Linux下ELF格式可执行文件及动态链接相关部分的解析

2024-06-22 05:58

本文主要是介绍Linux下ELF格式可执行文件及动态链接相关部分的解析,希望对大家解决编程问题提供一定的参考价值,需要的开发者们随着小编来一起学习吧!

Linux下面的ELF文件主要由ELF头、程序头和各个段组成。

二进制可执行文件结构

本文使用的示例程序如下。首先把它编译为可执行文件,再使用Linux下面的hexdump命令,把可执行文件完全转换为16进制的表示形式,然后分析这样的表示与ELF文件中各部分的对应关系。

示例程序:

#include <stdio.h>int global_init_var = 84;
int global_uninit_var;void func1(int i)
{printf("%d\n", i);
}
int main(int argc, char **argv)
{static int static_var1 = 85;static int static_var2;int a = 1;int b;func1(static_var1 + static_var2 + a + b);return a;
}

使用gcc编译生成二进制可执行文件之后,

gcc exam.c -o exam.out

可以通过反汇编工具objcump来查看文件中各个部分的信息,例如

objdump –d –x –s exam.out

生成的文件中展示了二进制文件中不同的节的解释和描述。

对于二进制文件,在Linux下面,可以通过hexdump命令来以文本的形式表示二进制可执行文件。以下是对exam.out文件执行hexdump命令之后所生成的文件的注释,指明了各个不同的节的开始位置及含义。

文件头:

00000000 7f 45 4c 46 02 01 01 00 00 00 00 00 00 00 00 00 |.ELF............|

00000010 02 00 3e 00 01 00 00 00 c0 03 40 00 00 00 00 00 |..>.......@.....|

phoffset = 40 sh offset = aa0

00000020 40 00 00 00 00 00 00 00 a0 0a 00 00 00 00 00 00||

ehsize=40,phentsiez=38, shentsize=40,shnum=1d

00000030 00 00 00 00 40 00 38 00 08 00 40 00 1d 00 1a 00|....@.8...@.....|

程序头表,phtable,大小为0x38* 0x8 =

00000040 06 00 00 00 05 00 00 00 40 00 00 00 00 00 00 00 |........@.......|

00000050 40 00 40 00 00 00 00 00 40 00 40 00 00 00 00 00 |@.@.....@.@.....|

00000060 c0 01 00 00 00 00 00 00 c0 01 00 00 00 00 00 00 |................|

00000070 08 00 00 00 00 00 00 0003 00 00 00 04 00 00 00 |................|

00000080 00 02 00 00 00 00 00 00 00 02 40 00 00 00 00 00 |..........@.....|

00000090 00 02 40 00 00 00 00 00 1c 00 00 00 00 00 00 00 |..@.............|

000000a0 1c 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 |................|

000000b0 01 00 00 00 05 00 00 00 00 00 00 00 00 00 00 00 |................|

000000c0 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 |..@.......@.....|

000000d0 dc 06 00 00 00 00 00 00 dc 06 00 00 00 00 00 00 |................|

000000e0 00 00 20 00 00 00 00 0001 00 00 00 06 00 00 00 |.. .............|

000000f0 e0 06 00 00 00 00 00 00 e0 06 60 00 00 00 00 00 |..........`.....|

00000100 e0 06 60 00 00 00 00 00 30 02 00 00 00 00 00 00 |..`.....0.......|

00000110 40 02 00 00 00 00 00 00 00 00 20 00 00 00 00 00 |@......... .....|

00000120 02 00 00 00 06 00 00 00 f8 06 00 00 00 00 00 00 |................|

00000130 f8 06 60 00 00 00 00 00 f8 06 60 00 00 00 00 00 |..`.......`.....|

00000140 d0 01 00 00 00 00 00 00 d0 01 00 00 00 00 00 00 |................|

00000150 08 00 00 00 00 00 00 0004 00 00 00 04 00 00 00 |................|

00000160 1c 02 00 00 00 00 00 00 1c 02 40 00 00 00 00 00 |..........@.....|

00000170 1c 02 40 00 00 00 00 00 20 00 00 00 00 00 00 00 |..@..... .......|

00000180 20 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...............|

