Linux objdump Command
objdump is an important command-line tool in the GNU Binutils toolset, used to display various information about object files and executable files. It is a powerful tool for binary analysis, reverse engineering, and debugging on Linux systems.
The main functions of objdump include:
- Disassemble binary files
- View file header information
- Display section contents
- View the symbol table
- Display relocation information
- Analyze file structure
Basic Syntax
The basic command format of objdump is as follows:
objdump [选项] 文件名
If no options are specified, objdump displays the section header information of the file.
Detailed Explanation of Common Options
Disassembly-Related Options
Example
-D, --disassemble-all # Disassemble all sections
-S, --source # Mixed display of source code and assembly code (requires -g option at compile time)
--prefix-addresses # Display full addresses during disassembly
--no-addresses # Do not display address information
Section Information Options
Example
-j, --section=name# Display only the contents of the specified section
Symbol Table Options
Example
-T, --dynamic-syms # Display the dynamic symbol table
File Header Information
-f, --file-headers # 显示文件头部信息
Other Useful Options
Example
-r, --reloc # Display relocation entries
-R, --dynamic-reloc # Display dynamic relocation entries
-s, --full-contents # Display the complete contents of all sections
Practical Examples
Example 1: Viewing the Structure of an Executable File
objdump -h /bin/ls
Sample output:
/bin/ls: file format elf64-x86-64
Sections:
Idx Name Size VMA LMA File off Algn
0 .interp 0000001c 0000000000400238 0000000000400238 00000238 2**0
CONTENTS, ALLOC, LOAD, READONLY, DATA
1 .note.ABI-tag 00000020 0000000000400254 0000000000400254 00000254 2**2
CONTENTS, ALLOC, LOAD, READONLY, DATA
...
Example 2: Disassembling an Executable File
objdump -d /bin/ls
Sample output (partial):
0000000000405a50 : 405a50: 31 ed xor %ebp,%ebp 405a52: 49 89 d1 mov %rdx,%r9 405a55: 5e pop %rsi 405a56: 48 89 e2 mov %rsp,%rdx 405a59: 48 83 e4 f0 and $0xfffffffffffffff0,%rsp ...
Example 3: Viewing the Symbol Table
objdump -t myprogram.o
Sample output:
myprogram.o: file format elf64-x86-64 SYMBOL TABLE: 0000000000000000 l df *ABS* 0000000000000000 myprogram.c 0000000000000000 l d .text 0000000000000000 .text 0000000000000000 g F .text 0000000000000015 main 0000000000000000 *UND* 0000000000000000 printf
Example 4: Mixed Display of Source Code and Assembly Code
objdump -S myprogram
Sample output:
Example
400526: 55 push %rbp
400527: 48 89 e5 mov %rsp,%rbp
printf("Hello, World!n");
40052a: bf d4 05 40 00 mov $0x4005d4,%edi
40052f: e8 cc fe ff ff callq 400400
return 0;
400534: b8 00 00 00 00 mov $0x0,%eax
}
Practical Application Scenarios
Scenario 1: Debugging Program Crashes
When a program crashes, you can use objdump to view the code near the crash address:
objdump -d --start-address=0x400526 --stop-address=0x400536 myprogram
Scenario 2: Analyzing Library Function Calls
View which dynamic library functions the program calls:
objdump -T myprogram | grep UND
Scenario 3: Learning Assembly Language
Learn assembly language by disassembling simple C programs:
Example
objdump -d simple
Notes
- Debug information: To obtain source-level information, you need to add
-goption - Optimization impact: Compiler optimization affects the generated assembly code; be careful when analyzing
- Architecture differences: Different CPU architectures have different assembly instructions; make sure to use the correct disassembly options
- Permission issues: Analyzing system files may require root privileges
- File format: objdump is mainly for ELF-format files; other formats may require special handling
Advanced Tips
Using with Other Tools
Example
objdump -d myprogram | grep -A20 "main>:"
# Calculate function sizes
objdump -d myprogram | awk '/^[0-9a-f]+ :/ {print $1,$2}'
Creating a Disassembly Script
Example
# Disassembly script example
if [ $# -ne 1 ]; then
echo "Usage: $0 "
exit 1
fi
echo "=== File Header Information ==="
objdump -f $1
echo -e "n=== Section Information ==="
objdump -h $1
echo -e "n=== Disassembly Code ==="
objdump -d $1
Summary
objdump is a powerful binary analysis tool on Linux systems. Mastering it allows you to:
- Deeply understand program execution mechanisms
- Quickly locate program issues
- Learn assembly language and system knowledge
- Perform basic reverse engineering analysis
With the basic usage and practical examples introduced in this article, you should already be able to start using objdump for basic binary file analysis. As you accumulate practical experience, you will discover more of its clever uses in system programming and debugging.
Other Extensions
Linux Command Encyclopedia