Reversing for dummies – x86 assembly and C code
0x41.cf
0x41.cf
Has Ghidra gotten better at dealing with those, and is there a good tutorial how to best handle it?
It gets really confusing if you aren't aware of the concept.
instance.Method(foo);
....
SomeClass::Method(int x) {
y += x;
}
more or less translates to something like this (using a pseudo C level here, rather than assembly): Method(&instance, foo);
....
Method(SomeClass *this, int x) {
this->y += x;
}
it gets more interesting if "SomeClass::Method" is virtual, in which case the call looks more like this: (((BaseClass *)&instance)->vtable.Method)(&instance, foo);
Where "vtable" is a compiler generated struct with function pointers. So here's your "pointery mess", neatly abstracted away by the syntax in the first example.With multiple inheritance, it gets a bit more hairy than this, because the compiler has to do some offset adjustments on the casted pointer to get at the right vtable.
I was going to illustrate with an example like yours but I couldn't figure my way out through all the bits (including the virtual-base offsets in the vtable, or the VTT which is a table of vtables!).
But I think best advice is aggressive labeling of the functions with their intent I guess.
It is very similar to jigsaw puzzle, more pieces you put it is easier to put next.
The most recent version of Ghidra has a plugin to try and construct classes via RTTI info. This still only helps if your binary has RTTI (e.g. there's a dynamic_cast anywhere) and Ghidra still doesn't handle OOP that well even with it. There are other community plugins on Github for the same type of thing.
For heavy C++ binaries, IDA and BinaryNinja handle them a lot better, with the decompiled code looking like normal C++. You still can use Ghidra, it just means you have to do manual recognition of `this` pointers and virtual calls more.
A nice exercise that’s helped me a lot is to write a very simple program in assembly, look at the output, and see how it all pieces together. Even random instructions that make no sense other than to see how it’s turned into machine code.
I wasn't able to arrive at this conclusion by reverse engineering the code - it only happened to crash suddenly when it started to execute the sendToEmail() function. (Lucky me!)
These are almost exclusively crackme/keygen-me exercises found on crackmes.one or similar websites, and came from my realization that the notes I was taking for myself while disassembling these programs might be useful to others trying to learn how to do the same, or to those who might be stuck on a particular binary that I managed to understand.
I was also thinking of exploring malware, although the articles would necessarily have a different structure since there isn't a clear challenge like with a crackme asking you for a password, and there could always be more to say. It still seems like it would be interesting, especially if they use advanced obfuscation techniques.
Feedback and suggestions welcome!