惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
CERT Recently Published Vulnerability Notes
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V
Visual Studio Blog
Stack Overflow Blog
Stack Overflow Blog
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Tor Project blog
P
Proofpoint News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Latest news
Latest news
L
LINUX DO - 热门话题
罗磊的独立博客
T
Tenable Blog
The Hacker News
The Hacker News
美团技术团队
N
Netflix TechBlog - Medium
V
Vulnerabilities – Threatpost
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
博客园 - 司徒正美
Jina AI
Jina AI
Cyberwarzone
Cyberwarzone
云风的 BLOG
云风的 BLOG
S
Secure Thoughts
Cloudbric
Cloudbric
S
Security @ Cisco Blogs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
Spread Privacy
Spread Privacy
U
Unit 42
雷峰网
雷峰网
C
CXSECURITY Database RSS Feed - CXSecurity.com
Webroot Blog
Webroot Blog
爱范儿
爱范儿
博客园 - 【当耐特】
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
P
Palo Alto Networks Blog
Google Online Security Blog
Google Online Security Blog
The Last Watchdog
The Last Watchdog
博客园 - 聂微东
Help Net Security
Help Net Security
Hacker News: Ask HN
Hacker News: Ask HN
F
Full Disclosure
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
S
Security Affairs
Project Zero
Project Zero

ABB00717

medusa 找不到 ssh module 中文文案排版指北 BugBounty Playbook 小知識 透過 Ubuntu 26 設定 Windows 11 雙系統並使用 Image Recovery 之踩坑全紀錄 清除 git history 中的機敏資料 編譯器筆記 部落格聚集地 HTB - Busqueda 788. Rotated Digits 396. Rotate Function 幫耳機補血! 紀錄/週刊/ 做過的夢(旅行) 做過的夢 週刊 Vol.18 週刊 Vol.17 週刊 Vol.16 做過的夢(火箭推進器和追蹤導彈) 在 Ubuntu 24.04 中安裝 python2 和 pip2 動態牆 紀錄/音樂/ 用 miniflux 和 Cloudflare Tunnel 自架 RSS Reader 週記 Vol.15 關於用了 GCC 擴充功能,而被批評不夠 Clean Code 這檔事 Makefile HTB - TwoMillion 週記 Vol.14 紀錄/Hack-The-Box/ 週記 Vol.13 ABB00717's Blog 1980. Find Unique Binary String 週記 Vol.12 紀錄/Leetcode/ 在互聯網上,什麼該說,什麼又不該說? 週記 Vol.8 週記 Vol.7 週記 Vol.6 天才之於一種義務 就算 LLM 能解答所有問題,你也不該放棄學習 Stack-Based Buffer Overflow 筆記/書籍/ 《絕佳時間》 週記 Vol.5 偽深刻的自我解構 筆記/Linux-雜項筆記/ 解決 Ubuntu 待機後喚醒異常的問題 將應用程式新增到 GNOME 的 Activities Overview 週記 Vol.4 Assembly Language 週記 Vol.3 筆記/ 文章/ 紀錄/ 資源/ 挑戰 週記 Vol.2 部落格該有的東西 週記 Vol.1 數學符號表 Advent of Code Day 8 Advent of Code Day 7 Obsidian 無痛轉成 Blog Advent of Code Day 6
GDB
2026-03-29 · via ABB00717

偵錯主要可分四大步驟:

  • 中斷
  • 檢測
  • 控制
  • 修改

小抄

一些用過 GDB 都應該要會的操作

disassemble <func>
disassemble *mem
run
start
starti
si
n
ni
fin (finish)
u (until)
c (continue)
b <func>
b *mem
info reg
bt      # 顯示 Call Stack
up/down # 在堆疊中移動
print
print /x $<reg>
x/NT N=單位 T=資料類型 (x:hex, d:decimal, c:char, s:string, i:instruction)
quit
focus cmd / src
layout next
list

建議先設定 Intel 格式

# ~/.gdbinit
set disassembly-flavor intel

接著就可以透過 $ gdb -q 啟動偵錯器了:

start   # 啟動並在第一行暫停
starti  # 啟動並在程式入口點(`_start`)暫停
run     # 啟動程式直到斷點

四大步驟

中斷

info breakpoints
b main
b *main+42
b func if a == 10
delete <num>

檢測

  • 語法: x/nfu <地址>
    • 數量 (n): 要看幾個單元。
    • 格式 (f): x (Hex), d (Decimal), i (Instruction/組語), s (String)。
    • 單位 (u): b (byte), h (halfword/2 bytes), w (word/4 bytes), g (giant word/8 bytes, 64-bit)。

暫存器

info reg (info registers)     # 查看所有暫存器,除了浮點數、向量計算相關
info all-registers            # 查看所有暫存器
p $rax                        # 以十進制顯示 $rax 的值
p/x $rax                      # 以十六進制顯示 $rax 的值
set $sp += 4

記憶體

x/16gx $rsp      # 查看 Stack 上的前 16 個 64-bit 數值 (以 Hex 顯示)
x/i $rip         # 查看當前即將執行的組語指令
x/10i main       # 查看 main 函數的前 10 行組語
x/gx $rbp-0x18   # 查看 Stack 中某個區域變數的值

display

在每次輸入指令後自動顯示指定資料

display/8i $rip
display/4gx $rsp

Convenience variables and functions

define auto_get_val_and_cont
    set $my_value = *(unsigned long long *)($rbp - 0x18)
    
    printf "==="
    printf "(Hex: 0x%lx\n)", $my_value
    printf "(Dec: %llu\n)", $my_value
    printf "==="
    
    cont
end

控制

## 針對原始程式碼
n [count]
s [count]
 
## 針對組合語言
ni [count]
si [count]
 
c                     # continue
fin                   # finish, 執行直到當前 stack frame 回傳
u                     # until, 執行直到遇到下個 jump
call (void)func()     # 呼叫 func
jump *0x400500        # 跳轉

修改

set $rdi = 0                                  # 將 rdi 歸零
set *0x7fffffffe000 = 0x1337                  # 修改記憶體內容
set *(unsigned long long*)($rbp-0x10) = $rax  # 複雜的賦值
set $rip = func+47                            # 修改 Instruction Pointer

其他

(gdb) alias lld = disable $_hit_bpnum.$_hit_locno
(gdb) alias lbd = disable $_hit_bpnum

參考資料

最實用的 Google Hacking 之一: