{"doc_urls":["intro.html#notes","tools/index.html#tools","tools/zsh.html#zsh1","tools/zsh.html#keybindings","tools/zsh.html#parameter","tools/zsh.html#variables","tools/zsh.html#expansion-flags","tools/zsh.html#regular-expressions","tools/zsh.html#completion","tools/zsh.html#installation","tools/zsh.html#completion-variables","tools/zsh.html#completion-functions","tools/zsh.html#example","tools/bash.html#bash1","tools/bash.html#expansion","tools/bash.html#generator","tools/bash.html#parameter","tools/bash.html#pathname","tools/bash.html#io-redirection","tools/bash.html#explanation","tools/bash.html#argument-parsing-with-getopts","tools/bash.html#example","tools/bash.html#regular-expressions","tools/bash.html#completion","tools/bash.html#example","tools/fish.html#fish1","tools/fish.html#quick-info","tools/fish.html#variables","tools/fish.html#setunset-variables","tools/fish.html#lists","tools/fish.html#special-variables-lists","tools/fish.html#command-handling","tools/fish.html#io-redirection","tools/fish.html#control-flow","tools/fish.html#if--else","tools/fish.html#switch","tools/fish.html#while-loop","tools/fish.html#for-loop","tools/fish.html#functions","tools/fish.html#autoloading","tools/fish.html#helper","tools/fish.html#prompt","tools/fish.html#useful-builtins","tools/fish.html#keymaps","tools/fish.html#debug","tools/tmux.html#tmux1","tools/tmux.html#tmux-cli","tools/tmux.html#scripting","tools/tmux.html#bindings","tools/tmux.html#command-mode","tools/git.html#git1","tools/git.html#staging","tools/git.html#remote","tools/git.html#branching","tools/git.html#resetting","tools/git.html#tags","tools/git.html#diff","tools/git.html#log","tools/git.html#file-history","tools/git.html#patching","tools/git.html#submodules","tools/git.html#inspection","tools/git.html#revision-specifier","tools/awk.html#awk1","tools/awk.html#input-processing","tools/awk.html#program","tools/awk.html#special-pattern","tools/awk.html#special-variables","tools/awk.html#special-statements--functions","tools/awk.html#examples","tools/awk.html#filter-records","tools/awk.html#access-last-fields-in-records","tools/awk.html#capture-in-variables","tools/awk.html#run-shell-command-and-capture-output","tools/emacs.html#emacs1","tools/emacs.html#help","tools/emacs.html#package-manager","tools/emacs.html#window","tools/emacs.html#buffer","tools/emacs.html#ibuffer","tools/emacs.html#isearch","tools/emacs.html#occur","tools/emacs.html#grep","tools/emacs.html#yankpaste","tools/emacs.html#register","tools/emacs.html#blockrect","tools/emacs.html#mass-edit","tools/emacs.html#narrow","tools/emacs.html#org","tools/emacs.html#org-source","tools/emacs.html#comapny","tools/emacs.html#tags","tools/emacs.html#lisp","tools/emacs.html#ido","tools/emacs.html#evil","tools/emacs.html#dired","tools/gpg.html#gpg1","tools/gpg.html#generate-new-keypair","tools/gpg.html#list-keys","tools/gpg.html#edit-keys","tools/gpg.html#export--import-keys","tools/gpg.html#search--send-keys","tools/gpg.html#encrypt-passphrase","tools/gpg.html#encrypt-public-key","tools/gpg.html#signing","tools/gpg.html#signing-detached","tools/gpg.html#abbreviations","tools/gpg.html#keyservers","tools/gdb.html#gdb1","tools/gdb.html#cli","tools/gdb.html#interactive-usage","tools/gdb.html#misc","tools/gdb.html#breakpoints","tools/gdb.html#inspection","tools/gdb.html#signal-handling","tools/gdb.html#source-file-locations","tools/gdb.html#configuration","tools/gdb.html#user-commands-macros","tools/gdb.html#hooks","tools/gdb.html#examples","tools/gdb.html#automatically-print-next-instr","tools/gdb.html#conditional-breakpoints","tools/gdb.html#catch-sigsegv-and-execute-commands","tools/gdb.html#run-backtrace-on-thread-1-batch-mode","tools/gdb.html#script-gdb-for-automating-debugging-sessions","tools/gdb.html#know-bugs","tools/gdb.html#workaround-command--finish-bug","tools/radare2.html#radare21","tools/radare2.html#print","tools/radare2.html#flags","tools/radare2.html#help","tools/radare2.html#relocation","tools/qemu.html#qemu1","tools/qemu.html#keybindings","tools/qemu.html#vm-config-snippet","tools/qemu.html#cpu--ram","tools/qemu.html#graphic--display","tools/qemu.html#boot-menu","tools/qemu.html#block-devices","tools/qemu.html#usb","tools/qemu.html#references","monitor/index.html#resource-analysis--monitor","monitor/lsof.html#lsof8","monitor/lsof.html#examples","monitor/lsof.html#file-flags","monitor/lsof.html#open-tcp-connections","monitor/lsof.html#open-connection-to-specific-host","monitor/lsof.html#open-connection-to-specific-port","monitor/lsof.html#ipv4-tcp-connections-in-established-state","monitor/ss.html#ss8","monitor/ss.html#examples","monitor/pidstat.html#pidstat1","monitor/pidstat.html#page-fault-and-memory-utilization","monitor/pidstat.html#io-statistics","monitor/pgrep.html#pgrep1","monitor/pgrep.html#debug-newest-process","monitor/pmap.html#pmap1","monitor/pstack.html#pstack1","trace_profile/index.html#trace-and-profile","trace_profile/strace.html#strace1","trace_profile/strace.html#examples","trace_profile/ltrace.html#ltrace1","trace_profile/ltrace.html#example","trace_profile/perf.html#perf1","trace_profile/perf.html#flamegraph","trace_profile/perf.html#flamegraph-with-single-event-trace","trace_profile/perf.html#flamegraph-with-multiple-event-traces","trace_profile/oprofile.html#oprofile","trace_profile/time.html#usrbintime1","binary/index.html#binary","binary/od.html#od1","binary/od.html#ascii-to-hex-string","binary/od.html#extract-parts-of-file","binary/xxd.html#xxd1","binary/xxd.html#ascii-to-hex-stream","binary/xxd.html#hex-to-binary-stream","binary/xxd.html#ascii-to-binary","binary/xxd.html#ascii-to-c-array-hex-encoded","binary/readelf.html#readelf1","binary/objdump.html#objdump1","binary/objdump.html#disassemble-section","binary/nm.html#nm1","development/index.html#development","development/c++filt.html#cfilt1","development/c++filt.html#demangle-symbol","development/c++filt.html#demangle-stream","development/c++.html#c","development/c++.html#type-deduction","development/glibc.html#glibc","development/glibc.html#malloc-tracer--mtrace3","development/glibc.html#malloc-check--mallopt3","development/gcc.html#gcc1","development/gcc.html#cli","development/gcc.html#preprocessing","development/gcc.html#builtins","development/gcc.html#__builtin_expectexpr-cond","development/gcc.html#abi-linux","development/make.html#make1","development/make.html#anatomy-of-make-rules","development/make.html#pattern-rules--automatic-variables","development/make.html#pattern-rules","development/make.html#automatic-variables","development/make.html#useful-functions","development/make.html#substitution-references","development/make.html#filter","development/make.html#filter-out","development/make.html#abspath","development/ld.so.html#ldso8","development/ld.so.html#environment-variables","development/ld.so.html#ld_preload-initialization-order-and-link-map","development/ld.so.html#dynamic-linking-x86_64","arch/index.html#arch","arch/x86_64.html#x86_64","arch/x86_64.html#registers","arch/x86_64.html#general-purpose-register","arch/x86_64.html#special-register","arch/x86_64.html#flags-register","arch/x86_64.html#addressing","arch/x86_64.html#size-directives","arch/x86_64.html#sysv-x86_64-abi","arch/x86_64.html#passing-arguments-to-functions","arch/x86_64.html#return-values-from-functions","arch/x86_64.html#caller-saved-registers","arch/x86_64.html#callee-saved-registers","arch/x86_64.html#stack","arch/x86_64.html#function-prologue--epilogue","arch/x86_64.html#asm-skeleton","arch/x86_64.html#references","arch/arm64.html#arm64","arch/arm64.html#registers","arch/arm64.html#general-purpose-registers","arch/arm64.html#special-registers-per-el","arch/arm64.html#addressing","arch/arm64.html#offset","arch/arm64.html#index","arch/arm64.html#pair-access","arch/arm64.html#procedure-call-standard-arm64--aapcs64-","arch/arm64.html#passing-arguments-to-functions","arch/arm64.html#return-values-from-functions","arch/arm64.html#callee-saved-registers","arch/arm64.html#stack","arch/arm64.html#frame-chain","arch/arm64.html#function-prologue--epilogue","arch/arm64.html#asm-skeleton","arch/arm64.html#references"],"index":{"documentStore":{"docInfo":{"0":{"body":8,"breadcrumbs":1,"title":1},"1":{"body":11,"breadcrumbs":1,"title":1},"10":{"body":25,"breadcrumbs":3,"title":2},"100":{"body":10,"breadcrumbs":4,"title":3},"101":{"body":14,"breadcrumbs":4,"title":3},"102":{"body":19,"breadcrumbs":3,"title":2},"103":{"body":26,"breadcrumbs":4,"title":3},"104":{"body":46,"breadcrumbs":2,"title":1},"105":{"body":32,"breadcrumbs":3,"title":2},"106":{"body":12,"breadcrumbs":2,"title":1},"107":{"body":3,"breadcrumbs":2,"title":1},"108":{"body":0,"breadcrumbs":2,"title":1},"109":{"body":42,"breadcrumbs":2,"title":1},"11":{"body":89,"breadcrumbs":3,"title":2},"110":{"body":0,"breadcrumbs":3,"title":2},"111":{"body":66,"breadcrumbs":2,"title":1},"112":{"body":103,"breadcrumbs":2,"title":1},"113":{"body":22,"breadcrumbs":2,"title":1},"114":{"body":42,"breadcrumbs":3,"title":2},"115":{"body":33,"breadcrumbs":4,"title":3},"116":{"body":72,"breadcrumbs":2,"title":1},"117":{"body":25,"breadcrumbs":4,"title":3},"118":{"body":24,"breadcrumbs":2,"title":1},"119":{"body":0,"breadcrumbs":2,"title":1},"12":{"body":77,"breadcrumbs":2,"title":1},"120":{"body":24,"breadcrumbs":5,"title":4},"121":{"body":25,"breadcrumbs":3,"title":2},"122":{"body":13,"breadcrumbs":5,"title":4},"123":{"body":9,"breadcrumbs":7,"title":6},"124":{"body":36,"breadcrumbs":6,"title":5},"125":{"body":0,"breadcrumbs":3,"title":2},"126":{"body":27,"breadcrumbs":5,"title":4},"127":{"body":0,"breadcrumbs":2,"title":1},"128":{"body":11,"breadcrumbs":2,"title":1},"129":{"body":16,"breadcrumbs":2,"title":1},"13":{"body":0,"breadcrumbs":2,"title":1},"130":{"body":9,"breadcrumbs":2,"title":1},"131":{"body":15,"breadcrumbs":2,"title":1},"132":{"body":11,"breadcrumbs":2,"title":1},"133":{"body":13,"breadcrumbs":2,"title":1},"134":{"body":37,"breadcrumbs":4,"title":3},"135":{"body":36,"breadcrumbs":3,"title":2},"136":{"body":19,"breadcrumbs":3,"title":2},"137":{"body":10,"breadcrumbs":3,"title":2},"138":{"body":105,"breadcrumbs":3,"title":2},"139":{"body":41,"breadcrumbs":2,"title":1},"14":{"body":0,"breadcrumbs":2,"title":1},"140":{"body":8,"breadcrumbs":2,"title":1},"141":{"body":6,"breadcrumbs":3,"title":3},"142":{"body":102,"breadcrumbs":4,"title":1},"143":{"body":0,"breadcrumbs":4,"title":1},"144":{"body":10,"breadcrumbs":5,"title":2},"145":{"body":21,"breadcrumbs":6,"title":3},"146":{"body":9,"breadcrumbs":7,"title":4},"147":{"body":10,"breadcrumbs":7,"title":4},"148":{"body":4,"breadcrumbs":8,"title":5},"149":{"body":52,"breadcrumbs":4,"title":1},"15":{"body":16,"breadcrumbs":2,"title":1},"150":{"body":28,"breadcrumbs":4,"title":1},"151":{"body":26,"breadcrumbs":4,"title":1},"152":{"body":50,"breadcrumbs":7,"title":4},"153":{"body":6,"breadcrumbs":5,"title":2},"154":{"body":22,"breadcrumbs":4,"title":1},"155":{"body":14,"breadcrumbs":6,"title":3},"156":{"body":12,"breadcrumbs":4,"title":1},"157":{"body":6,"breadcrumbs":4,"title":1},"158":{"body":5,"breadcrumbs":2,"title":2},"159":{"body":64,"breadcrumbs":3,"title":1},"16":{"body":69,"breadcrumbs":2,"title":1},"160":{"body":25,"breadcrumbs":3,"title":1},"161":{"body":27,"breadcrumbs":3,"title":1},"162":{"body":11,"breadcrumbs":3,"title":1},"163":{"body":128,"breadcrumbs":3,"title":1},"164":{"body":0,"breadcrumbs":3,"title":1},"165":{"body":15,"breadcrumbs":6,"title":4},"166":{"body":17,"breadcrumbs":6,"title":4},"167":{"body":43,"breadcrumbs":3,"title":1},"168":{"body":6,"breadcrumbs":3,"title":1},"169":{"body":5,"breadcrumbs":1,"title":1},"17":{"body":93,"breadcrumbs":2,"title":1},"170":{"body":45,"breadcrumbs":2,"title":1},"171":{"body":34,"breadcrumbs":4,"title":3},"172":{"body":76,"breadcrumbs":4,"title":3},"173":{"body":19,"breadcrumbs":2,"title":1},"174":{"body":6,"breadcrumbs":4,"title":3},"175":{"body":7,"breadcrumbs":4,"title":3},"176":{"body":11,"breadcrumbs":3,"title":2},"177":{"body":15,"breadcrumbs":6,"title":5},"178":{"body":55,"breadcrumbs":2,"title":1},"179":{"body":36,"breadcrumbs":2,"title":1},"18":{"body":24,"breadcrumbs":3,"title":2},"180":{"body":8,"breadcrumbs":3,"title":2},"181":{"body":7,"breadcrumbs":2,"title":1},"182":{"body":7,"breadcrumbs":1,"title":1},"183":{"body":0,"breadcrumbs":2,"title":1},"184":{"body":3,"breadcrumbs":3,"title":2},"185":{"body":10,"breadcrumbs":3,"title":2},"186":{"body":0,"breadcrumbs":2,"title":1},"187":{"body":14,"breadcrumbs":3,"title":2},"188":{"body":0,"breadcrumbs":2,"title":1},"189":{"body":62,"breadcrumbs":4,"title":3},"19":{"body":26,"breadcrumbs":2,"title":1},"190":{"body":34,"breadcrumbs":4,"title":3},"191":{"body":0,"breadcrumbs":2,"title":1},"192":{"body":0,"breadcrumbs":2,"title":1},"193":{"body":15,"breadcrumbs":2,"title":1},"194":{"body":0,"breadcrumbs":2,"title":1},"195":{"body":90,"breadcrumbs":3,"title":2},"196":{"body":9,"breadcrumbs