Feeds:
Posts
Comments

Archive for January, 2019

The basic idea of using debugger is that you can stop the program and continue the process before it terminates so you examine and identify if there is a problem with program.

In this tutorial, I will show few stepping process after breakpoints.

  1. Continue or c
  2. Next or n
  3. Step or s
  4. Nexti or ni
  5. Stepi or si

To check if the program has already run or not, type: info program.

(gdb) info program
The program being debugged is not being run.

1. Continue
It will resume the program execution until complete or stop at next breakpoint.

Before we start, type the code below and save it to ‘break.asm’.

1 section .text
2 global _start
3 _start:
4
5 mov eax,1111
6 mov ebx,2222
7 call do_nothing1
8 call do_nothing2
9 call do_nothing3
10 mov ecx,3333
11 mov edx,4444
12 call exit
13
14
15 do_nothing1:
16 nop
17 nop
18 ret
19
20 do_nothing2:
21 nop
22 nop
23 ret
24
25 do_nothing3:
26 nop
27 nop
28 ret
29
30 exit:
31 mov eax,1
32 int 0x80

Compile the program without debug function.

$ nasm -f elf32 break.asm -o break.o
$ ld break.o -o break
$ gdb ./break --silent
Reading symbols from /home/darklinux/break...(no debugging symbols found)...done.

(more…)

Read Full Post »

Reverse the program process is very useful when you are debugging and realize that you need to go backward. Instead of re-run the whole process, starting GDB version 7, you can go to the previous process.

There are few reverse that you can do:

  1. reverse-continue or rc
  2. reverse-step or reverse-step count
  3. reverse-stepi
  4. next or reverse-next count
  5. reverse-nexti

Before you use ‘reverse’ command, you need to activate the recording process otherwise you will get an error below:
“Target child does not support this command”.

Let’s try.
Type the code below and save it to ‘break.asm’.

1 section .text
2 global _start
3 _start:
4
5 mov eax,1111
6 mov ebx,2222
7 call do_nothing1
8 call do_nothing2
9 call do_nothing3
10 mov ecx,3333
11 mov edx,4444
12 call exit
13
14
15 do_nothing1:
16 nop
17 nop
18 ret
19
20 do_nothing2:
21 nop
22 nop
23 ret
24
25 do_nothing3:
26 nop
27 nop
28 ret
29
30 exit:
31 mov eax,1
32 int 0x80

reverse01
(more…)

Read Full Post »

In this tutorial, I will show you how to set break point in gnu debugger. Break point is very useful if you want to observe a program flow, find a debug in it or do reverse engineering. Using break point, you can jump the process directly to your pointer and stop the program.

Let’s find out more details about it.
Type the code below and save it to ‘break.asm’.

1 section .text
2 global _start
3 _start:
4
5 mov eax,1111
6 mov ebx,2222
7 mov ecx,3333
8 mov edx,4444
9
10 push eax
11 push ebx
12 push ecx
13 push edx
14
15
16 mov eax,1
17 int 0x80

To activate the debugging function, you have to add option -gstabs when you compile a program.

$ nasm -f elf32 -gstabs break.asm -o break.o && ld break.o -o break
$

Run with program with gdb (gnu debugger).

$ gdb ./break
GNU gdb (Ubuntu/Linaro 7.3-0ubuntu2) 7.3-2011.08
Copyright (C) 2011 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law. Type "show copying"
and "show warranty" for details.
This GDB was configured as "i686-linux-gnu".
For bug reporting instructions, please see:
<http://bugs.launchpad.net/gdb-linaro/>...
Reading symbols from /home/darklinux/break...done.
(gdb)

Display the source code from line 1 to 20.

(gdb) list 1,20
1 section .text
2 global _start
3 _start:
4
5 mov eax,1111
6 mov ebx,2222
7 mov ecx,3333
8 mov edx,4444
9
10 push eax
11 push ebx
12 push ecx
13 push edx
14
15
16 mov eax,1
17 int 0x80
(gdb)

(more…)

Read Full Post »

What is a debugger?
Debugger is a program that used to test, explore or find a bug (error) in other program. Using debugger you can run the program step by step. You can analyze why a program crash. You can stop a program with a specific conditions. If you’ve ever worked with Debug, on old MS-DOS program, you can even create a simply new program.