00000190 50 e5 74 64 04 00 00 00 e0 05 00 00 00 00 00 00 |P.td............|

000001a0 e0 05 40 00 00 00 00 00 e0 05 40 00 00 00 00 00 |..@.......@.....|

000001b0 34 00 00 00 00 00 00 00 34 00 00 00 00 00 00 00 |4.......4.......|

000001c0 04 00 00 00 00 00 00 0051 e5 74 64 06 00 00 00 |........Q.td....|

000001d0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|

000001e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|

000001f0 00 00 00 00 00 00 00 00 08 00 00 00 00 00 00 00 |................|


.interpPROGBITS

00000200 2f 6c 69 62 36 34 2f 6c 64 2d 6c 69 6e 75 78 2d |/lib64/ld-linux-|

.note.ABI-tagNOTE

00000210 78 38 36 2d 36 34 2e 73 6f 2e 32 000400 00 00 |x86-64.so.2.....|

00000220 10 00 00 00 01 00 00 00 47 4e 55 00 00 00 00 00 |........GNU.....|

00000230 02 00 00 00 06 00 00 00 09 00 00 00 00 00 00 00 |................|

.hashHASH

00000240 03 00 00 00 04 00 00 00 03 00 00 00 02 00 00 00 |................|

00000250 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|

00000260 00 00 00 00 00 00 00 00.dynsym

0000 00 00 00 00 00 00 |................|

00000270 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|

00000280 0b 00 00 00 12 00 00 00 00 00 00 00 00 00 00 00 |................|

00000290 00 00 00 00 00 00 00 00 12 00 00 00 12 00 00 00 |................|

000002a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|

000002b0 24 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 |$... ...........|

000002c0 00 00 00 00 00 00 00 00

.dynstr字符串表1STRTAB

006c 69 62 63 2e 73 6f |.........libc.so|

000002d0 2e 36 00 70 72 69 6e 74 66 00 5f 5f 6c 69 62 63 |.6.printf.__libc|

000002e0 5f 73 74 61 72 74 5f 6d 61 69 6e 00 5f 5f 67 6d |_start_main.__gm|

000002f0 6f 6e 5f 73 74 61 72 74 5f 5f 00 47 4c 49 42 43 |on_start__.GLIBC|

00000300 5f 32 2e 32 2e 35 00 00.gnu.versionVERSYM

0000 02 00 02 00 00 00 |_2.2.5..........|

.gnu.version_rVERNEED

00000310 01 00 01 00 01 00 00 00 10 00 00 00 00 00 00 00 |................|

00000320 75 1a 69 09 00 00 02 00 33 00 00 00 00 00 00 00 |u.i.....3.......|

.rela.dynRELA

00000330 c8 08 60 00 00 00 00 00 06 00 00 00 03 00 00 00 |..`.............|

00000340 00 00 00 00 00 00 00 00

.rela.pltRELA

e808 60 00 00 00 00 00 |..........`.....|

00000350 07 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 |................|

00000360 f0 08 60 00 00 00 00 00 07 00 00 00 02 00 00 00 |..`.............|

00000370 00 00 00 00 00 00 00 00

.initPROGBITS

4883 ec 08 e8 6b 00 00 |........H....k..|

00000380 00 48 83 c4 08 c3 00 00 00 00 00 00 00 00 00 00 |.H..............|

.pltPROGBITS

00000390 ff 35 42 05 20 00 ff 25 44 05 20 00 0f 1f 40 00 |.5B. ..%D. ...@.|

000003a0 ff 25 42 05 20 00 68 00 00 00 00 e9 e0 ff ff ff |.%B. .h.........|

000003b0 ff 25 3a 05 20 00 68 01 00 00 00 e9 d0 ff ff ff |.%:. .h.........|

.textPROGBITS

000003c0 31 ed 49 89 d1 5e 48 89 e2 48 83 e4 f0 50 54 49 |1.I..^H..H...PTI|

000003d0 c7 c0 30 05 40 00 48 c7 c1 40 05 40 00 48 c7 c7 |..0.@.H..@.@.H..|

000003e0 f1 04 40 00 e8 c7 ff ff ff f4 90 90 48 83 ec 08 |..@.........H...|

000003f0 48 8b 05 d1 04 20 00 48 85 c0 74 02 ff d0 48 83 |H.... .H..t...H.|

00000400 c4 08 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 |...f............|