":3,"title":2},"197":{"body":0,"breadcrumbs":2,"title":1},"198":{"body":27,"breadcrumbs":4,"title":3},"199":{"body":0,"breadcrumbs":5,"title":4},"2":{"body":0,"breadcrumbs":2,"title":1},"20":{"body":64,"breadcrumbs":4,"title":3},"200":{"body":36,"breadcrumbs":3,"title":2},"201":{"body":68,"breadcrumbs":3,"title":2},"202":{"body":0,"breadcrumbs":3,"title":2},"203":{"body":14,"breadcrumbs":3,"title":2},"204":{"body":16,"breadcrumbs":2,"title":1},"205":{"body":17,"breadcrumbs":3,"title":2},"206":{"body":23,"breadcrumbs":2,"title":1},"207":{"body":0,"breadcrumbs":2,"title":1},"208":{"body":38,"breadcrumbs":3,"title":2},"209":{"body":128,"breadcrumbs":6,"title":5},"21":{"body":35,"breadcrumbs":2,"title":1},"210":{"body":246,"breadcrumbs":4,"title":3},"211":{"body":2,"breadcrumbs":1,"title":1},"212":{"body":21,"breadcrumbs":2,"title":1},"213":{"body":0,"breadcrumbs":2,"title":1},"214":{"body":62,"breadcrumbs":4,"title":3},"215":{"body":15,"breadcrumbs":3,"title":2},"216":{"body":31,"breadcrumbs":3,"title":2},"217":{"body":34,"breadcrumbs":2,"title":1},"218":{"body":40,"breadcrumbs":3,"title":2},"219":{"body":0,"breadcrumbs":4,"title":3},"22":{"body":58,"breadcrumbs":3,"title":2},"220":{"body":40,"breadcrumbs":4,"title":3},"221":{"body":23,"breadcrumbs":4,"title":3},"222":{"body":14,"breadcrumbs":4,"title":3},"223":{"body":15,"breadcrumbs":4,"title":3},"224":{"body":29,"breadcrumbs":2,"title":1},"225":{"body":31,"breadcrumbs":4,"title":3},"226":{"body":94,"breadcrumbs":3,"title":2},"227":{"body":42,"breadcrumbs":2,"title":1},"228":{"body":14,"breadcrumbs":2,"title":1},"229":{"body":0,"breadcrumbs":2,"title":1},"23":{"body":123,"breadcrumbs":2,"title":1},"230":{"body":40,"breadcrumbs":4,"title":3},"231":{"body":52,"breadcrumbs":5,"title":4},"232":{"body":0,"breadcrumbs":2,"title":1},"233":{"body":47,"breadcrumbs":2,"title":1},"234":{"body":18,"breadcrumbs":2,"title":1},"235":{"body":18,"breadcrumbs":3,"title":2},"236":{"body":0,"breadcrumbs":6,"title":5},"237":{"body":35,"breadcrumbs":4,"title":3},"238":{"body":8,"breadcrumbs":4,"title":3},"239":{"body":3,"breadcrumbs":4,"title":3},"24":{"body":66,"breadcrumbs":2,"title":1},"240":{"body":15,"breadcrumbs":2,"title":1},"241":{"body":52,"breadcrumbs":3,"title":2},"242":{"body":36,"breadcrumbs":4,"title":3},"243":{"body":139,"breadcrumbs":3,"title":2},"244":{"body":12,"breadcrumbs":2,"title":1},"25":{"body":0,"breadcrumbs":2,"title":1},"26":{"body":19,"breadcrumbs":3,"title":2},"27":{"body":19,"breadcrumbs":2,"title":1},"28":{"body":25,"breadcrumbs":3,"title":2},"29":{"body":51,"breadcrumbs":2,"title":1},"3":{"body":96,"breadcrumbs":2,"title":1},"30":{"body":39,"breadcrumbs":4,"title":3},"31":{"body":8,"breadcrumbs":3,"title":2},"32":{"body":8,"breadcrumbs":3,"title":2},"33":{"body":0,"breadcrumbs":3,"title":2},"34":{"body":10,"breadcrumbs":1,"title":0},"35":{"body":14,"breadcrumbs":2,"title":1},"36":{"body":4,"breadcrumbs":2,"title":1},"37":{"body":5,"breadcrumbs":2,"title":1},"38":{"body":11,"breadcrumbs":2,"title":1},"39":{"body":24,"breadcrumbs":2,"title":1},"4":{"body":88,"breadcrumbs":2,"title":1},"40":{"body":24,"breadcrumbs":2,"title":1},"41":{"body":19,"breadcrumbs":2,"title":1},"42":{"body":24,"breadcrumbs":3,"title":2},"43":{"body":28,"breadcrumbs":2,"title":1},"44":{"body":19,"breadcrumbs":2,"title":1},"45":{"body":19,"breadcrumbs":2,"title":1},"46":{"body":86,"breadcrumbs":3,"title":2},"47":{"body":119,"breadcrumbs":2,"title":1},"48":{"body":128,"breadcrumbs":2,"title":1},"49":{"body":24,"breadcrumbs":3,"title":2},"5":{"body":79,"breadcrumbs":2,"title":1},"50":{"body":0,"breadcrumbs":2,"title":1},"51":{"body":7,"breadcrumbs":2,"title":1},"52":{"body":21,"breadcrumbs":2,"title":1},"53":{"body":55,"breadcrumbs":2,"title":1},"54":{"body":50,"breadcrumbs":2,"title":1},"55":{"body":35,"breadcrumbs":2,"title":1},"56":{"body":22,"breadcrumbs":2,"title":1},"57":{"body":27,"breadcrumbs":2,"title":1},"58":{"body":19,"breadcrumbs":3,"title":2},"59":{"body":109,"breadcrumbs":2,"title":1},"6":{"body":51,"breadcrumbs":3,"title":2},"60":{"body":64,"breadcrumbs":2,"title":1},"61":{"body":27,"breadcrumbs":2,"title":1},"62":{"body":28,"breadcrumbs":3,"title":2},"63":{"body":18,"breadcrumbs":2,"title":1},"64":{"body":45,"breadcrumbs":3,"title":2},"65":{"body":37,"breadcrumbs":2,"title":1},"66":{"body":29,"breadcrumbs":3,"title":2},"67":{"body":29,"breadcrumbs":3,"title":2},"68":{"body":72,"breadcrumbs":4,"title":3},"69":{"body":0,"breadcrumbs":2,"title":1},"7":{"body":46,"breadcrumbs":3,"title":2},"70":{"body":18,"breadcrumbs":3,"title":2},"71":{"body":19,"breadcrumbs":5,"title":4},"72":{"body":39,"breadcrumbs":3,"title":2},"73":{"body":25,"breadcrumbs":6,"title":5},"74":{"body":0,"breadcrumbs":2,"title":1},"75":{"body":74,"breadcrumbs":2,"title":1},"76":{"body":21,"breadcrumbs":3,"title":2},"77":{"body":40,"breadcrumbs":2,"title":1},"78":{"body":50,"breadcrumbs":2,"title":1},"79":{"body":77,"breadcrumbs":2,"title":1},"8":{"body":0,"breadcrumbs":2,"title":1},"80":{"body":57,"breadcrumbs":2,"title":1},"81":{"body":51,"breadcrumbs":2,"title":1},"82":{"body":24,"breadcrumbs":2,"title":1},"83":{"body":43,"breadcrumbs":2,"title":1},"84":{"body":24,"breadcrumbs":2,"title":1},"85":{"body":19,"breadcrumbs":2,"title":1},"86":{"body":32,"breadcrumbs":3,"title":2},"87":{"body":22,"breadcrumbs":2,"title":1},"88":{"body":39,"breadcrumbs":2,"title":1},"89":{"body":23,"breadcrumbs":3,"title":2},"9":{"body":36,"breadcrumbs":2,"title":1},"90":{"body":26,"breadcrumbs":2,"title":1},"91":{"body":38,"breadcrumbs":2,"title":1},"92":{"body":49,"breadcrumbs":2,"title":1},"93":{"body":24,"breadcrumbs":2,"title":1},"94":{"body":28,"breadcrumbs":2,"title":1},"95":{"body":16,"breadcrumbs":2,"title":1},"96":{"body":21,"breadcrumbs":2,"title":1},"97":{"body":4,"breadcrumbs":4,"title":3},"98":{"body":13,"breadcrumbs":3,"title":2},"99":{"body":55,"breadcrumbs":3,"title":2}},"docs":{"0":{"body":"A personal collection of notes and cheatsheets. Source code is located at johannst/notes .","breadcrumbs":"Notes","id":"0","title":"Notes"},"1":{"body":"zsh bash fish tmux git awk emacs gpg gdb radare2 qemu","breadcrumbs":"Tools","id":"1","title":"Tools"},"10":{"body":"Following variables are available in Completion functions: $words # array with command line in words\n$#words # number words\n$CURRENT # index into $words for cursor position\n$words[CURRENT-1] # previous word (relative to cursor position)","breadcrumbs":"Tools » Completion