There are few debugger available for Linux:
-GDB (gnu debugger)
-Radare (reverse engineering and analyzing binaries)
-DDD (data display debugger)
-Nemiver (debugger for GNOME)
-Valgrind (memory debugger)
-Electric Fence (Malloc debugger)

What is Gnu Debugger?
GDB is a free software, protected by GPL (General Public License). GPL is a software license, globally used, which guarantees end users the freedom to run, study, share and modify the software.

GDB is part of Gnu Project, first annouched on 27 September 1983 by Richard Stallman at MIT to develop a complete Unix-Like operating system which is free software. Gnu Debugger (GDB), Gnu Assembler (GAS) and Gnu C Compiler (GCC) are part of it.

GDB can be used to debug programs written C, C++, Assembly, ADA, D, Fortran, Go, Objective-C, OpenCL, Modula-2, Rust and Pascal (some still not work with pascal syntax). Richard Stallman was the original author of GDB.
(more…)

Read Full Post »

To get input from user, we can use sys_call no.3 with file descriptor in ebx which is 0 (stdin).
Type the code below, save to input.asm, assemble, link and run.

1 section .text
2 global _start
3 _start:
4 %macro printmsg 2
5 mov eax,4
6 mov ebx,1
7 mov ecx,%1
8 mov edx,%2
9 int 0x80
10 %endmacro
11 %macro getinput 1
12 mov eax,3
13 mov ebx,0
14 mov ecx,name
15 mov edx,10
16 int 0x80
17 %endmacro
18
19 printmsg msg1,lengmsg1 ;enter name
20 getinput name ;get input
21 printmsg msg2,lenmsg2 ;print hello
22 printmsg name,6 ;print name
23 printmsg newline,1 ;new line
24 printmsg msg3,lenmsg3 ;print welcome
25
26 mov eax,1 ;exit
27 int 0x80
28
29 section .data
30 msg1 db 'Please, enter your name (6 chars)?',0xA
31 lengmsg1 equ $ - msg1
32 msg2 db 'Hello '
33 lenmsg2 equ $ - msg2
34 msg3 db 'Welcome to assembly programming',0xA
35 lenmsg3 equ $ - msg3
36 newline db 0xA
37 section .bss
38 name resb 0

Compile and run the program

$ nasm -f elf32 input.asm -o input.o && ld input.o -o input
$ ./input
Please, enter your name (6 chars)?
Taufan
Hello Taufan
Welcome to assembly programming
$

Read Full Post »

In this tutorial, I will show you how to count the string length.
Type the codes below and save it to ‘stringlen.asm’.
1 section .text
2 global _start
3 _start:
4
5 mov eax,msg ;copy msg address pointer to eax register
6 mov ebx,eax ;copy to ebx register
7
8 nextchar: ;LOOP
9 cmp byte [eax],0 ;check if reach 0h character
10 jz done ;if reach go to done:
11 inc eax ;if not reach, increase eax pointer by 1
12 jmp nextchar ;jump back to next character:
13 done:
14 sub eax,ebx ;after all done. eax will has the last address of msg memory
15 ;by subtitute eax with ebx (eax=eax-ebx)
16 ;from the beginning msg memory you will get
17 ;total number of characters.
18 mov ebx,eax ;copy the total number to ebx register so you can display it
19 ;using ‘$echo $?’ command.
20 mov eax,1 ;exit
21 int 0x80
22
23 section .data
24 msg db ‘12345678901234567890’,0h

Compile and run it.
$ nasm -f elf32 stringlen.asm -o stringlen.o && ld stringlen.o -o stringlen
$ ./stringlen
To display the return value of the program, you can type: echo $?
$ echo $?
20
$

 

Read Full Post »