00000410 b8 17 09 60 00 55 48 2d 10 09 60 00 48 83 f8 0e |...`.UH-..`.H...|

00000420 48 89 e5 77 02 5d c3 b8 00 00 00 00 48 85 c0 74 |H..w.]......H..t|

00000430 f4 5d bf 10 09 60 00 ff e0 0f 1f 80 00 00 00 00 |.]...`..........|

00000440 b8 10 09 60 00 55 48 2d 10 09 60 00 48 c1 f8 03 |...`.UH-..`.H...|

00000450 48 89 e5 48 89 c2 48 c1 ea 3f 48 01 d0 48 d1 f8 |H..H..H..?H..H..|

00000460 75 02 5d c3 ba 00 00 00 00 48 85 d2 74 f4 5d 48 |u.]......H..t.]H|

00000470 89 c6 bf 10 09 60 00 ff e2 0f 1f 80 00 00 00 00 |.....`..........|

00000480 80 3d 89 04 20 00 00 75 11 55 48 89 e5 e8 7e ff |.=.. ..u.UH...~.|

00000490 ff ff 5d c6 05 76 04 20 00 01 f3 c3 0f 1f 40 00 |..]..v. ......@.|

000004a0 48 83 3d 48 02 20 00 00 74 1e b8 00 00 00 00 48 |H.=H. ..t......H|

000004b0 85 c0 74 14 55 bf f0 06 60 00 48 89 e5 ff d0 5d |..t.U...`.H....]|

000004c0 e9 7b ff ff ff 0f 1f 00 e9 73 ff ff ff 0f 1f 00 |.{.......s......|

000004d0 55 48 89 e5 48 83 ec 10 89 7d fc 8b 45 fc 89 c6 |UH..H....}..E...|

000004e0 bf dc 05 40 00 b8 00 00 00 00 e8 b1 fe ff ff c9 |...@............|

000004f0 c3 55 48 89 e5 48 83 ec 20 89 7d ec 48 89 75 e0 |.UH..H.. .}.H.u.|

00000500 c7 45 fc 01 00 00 00 8b 15 ff 03 20 00 8b 05 01 |.E......... ....|

00000510 04 20 00 01 c2 8b 45 fc 01 c2 8b 45 f8 01 d0 89 |. ....E....E....|

00000520 c7 e8 aa ff ff ff 8b 45 fc c9 c3 0f 1f 44 00 00 |.......E.....D..|

00000530 f3 c3 0f 1f 80 00 00 00 00 0f 1f 80 00 00 00 00 |................|

00000540 4c 89 64 24 e0 4c 89 6c 24 e8 4c 8d 25 97 01 20 |L.d$.L.l$.L.%.. |

00000550 00 4c 89 74 24 f0 4c 89 7c 24 f8 49 89 f6 48 89 |.L.t$.L.|$.I..H.|

00000560 5c 24 d0 48 89 6c 24 d8 48 83 ec 38 41 89 ff 49 |\$.H.l$.H..8A..I|

00000570 89 d5 e8 01 fe ff ff 48 8d 05 62 01 20 00 49 29 |.......H..b. .I)|

00000580 c4 49 c1 fc 03 4d 85 e4 74 1e 31 ed 48 89 c3 90 |.I...M..t.1.H...|

00000590 48 83 c5 01 4c 89 ea 4c 89 f6 44 89 ff ff 13 48 |H...L..L..D....H|

000005a0 83 c3 08 49 39 ec 75 e8 48 8b 5c 24 08 48 8b 6c |...I9.u.H.\$.H.l|

这篇关于Linux下ELF格式可执行文件及动态链接相关部分的解析的文章就介绍到这儿,希望我们推荐的文章对编程师们有所帮助!