Variables","id":"10","title":"Completion Variables"},"100":{"body":"gpg --export --armor --output \ngpg --import ","breadcrumbs":"Tools » Export & Import Keys","id":"100","title":"Export & Import Keys"},"101":{"body":"gpg --keyserver --send-keys \ngpg --keyserver --search-keys ","breadcrumbs":"Tools » Search & Send keys","id":"101","title":"Search & Send keys"},"102":{"body":"Encrypt file using passphrase and write encrypted data to .gpg. gpg --symmetric # Decrypt using passphrase\ngpg -o --decrypt .gpg","breadcrumbs":"Tools » Encrypt (passphrase)","id":"102","title":"Encrypt (passphrase)"},"103":{"body":"Encrypt file with public key of specified recipient and write encrypted data to .gpg. gpg --encrypt -r foo@bar.de # Decrypt at foos side (private key required)\ngpg -o --decrypt .gpg","breadcrumbs":"Tools » Encrypt (public key)","id":"103","title":"Encrypt (public key)"},"104":{"body":"Generate a signed file and write to .gpg. gpg --sign -u foor@bar.de # Verify\ngpg --verify # Extract content from signed file\ngpg -o --decrypt .gpg Without -u use first private key in list gpg -K for signing. Files can also be signed and encrypted at once, gpg will first sign the file and then encrypt it. gpg --sign --encrypt ","breadcrumbs":"Tools » Signing","id":"104","title":"Signing"},"105":{"body":"Generate a detached signature and write to .asc. Send .asc along with when distributing. gpg --detach-sign --armor -u foor@bar.de # Verify\ngpg --verify .asc Without -u use first private key in list gpg -K for signing.","breadcrumbs":"Tools » Signing (detached)","id":"105","title":"Signing (detached)"},"106":{"body":"sec secret key ssb secret subkey pub public key sub public subkey","breadcrumbs":"Tools » Abbreviations","id":"106","title":"Abbreviations"},"107":{"body":"http://pgp.mit.edu http://keyserver.ubuntu.com hkps://pgp.mailbox.org","breadcrumbs":"Tools » Keyservers","id":"107","title":"Keyservers"},"108":{"body":"","breadcrumbs":"Tools » gdb(1)","id":"108","title":"gdb(1)"},"109":{"body":"gdb [opts] [prg [-c coredump | -p pid]] gdb [opts] --args prg opts: -p attach to pid -c use -x execute script before prompt -ex execute command before prompt --tty set I/O tty for debugee","breadcrumbs":"Tools » CLI","id":"109","title":"CLI"},"11":{"body":"_describe simple completion, just words + description _arguments sophisticated completion, allow to specify actions Completion with _describe _describe MSG COMP MSG simple string with header message COMP array of completions where each entry is \"opt:description\" function _foo() { local -a opts opts=('bla:desc for bla' 'blu:desc for blu') _describe 'foo-msg' opts\n}\ncompdef _foo foo foo -- foo-msg --\nbla -- desc for bla\nblu -- desc for blu Completion with _arguments _arguments SPEC [SPEC...] where SPEC can have one of the following forms: OPT[DESC]:MSG:ACTION N:MSG:ACTION Available actions (op1 op2) list possible matches\n->VAL set $state=VAL and continue, `$state` can be checked later in switch case\nFUNC call func to generate matches\n{STR} evaluate `STR` to generate matches","breadcrumbs":"Tools » Completion Functions","id":"11","title":"Completion Functions"},"110":{"body":"","breadcrumbs":"Tools » Interactive usage","id":"110","title":"Interactive usage"},"111":{"body":"tty Set as tty for debugee. Make sure nobody reads from target tty, easiest is to spawn a shell and run following in target tty: > while true; do sleep 1024; done sharedlibrary [] Load symbols of shared libs loaded by debugee. Optionally use to filter libs for symbol loading. display [/FMT] Print every time debugee stops. Eg print next instr, see examples below. undisplay [] Delete display expressions either all or one referenced by . info display List display expressions.","breadcrumbs":"Tools » Misc","id":"111","title":"Misc"},"112":{"body":"break [-qualified] thread Set a breakpoint only for a specific thread. -qualified: Treat as fully qualified symbol (quiet handy to set breakpoints on C symbols in C++ contexts) break if Set conditional breakpoint (see examples below). delete [] Delete breakpoint either all or one referenced by . info break List breakpoints. cond Make existing breakpoint conditional with . tbreak Set temporary breakpoint, will be deleted when hit. Same syntax as `break`. rbreak Set breakpoints matching , where matching internally is done on: .*.* command [] Define commands to run after breakpoint hit. If is not specified attach command to last created breakpoint. Command block terminated with 'end' token. : Space separates list, eg 'command 2 5-8' to run command for breakpoints: 2,5,6,7,8.","breadcrumbs":"Tools » Breakpoints","id":"112","title":"Breakpoints"},"113":{"body":"info functions [] List functions matching . List all functions if no provided. info variables [] List variables matching . List all variables if no provided.","breadcrumbs":"Tools » Inspection","id":"113","title":"Inspection"},"114":{"body":"info handle [] Print how to handle . If no specified print for all signals. handle Configure how gdb handles sent to debugee. : stop/nostop Catch signal in gdb and break. print/noprint Print message when gdb catches signal. pass/nopass Pass signal down to debugee. catch signal Create a catchpoint for .","breadcrumbs":"Tools » Signal handling","id":"114","title":"Signal handling"},"115":{"body":"dir Add to the beginning of the searh path for source files. show dir Show current search path. set substitute-path Add substitution rule checked during source file lookup. show substitute-path Show current substitution rules.","breadcrumbs":"Tools » Source file locations","id":"115","title":"Source file locations"},"116":{"body":"set follow-fork-mode Specify which process to follow when debuggee makes a fork(2) syscall. set pagination Turn on/off gdb's pagination. set breakpoint pending on: always set pending breakpoints. off: error when trying to set pending breakpoints. auto: interatively query user to set breakpoint. set print pretty Turn on/off pertty printing of structures. set logging Enable output logging to file (default gdb.txt). set logging file Change output log file to set logging redirect on: only log to file. off: log to file and tty.","breadcrumbs":"Tools » Configuration","id":"116","title":"Configuration"},"117":{"body":"Gdb allows to create & document user commands as follows: define # cmds end document # docu end To get all user commands or documentations one can use: help user-defined help ","breadcrumbs":"Tools » User commands (macros)","id":"117","title":"User commands (macros)"},"118":{"body":"Gdb allows to create two types of command hooks hook- will be run before hookpost- will be run after define hook- # cmds end define hookpost- # cmds end","breadcrumbs":"Tools » Hooks","id":"118","title":"Hooks"},"119":{"body":"","breadcrumbs":"Tools » Examples","id":"119","title":"Examples"},"12":{"body":"Skeleton to copy/paste for writing simple completions. Assume a program foo with the following interface: foo -c green|red|blue -s low|high -f -d -h The completion handler could be implemented as follows in a file called _foo: #compdef _foo foo function _foo_color() { local colors=() colors+=('green:green color') colors+=('red:red color') colors+=('blue:blue color') _describe \"color\" colors\n} function _foo() { _arguments \\ \"-c[define color]:color:->s_color\" \\ \"-s[select sound]:sound:(low high)\" \\ \"-f[select file]:file:_files\" \\ \"-d[select dir]:dir:_files -/\" \\ \"-h[help]\" case $state in s_color) _foo_color;; esac\n} _files is a zsh builtin utility function to complete files/dirs see zsh completion functions zsh completion utility functions","breadcrumbs":"Tools » Example","id":"12","title":"Example"},"120":{"body":"When ever the debugee stops automatically print the memory at the current instruction pointer ($rip x86) and format as instruction /i. # rip - x86 display /i $rip # step instruction, after the step the next instruction is automatically printed si","breadcrumbs":"Tools » Automatically print next instr","id":"120","title":"Automatically print next instr"},"121":{"body":"Create conditional breakpoints for a function void foo(int i) in the debugee. # Create conditional breakpoint b foo if i == 42 b foo # would create bp 2 # Make existing breakpoint conditional cond 2 if i == 7","breadcrumbs":"Tools » Conditional breakpoints","id":"121","title":"Conditional breakpoints"},"122":{"body":"This creates a catchpoint for the SIGSEGV signal and attached the command to it. catch signal SIGSEGV command bt c end","breadcrumbs":"Tools » Catch SIGSEGV and execute commands","id":"122","title":"Catch SIGSEGV and execute commands"},"123":{"body":"gdb --batch -ex 'thread 1' -ex 'bt' -p ","breadcrumbs":"Tools » Run backtrace on thread 1 (batch mode)","id":"123","title":"Run backtrace on thread 1 (batch mode)"},"124":{"body":"To script gdb add commands into a file and pass it to gdb via -x. For example create run.gdb: set pagination off break mmap command info reg rdi rsi rdx bt c end #initial drop c This script can be used as: gdb --batch -x ./run.gdb -p ","breadcrumbs":"Tools » Script gdb for automating debugging sessions","id":"124","title":"Script gdb for automating debugging sessions"},"125":{"body":"","breadcrumbs":"Tools » Know Bugs","id":"125","title":"Know Bugs"},"126":{"body":"When using finish inside a command block, commands after finish are not executed. To workaround that bug one can create a wrapper function which calls finish. define handler bt finish info reg rax end command handler end","breadcrumbs":"Tools » Workaround command + finish bug","id":"126","title":"Workaround command + finish bug"},"127":{"body":"","breadcrumbs":"Tools » radare2(1)","id":"127","title":"radare2(1)"},"128":{"body":"pd [@ ] # print disassembly for instructions # with optional temporary seek to ","breadcrumbs":"Tools » print","id":"128","title":"print"},"129":{"body":"fs # list flag-spaces fs # select flag-space f # print flags of selected flag-space","breadcrumbs":"Tools » flags","id":"129","title":"flags"},"13":{"body":"","breadcrumbs":"Tools » bash(1)","id":"13","title":"bash(1)"},"130":{"body":"?*~ # '?*' list all commands and '~' grep for ?*~... # '..' less mode /'...' interactive search","breadcrumbs":"Tools » help","id":"130","title":"help"},"131":{"body":"> r2 -B # open mapped to addr oob # reopen current file at ","breadcrumbs":"Tools » relocation","id":"131","title":"relocation"},"132":{"body":"All the examples & notes use qemu-system-x86_64 but in most cases this can be swapped with the system emulator for other architectures.","breadcrumbs":"Tools » qemu(1)","id":"132","title":"qemu(1)"},"133":{"body":"Ctrl+Alt+g release mouse capture from VM Ctrl+Alt+1 switch to display of VM\nCtrl+Alt+2 switch to qemu monitor","breadcrumbs":"Tools » Keybindings","id":"133","title":"Keybindings"},"134":{"body":"Following command-line gives a good starting point to assemble a VM: qemu-system-x86_64 \\ -cpu host -enable-kvm -smp 4 \\ -m 8G \\ -vga virtio -display sdl,gl=on \\ -boot menu=on \\ -cdrom \\ -hda \\ -device qemu-xhci,id=xhci \\ -device usb-host,bus=xhci.0,vendorid=0x05e1,productid=0x0408,id=capture-card","breadcrumbs":"Tools » VM config snippet","id":"134","title":"VM config snippet"},"135":{"body":"-cpu host emulate host CPU in guest VM -enable-kvm use KVM instead software models (requires KVM on host machine) -smp number of guest CPUs List available CPUs qemu-system-x86_64 -cpu help. -m 8G size of guest RAM","breadcrumbs":"Tools » CPU & RAM","id":"135","title":"CPU & RAM"},"136":{"body":"-vga virtio use virtio as 3D video graphic accelerator (requires virgl in guest) -display sdl,gl=on use sdl window and enable openGL context","breadcrumbs":"Tools » Graphic & Display","id":"136","title":"Graphic & Display"},"137":{"body":"-boot menu=on enables boot menu to select boot device (enter with ESC)","breadcrumbs":"Tools » Boot Menu","id":"137","title":"Boot Menu"},"138":{"body":"-cdrom attach cdrom drive with iso to a VM -hda attach disk drive to a VM -drive file=,format=qcow2 generic way to configure & attach a drive to a VM Create a disk with qemu-img To create a qcow2 disk (qemu copy-on-write) of size 10G: qemu-img create -f qcow2 disk.qcow2 10G The disk does not contain any partitions or a partition table. We can format the disk from within the guest as following example: # Create `gpt` partition table.\nsudo parted /dev/sda mktable gpt # Create two equally sized primary partitions.\nsudo parted /dev/sda mkpart primary 0% 50%\nsudo parted /dev/sda mkpart primary 50% 100% # Create filesystem on each partition.