Patching a binary file with dd: Difference between revisions

From Leo's Notes
This page was last edited on 14 June 2020, at 22:21.
No edit summary
mNo edit summary
 
(5 intermediate revisions by the same user not shown)
Line 1: Line 1:
Suppose I know an instruction in a particular offset after disassembling a binary file. You can use `dd` to change or patch a file like so.
Suppose I know an instruction in a particular offset after disassembling a binary file. You can use the [[dd]] utility to change or patch a file.
 
{{highlight|lang=terminal|code=
dd if=nprobe bs=1 count=6 skip=$((0x1430C)) | xxd
<nowiki>
6+0 records in
dd if=nprobe bs=1 count=6 skip=$((0x1430C)) | xxd
6+0 records out
6+0 records in
6 bytes (6 B) copied, 0.000122275 s, 49.1 kB/s
6+0 records out
0000000: 0f84 5401 0000                          ..T...
6 bytes (6 B) copied, 0.000122275 s, 49.1 kB/s
 
0000000: 0f84 5401 0000                          ..T...
</nowiki>
}}
I want to change the above from a jz to jnz like so:
I want to change the above from a jz to jnz like so:
echo "0F 85 54 01 00 00" | udcli -64  -x
{{highlight|lang=terminal|code=
0000000000000000 0f8554010000    jnz 0x15a
<nowiki>
 
# echo "0F 85 54 01 00 00" | udcli -64  -x
0000000000000000 0f8554010000    jnz 0x15a
</nowiki>
}}
Overwrite the byte (or bytes) like so:
Overwrite the byte (or bytes) like so:
printf '\x0f\x85' | dd conv=notrunc of=nprobe bs=1 seek=$((0x1430C))
{{highlight|lang=terminal|code=
2+0 records in
<nowiki>
2+0 records out
# printf '\x0f\x85' | dd conv=notrunc of=nprobe bs=1 seek=$((0x1430C))
2 bytes (2 B) copied, 0.00097866 s, 2.0 kB/s
2+0 records in
 
2+0 records out
2 bytes (2 B) copied, 0.00097866 s, 2.0 kB/s
</nowiki>
}}
Verify:
Verify:
[root@localhost bin]# dd if=nprobe bs=1 count=6 skip=$((0x1430C)) | xxd
{{highlight|lang=terminal|code=
6+0 records in
<nowiki>
6+0 records out
# dd if=nprobe bs=1 count=6 skip=$((0x1430C)) | xxd
6 bytes (6 B) copied, 0.000136555 s, 43.9 kB/s
6+0 records in
0000000: 0f85 5401 0000                          ..T...
6+0 records out
 
6 bytes (6 B) copied, 0.000136555 s, 43.9 kB/s
0000000: 0f85 5401 0000                          ..T...
</nowiki>
}}


To patch libnprobe so that it doesn't stop after 25000:
To patch libnprobe so that it doesn't stop after 25000:
printf '\x0f\x85' | dd conv=notrunc of=/usr/local/lib/libnprobe-7.1.150608.so bs=1 seek=$((0x47e97))
{{highlight|lang=terminal|code=
dd if=/usr/local/lib/libnprobe-7.1.150608.so bs=1 count=6 skip=$((0x47e97)) | xxd
<nowiki>
0000000: 0f85 d700 0000     
# printf '\x0f\x85' | dd conv=notrunc of=/usr/local/lib/libnprobe-7.1.150608.so bs=1 seek=$((0x47e97))
dd if=/usr/local/lib/libnprobe-7.1.150608.so bs=1 count=6 skip=$((0x47e97)) | xxd
0000000: 0f85 d700 0000     
</nowiki>
}}


This will effectively disable the limitation by always jumping regardless of the count.
This will effectively disable the limitation by always jumping regardless of the count.
{{Navbox Linux}}[[Category:Linux]]

Latest revision as of 22:21, 14 June 2020

Suppose I know an instruction in a particular offset after disassembling a binary file. You can use the dd utility to change or patch a file.

dd if=nprobe bs=1 count=6 skip=$((0x1430C)) | xxd
6+0 records in
6+0 records out
6 bytes (6 B) copied, 0.000122275 s, 49.1 kB/s
0000000: 0f84 5401 0000                           ..T...

I want to change the above from a jz to jnz like so:

# echo "0F 85 54 01 00 00" | udcli -64  -x
0000000000000000 0f8554010000     jnz 0x15a

Overwrite the byte (or bytes) like so:

# printf '\x0f\x85' | dd conv=notrunc of=nprobe bs=1 seek=$((0x1430C))
2+0 records in
2+0 records out
2 bytes (2 B) copied, 0.00097866 s, 2.0 kB/s

Verify:

# dd if=nprobe bs=1 count=6 skip=$((0x1430C)) | xxd
6+0 records in
6+0 records out
6 bytes (6 B) copied, 0.000136555 s, 43.9 kB/s
0000000: 0f85 5401 0000                           ..T...

To patch libnprobe so that it doesn't stop after 25000:

# printf '\x0f\x85' | dd conv=notrunc of=/usr/local/lib/libnprobe-7.1.150608.so bs=1 seek=$((0x47e97))
dd if=/usr/local/lib/libnprobe-7.1.150608.so bs=1 count=6 skip=$((0x47e97)) | xxd
0000000: 0f85 d700 0000

This will effectively disable the limitation by always jumping regardless of the count.