http://www.chinasem.cn/article/1083479

相关文章

线上Java OOM问题定位与解决方案超详细解析

《线上JavaOOM问题定位与解决方案超详细解析》OOM是JVM抛出的错误,表示内存分配失败,:本文主要介绍线上JavaOOM问题定位与解决方案的相关资料,文中通过代码介绍的非常详细,需要的朋... 目录一、OOM问题核心认知1.1 OOM定义与技术定位1.2 OOM常见类型及技术特征二、OOM问题定位工具

防止Linux rm命令误操作的多场景防护方案与实践

《防止Linuxrm命令误操作的多场景防护方案与实践》在Linux系统中,rm命令是删除文件和目录的高效工具,但一旦误操作,如执行rm-rf/或rm-rf/*,极易导致系统数据灾难,本文针对不同场景... 目录引言理解 rm 命令及误操作风险rm 命令基础常见误操作案例防护方案使用 rm编程 别名及安全删除

Linux下MySQL数据库定时备份脚本与Crontab配置教学

《Linux下MySQL数据库定时备份脚本与Crontab配置教学》在生产环境中,数据库是核心资产之一,定期备份数据库可以有效防止意外数据丢失,本文将分享一份MySQL定时备份脚本,并讲解如何通过cr... 目录备份脚本详解脚本功能说明授权与可执行权限使用 Crontab 定时执行编辑 Crontab添加定

Java使用Javassist动态生成HelloWorld类

《Java使用Javassist动态生成HelloWorld类》Javassist是一个非常强大的字节码操作和定义库,它允许开发者在运行时创建新的类或者修改现有的类,本文将简单介绍如何使用Javass... 目录1. Javassist简介2. 环境准备3. 动态生成HelloWorld类3.1 创建CtC

使用Python批量将.ncm格式的音频文件转换为.mp3格式的实战详解

《使用Python批量将.ncm格式的音频文件转换为.mp3格式的实战详解》本文详细介绍了如何使用Python通过ncmdump工具批量将.ncm音频转换为.mp3的步骤,包括安装、配置ffmpeg环... 目录1. 前言2. 安装 ncmdump3. 实现 .ncm 转 .mp34. 执行过程5. 执行结

使用docker搭建嵌入式Linux开发环境

《使用docker搭建嵌入式Linux开发环境》本文主要介绍了使用docker搭建嵌入式Linux开发环境,文中通过示例代码介绍的非常详细,对大家的学习或者工作具有一定的参考学习价值,需要的朋友们下面... 目录1、前言2、安装docker3、编写容器管理脚本4、创建容器1、前言在日常开发全志、rk等不同

深度解析Python中递归下降解析器的原理与实现

《深度解析Python中递归下降解析器的原理与实现》在编译器设计、配置文件处理和数据转换领域,递归下降解析器是最常用且最直观的解析技术,本文将详细介绍递归下降解析器的原理与实现,感兴趣的小伙伴可以跟随... 目录引言:解析器的核心价值一、递归下降解析器基础1.1 核心概念解析1.2 基本架构二、简单算术表达

深度解析Java @Serial 注解及常见错误案例

《深度解析Java@Serial注解及常见错误案例》Java14引入@Serial注解,用于编译时校验序列化成员,替代传统方式解决运行时错误,适用于Serializable类的方法/字段,需注意签... 目录Java @Serial 注解深度解析1. 注解本质2. 核心作用(1) 主要用途(2) 适用位置3

Java MCP 的鉴权深度解析

《JavaMCP的鉴权深度解析》文章介绍JavaMCP鉴权的实现方式,指出客户端可通过queryString、header或env传递鉴权信息,服务器端支持工具单独鉴权、过滤器集中鉴权及启动时鉴权... 目录一、MCP Client 侧(负责传递,比较简单)(1)常见的 mcpServers json 配置

从原理到实战解析Java Stream 的并行流性能优化

《从原理到实战解析JavaStream的并行流性能优化》本文给大家介绍JavaStream的并行流性能优化:从原理到实战的全攻略,本文通过实例代码给大家介绍的非常详细,对大家的学习或工作具有一定的... 目录一、并行流的核心原理与适用场景二、性能优化的核心策略1. 合理设置并行度:打破默认阈值2. 避免装箱