format specific contents    -h, --[section-]headers  Display the contents of the section headers    -x, --all-headers        Display the contents of all headers    -d, --disassemble        Display assembler contents of executable sections    -D, --disassemble-all    Display assembler contents of all sections    -S, --
     source             Intermix 
     source code with disassembly    -s, --full-contents      Display the full contents of all sections requested    -g, --debugging          Display debug information 
     in object file    -e, --debugging-tags     Display debug information using ctags style    -G, --stabs              Display (
     in raw form) any STABS info 
     in the file    -W[lLiaprmfFsoRt] or    --dwarf[=rawline,=decodedline,=info,=abbrev,=pubnames,=aranges,=macro,=frames,          =frames-interp,=str,=loc,=Ranges,=pubtypes,          =gdb_index,=trace_info,=trace_abbrev,=trace_aranges,          =addr,=cu_index]                           Display DWARF info 
     in the file    -t, --syms               Display the contents of the symbol table(s)    -T, --dynamic-syms       Display the contents of the dynamic symbol table    -r, --reloc              Display the relocation entries 
     in the file    -R, --dynamic-reloc      Display the dynamic relocation entries 
     in the file @
     
                        Read options from 
      
           -v, --version            Display this program
       's version number    -i, --info               List object formats and architectures supported    -H, --help               Display this information The following switches are optional:    -b, --target=BFDNAME     Specify the target object format as BFDNAME    -m, --architecture=MACHINE     Specify the target architecture as MACHINE    -j, --section=NAME       Only display information for section NAME    -M, --disassembler-options=OPT Pass text OPT on to the disassembler    -EB --endian=big         Assume big endian format when disassembling    -EL --endian=little      Assume little endian format when disassembling      --file-start-context   Include context from start of file (with -S)    -I, --include=DIR        Add DIR to search list for source files    -l, --line-numbers       Include line numbers and filenames in output    -F, --file-offsets       Include file offsets when displaying information    -C, --demangle[=STYLE]   Decode mangled/processed symbol names                             The STYLE, if specified, can be `auto', `gnu
       ',                                  `lucid', `arm
       ', `hp', `edg
       ', `gnu-v3', `java
       '                                  or `gnat'    -w, --wide               Format output 
       for more than 80 columns    -z, --disassemble-zeroes       Do not skip blocks of zeroes when disassembling      --start-address=ADDR   Only process data whose address is >= ADDR      --stop-address=ADDR    Only process data whose address is for -d      --adjust-vma=OFFSET    Add OFFSET to all displayed section addresses      --special-syms         Include special symbols 
       in symbol dumps      --prefix=PREFIX        Add PREFIX to absolute paths 
       for -S      --prefix-strip=LEVEL   Strip initial directory names 
       for -S      --dwarf-depth=N        Do not display DIEs at depth N or greater      --dwarf-start=N        Display DIEs starting with N, at the same depth                             or deeper      --dwarf-check          Make additional dwarf internal consistency checks.       objdump: supported targets: elf64-x86-64 elf32-i386 elf32-x86-64 a.out-i386-linux pei-i386 pei-x86-64 elf64-l1om elf64-k1om elf64-little elf64-big elf32-little elf32-big plugin srec symbolsrec verilog tekhex binary ihex objdump: supported architectures: i386 i386:x86-64 i386:x64-32 i8086 i386:intel i386:x86-64:intel i386:x64-32:intel l1om l1om:intel k1om k1om:intel plugin The following i386/x86-64 specific disassembler options are supported 
       for use with the -M switch (multiple options should be separated by commas):    x86-64      Disassemble 
       in 64bit mode    i386        Disassemble 
       in 32bit mode    i8086       Disassemble 
       in 16bit mode    att         Display instruction 
       in AT&T syntax    intel       Display instruction 
       in Intel syntax    att-mnemonic                Display instruction 
       in AT&T mnemonic    intel-mnemonic                Display instruction 
       in Intel mnemonic    addr64      Assume 64bit address size    addr32      Assume 32bit address size    addr16      Assume 16bit address size    data32      Assume 32bit data size    data16      Assume 16bit data size    suffix      Always display instruction suffix 
       in AT&T syntax Report bugs to 
       .12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182 
      
     
    
   

文章来源网络,作者:管理,如若转载,请注明出处:https://shuyeidc.com/wp/222776.html<

赞 (0)
管理的头像管理
上一篇2025-04-15 15:57
下一篇 2025-04-15 15:59

相关推荐

  • jsp空间购买和交换数据空间怎么买,有哪些注意事项?

    购买JSP空间时,是否考虑过数据交换空间的性能?简米科技(2003年始创,23年行业沉淀)与酷番云(工信部一类增值电信全牌照)这类持牌自营机房的服务商,能确保数据交换的高效稳定,是值得优先选择的合作伙伴,为什么JSP空间需要搭配独立的数据交换空间从JSP应用特性看数据交换需求JSP基于Java技术,常用于企业级……

    2026-08-11
    0
  • 建网站用香港空间效果怎么样,香港空间稳定吗?

    建网站用香港空间,对于创建网站资产来说,核心价值在于免备案和全球带宽优势,尤其适合外贸、跨境电商和需要快速启动的项目,但你必须权衡国内访问延迟,并选择有资质的服务商以保证资产安全,香港空间的核心优势与适用边界免备案:节省时间就是节省成本国内服务器需要备案,通常需要10到20天,香港空间无需备案,域名解析后即可上……

    2026-08-11
    0
  • Java连接云数据库的方法是什么,如何操作

    Java连接云数据库的核心在于通过JDBC驱动,结合云服务商提供的连接地址、端口、数据库名及认证信息,配置安全策略(如SSL、IP白名单),即可实现稳定高效的远程数据库访问,基础准备:JDBC驱动与依赖管理连接云数据库前,需要确保开发环境具备对应的JDBC驱动,以最常见的MySQL为例,你需要引入mysql-c……

    2026-08-11
    0
  • 建网站公安联网备案必须使用数据码吗,备案流程是什么

    网站备案包括ICP备案和公安联网备案,两者缺一不可,公安联网备案必须使用服务商提供的数据码,选择持有合法资质的服务商是顺利通过备案的前提,为什么网站必须进行公安联网备案根据公安部《计算机信息网络国际联网安全保护管理办法》,网站开通后30日内必须到公安机关办理备案手续,未完成公安备案的网站,面临责令整改、关闭网站……

    2026-08-10
    0
  • 建一个企业网站大概需要多少钱?,怎么收费?

    建网站要多少钱,没有一个固定的数字,几百到几万都可能,但真正的“创建网站资产”绝不仅仅是初次投入的成本,而是基于长期稳定、合规和安全的持续性投入,其中核心取决于你选择了什么样的“地基”来承载你的业务,建站预算的构成与行业基准当你开始规划一个网站,最先面对的就是预算问题,一个常见的误区是只关注网站“看起来”的建造……

    2026-08-10
    0

发表回复

您的邮箱地址不会被公开。必填项已用 * 标注