\nsudo mkfs.ext3 /dev/sda1\nsudo mkfs.ext4 /dev/sda2 lsblk -f /dev/sda NAME FSTYPE LABEL UUID FSAVAIL FSUSE% MOUNTPOINT sda ├─sda1 ext3 .... └─sda2 ext4 ....","breadcrumbs":"Tools » Block devices","id":"138","title":"Block devices"},"139":{"body":"Host Controller -device qemu-xhci,id=xhci add XHCI USB controller to the VM (supports USB 3.0, 2.0, 1.1). id=xhci creates a usb bus named xhci. USB Device -device usb-host,bus=xhci.0,vendorid=0x05e1,productid=0x0408 pass-through USB device from host identified by vendorid & productid and attach to usb bus xhci.0 (defined with controller id)","breadcrumbs":"Tools » USB","id":"139","title":"USB"},"14":{"body":"","breadcrumbs":"Tools » Expansion","id":"14","title":"Expansion"},"140":{"body":"QEMU USB QEMU IMG QEMU Tools QEMU System","breadcrumbs":"Tools » References","id":"140","title":"References"},"141":{"body":"lsof ss pidstat pgrep pmap pstack","breadcrumbs":"Resource analysis & monitor","id":"141","title":"Resource analysis & monitor"},"142":{"body":"lsof -r ..... repeatedly execute command ervery seconds -a ......... AND slection filters instead ORing (OR: default) -p ... filter by +fg ........ show file flags for file descripros -n ......... don't convert network addr to hostnames -P ......... don't convert network port to service names -i <@h[:p]>. show connections to h (hostname|ip addr) with optional port p -s ... in conjunction with '-i' filter for protocol
in state -U ......... show unix domain sockets ('@' indicates abstract sock name, see unix(7)) file flags: R/W/RW ..... read/write/read-write CR ......... create AP ......... append TR ......... truncate -s protocols TCP, UDP -s states (TCP) CLOSED, IDLE, BOUND, LISTEN, ESTABLISHED, SYN_SENT, SYN_RCDV, ESTABLISHED, CLOSE_WAIT, FIN_WAIT1, CLOSING, LAST_ACK, FIN_WAIT_2, TIME_WAIT -s states (UDP) Unbound, Idle","breadcrumbs":"Resource analysis & monitor » lsof(8)","id":"142","title":"lsof(8)"},"143":{"body":"","breadcrumbs":"Resource analysis & monitor » Examples","id":"143","title":"Examples"},"144":{"body":"Show open files with file flags for process: lsof +fg -p ","breadcrumbs":"Resource analysis & monitor » File flags","id":"144","title":"File flags"},"145":{"body":"Show open tcp connections for $USER: lsof -a -u $USER -i TCP Note : -a ands the results. If -a is not given all open files matching $USER and all tcp connections are listed ( ored ).","breadcrumbs":"Resource analysis & monitor » Open TCP connections","id":"145","title":"Open TCP connections"},"146":{"body":"Show open connections to localhost for $USER: lsof -a -u $USER -i @localhost","breadcrumbs":"Resource analysis & monitor » Open connection to specific host","id":"146","title":"Open connection to specific host"},"147":{"body":"Show open connections to port :1234 for $USER: lsof -a -u $USER -i :1234","breadcrumbs":"Resource analysis & monitor » Open connection to specific port","id":"147","title":"Open connection to specific port"},"148":{"body":"lsof -i 4TCP -s TCP:ESTABLISHED","breadcrumbs":"Resource analysis & monitor » IPv4 TCP connections in ESTABLISHED state","id":"148","title":"IPv4 TCP connections in ESTABLISHED state"},"149":{"body":"ss [option] [filter] [option] -p ..... Show process using socket -l ..... Show sockets in listening state -4/-6 .. Show IPv4/6 sockets -x ..... Show unix sockets -n ..... Show numeric ports (no resolve) -O ..... Oneline output per socket [filter] dport/sport PORT .... Filter for destination/source port dst/src ADDR ........ Filter for destination/source address and/or .............. Logic operator ==/!= ............... Comparison operator (EXPR) .............. Group exprs","breadcrumbs":"Resource analysis & monitor » ss(8)","id":"149","title":"ss(8)"},"15":{"body":"# generate sequence from n to m\n{n..m}\n# generate sequence from n to m step by s\n{n..m..s} # expand cartesian product\n{a,b}{c,d}","breadcrumbs":"Tools » Generator","id":"15","title":"Generator"},"150":{"body":"Show all tcp IPv4 sockets connecting to port 443: ss -4 'dport 443' Show all tcp IPv4 sockets that don't connect to port 443 or connect to address 1.2.3.4. ss -4 'dport != 443 or dst 1.2.3.4'","breadcrumbs":"Resource analysis & monitor » Examples","id":"150","title":"Examples"},"151":{"body":"pidstat [opt] [interval] [cont] -U [user] show username instead UID, optionally only show for user -r memory statistics -d I/O statistics -h single line per process and no lines with average","breadcrumbs":"Resource analysis & monitor » pidstat(1)","id":"151","title":"pidstat(1)"},"152":{"body":"pidstat -r -p [interval] [count] minor_pagefault: Happens when the page needed is already in memory but not allocated to the faulting process, in that case the kernel only has to create a new page-table entry pointing to the shared physical page (not required to load a memory page from disk). major_pagefault: Happens when the page needed is NOT in memory, the kernel has to create a new page-table entry and populate the physical page (required to load a memory page from disk).","breadcrumbs":"Resource analysis & monitor » Page fault and memory utilization","id":"152","title":"Page fault and memory utilization"},"153":{"body":"pidstat -d -p [interval] [count]","breadcrumbs":"Resource analysis & monitor » I/O statistics","id":"153","title":"I/O statistics"},"154":{"body":"pgrep [opts] -n only list newest matching process -u only show matching for user -l additionally list command -a additionally list command + arguments","breadcrumbs":"Resource analysis & monitor » pgrep(1)","id":"154","title":"pgrep(1)"},"155":{"body":"For example attach gdb to newest zsh process from $USER. gdb -p $(pgrep -n -u $USER zsh)","breadcrumbs":"Resource analysis & monitor » Debug newest process","id":"155","title":"Debug newest process"},"156":{"body":"pmap Dump virtual memory map of process. Compared to /proc//maps it shows the size of the mappings.","breadcrumbs":"Resource analysis & monitor » pmap(1)","id":"156","title":"pmap(1)"},"157":{"body":"pstack Dump stack for all threads of process.","breadcrumbs":"Resource analysis & monitor » pstack(1)","id":"157","title":"pstack(1)"},"158":{"body":"strace ltrace perf OProfile time","breadcrumbs":"Trace and Profile","id":"158","title":"Trace and Profile"},"159":{"body":"strace [opts] [prg] -f .......... follow child processes on fork(2) -p .... attach to running process -s ... max string size, truncate of longer (default: 32) -e ... expression for trace filtering -o ... log output into -c .......... dump syscall statitics at the end : trace=syscall[,syscall] .... trace only syscall listed trace=file ................. trace all syscall that take a filename as arg trace=process .............. trace process management related syscalls trace=signal ............... trace signal related syscalls signal ..................... trace signals delivered to the process","breadcrumbs":"Trace and Profile » strace(1)","id":"159","title":"strace(1)"},"16":{"body":"# default value\nbar=${foo:-some_val} # if $foo set, then bar=$foo else bar=some_val # alternate value\nbar=${foo:+bla $foo} # if $foo set, then bar=\"bla $foo\" else bar=\"\" # check param set\nbar=${foo:?msg} # if $foo set, then bar=$foo else exit and print msg # indirect\nFOO=foo\nBAR=FOO\nbar=${!BAR} # deref value of BAR -> bar=$FOO # prefix\n${foo#prefix} # remove prefix when expanding $foo\n# suffix\n${foo%suffix} # remove suffix when expanding $foo # substitute\n${foo/pattern/string} # replace pattern with string when expanding foo\n# pattern starts with\n# '/' replace all occurences of pattern\n# '#' pattern match at beginning\n# '%' pattern match at end Note: prefix/suffix/pattern are expanded as pathnames .","breadcrumbs":"Tools » Parameter","id":"16","title":"Parameter"},"160":{"body":"Trace open(2) & socket(2) syscalls for a running process + child processes: strace -f -e trace=open,socket -p Trace signals delivered to a running process: strace -f -e signal -p ","breadcrumbs":"Trace and Profile » Examples","id":"160","title":"Examples"},"161":{"body":"ltrace [opts] [prg] -f .......... follow child processes on fork(2) -p .... attach to running process -o ... log output into -l . show who calls into lib matched by -C .......... demangle","breadcrumbs":"Trace and Profile » ltrace(1)","id":"161","title":"ltrace(1)"},"162":{"body":"List which program/libs call into libstdc++: ltrace -l '*libstdc++*' -C -o ltrace.log ./main","breadcrumbs":"Trace and Profile » Example","id":"162","title":"Example"},"163":{"body":"perf list show supported hw/sw events perf stat -p .. show stats for running process -I ... show stats periodically over interval -e ... filter for events perf top -p .. show stats for running process -F ... sampling frequency -K ........ hide kernel threads perf record -p ............... record stats for running process -F ................ sampling frequency --call-graph .. [fp, dwarf, lbr] method how to caputre backtrace fp : use frame-pointer, need to compile with -fno-omit-frame-pointer dwarf: use .cfi debug information lbr : use hardware last branch record facility -g ..................... short-hand for --call-graph fp -e ................ filter for events perf report -n .................... annotate symbols with nr of samples --stdio ............... report to stdio, if not presen tui mode -g graph,0.5,caller ... show caller based call chains with value >0.5 Useful : page-faults minor-faults major-faults cpu-cycles` task-clock","breadcrumbs":"Trace and Profile » perf(1)","id":"163","title":"perf(1)"},"164":{"body":"","breadcrumbs":"Trace and Profile » Flamegraph","id":"164","title":"Flamegraph"},"165":{"body":"perf record -g -e cpu-cycles -p \nperf script | FlameGraph/stackcollapse-perf.pl | FlameGraph/flamegraph.pl > cycles-flamegraph.svg","breadcrumbs":"Trace and Profile » Flamegraph with single event trace","id":"165","title":"Flamegraph with single event trace"},"166":{"body":"perf record -g -e cpu-cycles,page-faults -p \nperf script --per-event-dump\n# fold & generate as above","breadcrumbs":"Trace and Profile » Flamegraph with multiple event traces","id":"166","title":"Flamegraph with multiple event traces"},"167":{"body":"operf -g -p -g ...... caputre call-graph information opreport [opt] FILE show time spent per binary image -l ...... show time spent per symbol -c ...... show callgraph information (see below) -a ...... add column with time spent accumulated over child nodes ophelp show supported hw/sw events","breadcrumbs":"Trace and Profile » OProfile","id":"167","title":"OProfile"},"168":{"body":"# statistics of process run\n/usr/bin/time -v ","breadcrumbs":"Trace and Profile » /usr/bin/time(1)","id":"168","title":"/usr/bin/time(1)"},"169":{"body":"od xxd readelf objdump nm","breadcrumbs":"Binary","id":"169","title":"Binary"},"17":{"body":"* match any string\n? match any single char\n\\\\ match backslash\n[abc] match any char of 'a' 'b' 'c'\n[a-z] match any char between 'a' - 'z'\n[^ab] negate, match all not 'a' 'b'\n[:class:] match any char in class, available: alnum,alpha,ascii,blank,cntrl,digit,graph,lower, print,punct,space,upper,word,xdigit Wit extglob shell option enabled it is possible to have more powerful patterns. In the following pattern-list is one ore more patterns separated by | char. ?(pattern-list) matches zero or one occurrence of the given patterns\n*(pattern-list) matches zero or more occurrences of the given patterns\n+(pattern-list) matches one or more occurrences of the given patterns\n@(pattern-list) matches one of the given patterns\n!(pattern-list) matches anything except one of the given patterns Note: shopt -s extglob/shopt -u extglob to enable/disable extglob option.","breadcrumbs":"Tools » Pathname","id":"17","title":"Pathname"},"170":{"body":"od [opts] -An don't print addr info -tx4 print hex in 4 byte chunks -ta print as named character -tc printable chars or backslash escape -w4 print 4 bytes per line -j skip bytes from (hex if start with 0x) -N dump bytes (hex of start with 0x)","breadcrumbs":"Binary » od(1)","id":"170","title":"od(1)"},"171":{"body":"echo -n AAAABBBB | od -An -w4 -tx4 >> 41414141 >> 42424242 echo -n '\\x7fELF\\n' | od -tx1 -ta -tc >> 0000000 7f 45 4c 46 0a # tx1 >> del E L F nl # ta >> 177 E L F \\n # tc","breadcrumbs":"Binary » ASCII to hex string","id":"171","title":"ASCII to hex string"},"172":{"body":"For example .rodata section from an elf file. We can use readelf to get the offset into the file where the .rodata section starts. readelf -W -S foo >> Section Headers: >> [Nr] Name Type Address Off Size ES Flg Lk Inf Al >> ... >> [15] .rodata PROGBITS 00000000004009c0 0009c0 000030 00 A 0 0 16 With the offset of -j 0x0009c0 we can dump -N 0x30 bytes from the beginning of the .rodata section as follows: od -j 0x0009c0 -N 0x30 -tx4 -w4 foo >> 0004700 00020001 >> 0004704 00000000 >> * >> 0004740 00000001 >> 0004744 00000002 >> 0004750 00000003 >> 0004754 00000004 Note : Numbers starting with 0x will be interpreted as hex by od.","breadcrumbs":"Binary » Extract parts of file","id":"172","title":"Extract parts of file"},"173":{"body":"xxd [opts] -p dump continuous hexdump -r convert hexdump into binary ('revert') -e dump as little endian mode -i output as C array","breadcrumbs":"Binary » xxd(1)","id":"173","title":"xxd(1)"},"174":{"body":"echo -n 'aabb' | xxd -p >> 61616262","breadcrumbs":"Binary » ASCII to hex stream","id":"174","title":"ASCII to hex stream"},"175":{"body":"echo -n '61616262' | xxd -p -r >> aabb","breadcrumbs":"Binary » Hex to binary stream","id":"175","title":"Hex to binary stream"},"176":{"body":"echo -n '\\x7fELF' | xxd -p | xxd -p -r | file -p - >> ELF","breadcrumbs":"Binary » ASCII to binary","id":"176","title":"ASCII to binary"},"177":{"body":"xxd -i <(echo -n '\\x7fELF') >> unsigned char _proc_self_fd_11[] = { >> 0x7f, 0x45, 0x4c, 0x46 >> }; >> unsigned int _proc_self_fd_11_len = 4;","breadcrumbs":"Binary » ASCII to C array (hex encoded)","id":"177","title":"ASCII to C array (hex encoded)"},"178":{"body":"readelf [opts] -W|--wide wide output, dont break output at 80 chars -h print ELF header -S print section headers -l print program headers + segment mapping -d print .dynamic section (dynamic link information) --syms print symbol tables (.symtab .dynsym) --dyn-syms print dynamic symbol table (exported symbols for dynamic linker) -r print relocation sections (.rel.*, .rela.*)","breadcrumbs":"Binary » readelf(1)","id":"178","title":"readelf(1)"},"179":{"body":"objdump [opts] -M intel use intil syntax -d disassemble text section -D disassemble all sections -S mix disassembly with source code -C demangle -j display info for section --[no-]show-raw-insn [dont] show object code next to disassembly","breadcrumbs":"Binary » objdump(1)","id":"179","title":"objdump(1)"},"18":{"body":"Note: The trick with bash I/O redirection is to interpret from left-to-right. # stdout & stderr to file\ncommand >file 2>&1\n# equivalent\ncommand &>file # stderr to stdout & stdout to file\ncommand 2>&1 >file","breadcrumbs":"Tools » I/O redirection","id":"18","title":"I/O redirection"},"180":{"body":"For example .plt section: objdump -j .plt -d ","breadcrumbs":"Binary » Disassemble section","id":"180","title":"Disassemble section"},"181":{"body":"nm [opts] -C demangle -u undefined only","breadcrumbs":"Binary » nm(1)","id":"181","title":"nm(1)"},"182":{"body":"c++filt c++ glibc gcc [make] (./make.md) ld.so","breadcrumbs":"Development","id":"182","title":"Development"},"183":{"body":"","breadcrumbs":"Development » c++filt(1)","id":"183","title":"c++filt(1)"},"184":{"body":"c++-filt ","breadcrumbs":"Development » Demangle symbol","id":"184","title":"Demangle symbol"},"185":{"body":"For example dynamic symbol table: readelf -W --dyn-syms | c++filt","breadcrumbs":"Development » Demangle stream","id":"185","title":"Demangle stream"},"186":{"body":"","breadcrumbs":"Development » c++","id":"186","title":"c++"},"187":{"body":"Force compile error to see what auto is deduced to. auto foo = bar(); // force compile error\ntypename decltype(foo)::_;","breadcrumbs":"Development » Type deduction","id":"187","title":"Type deduction"},"188":{"body":"","breadcrumbs":"Development » glibc","id":"188","title":"glibc"},"189":{"body":"Trace memory allocation and de-allocation to detect memory leaks. Need to call mtrace(3) to install the tracing hooks. If we can't modify the binary to call mtrace we can create a small shared library and pre-load it. // libmtrace.c\n#include \n__attribute__((constructor)) static void init_mtrace() { mtrace(); } Compile as: gcc -shared -fPIC -o libmtrace.so libmtrace.c To generate the trace file run: export MALLOC_TRACE=\nLD_PRELOAD=./libmtrace.so Note : If MALLOC_TRACE is not set mtrace won't install tracing hooks. To get the results of the trace file: mtrace $MALLOC_TRACE","breadcrumbs":"Development » malloc tracer mtrace(3)","id":"189","title":"malloc tracer mtrace(3)"},"19":{"body":"j>&i Duplicate fd i to fd j, making j a copy of i. See dup2(2) . Example: command 2>&1 >file duplicate fd 1 to fd 2, effectively redirecting stderr to stdout redirect stdout to file","breadcrumbs":"Tools » Explanation","id":"19","title":"Explanation"},"190":{"body":"Configure action when glibc detects memory error. export MALLOC_CHECK_= Useful values: 1 print detailed error & continue\n3 print detailed error + stack trace + memory mappings & abort\n7 print simple error message + stack trace + memory mappings & abort","breadcrumbs":"Development » malloc check mallopt(3)","id":"190","title":"malloc check mallopt(3)"},"191":{"body":"","breadcrumbs":"Development » gcc(1)","id":"191","title":"gcc(1)"},"192":{"body":"","breadcrumbs":"Development » CLI","id":"192","title":"CLI"},"193":{"body":"While debugging can be helpful to just pre-process files. gcc -E [-dM] ... -E run only preprocessor -dM list only #define statements","breadcrumbs":"Development » Preprocessing","id":"193","title":"Preprocessing"},"194":{"body":"","breadcrumbs":"Development » Builtins","id":"194","title":"Builtins"},"195":{"body":"Give the compiler a hint which branch is hot, so it can lay out the code accordingly to reduce number of jump instructions. See on compiler explorer . echo \"\nextern void foo();\nextern void bar();\nvoid run0(int x) { if (__builtin_expect(x,0)) { foo(); } else { bar(); }\n}\nvoid run1(int x) { if (__builtin_expect(x,1)) { foo(); } else { bar(); }\n}\n\" | gcc -O2 -S -masm=intel -o /dev/stdout -xc - Will generate something similar to the following. run0: bar is on the path without branch run1: foo is on the path without branch run0: test edi, edi jne .L4 xor eax, eax jmp bar\n.L4: xor eax, eax jmp foo\nrun1: test edi, edi je .L6 xor eax, eax jmp foo\n.L6: xor eax, eax jmp bar","breadcrumbs":"Development » __builtin_expect(expr, cond)","id":"195","title":"__builtin_expect(expr, cond)"},"196":{"body":"C ABI - SystemV ABI C++ ABI - C++ Itanium ABI","breadcrumbs":"Development » ABI (Linux)","id":"196","title":"ABI (Linux)"},"197":{"body":"","breadcrumbs":"Development » make(1)","id":"197","title":"make(1)"},"198":{"body":"target .. : prerequisite .. recipe .. target: an output generated by the rule prerequisite: an input that is used to generate the target recipe: list of actions to generate the output from the input Use make -p to print all rules and variables (implicitly + explicitly defined).","breadcrumbs":"Development » Anatomy of make rules","id":"198","title":"Anatomy of make rules"},"199":{"body":"","breadcrumbs":"Development » Pattern rules & Automatic variables","id":"199","title":"Pattern rules & Automatic variables"},"2":{"body":"","breadcrumbs":"Tools » zsh(1)","id":"2","title":"zsh(1)"},"20":{"body":"The getopts builtin uses following global variables: OPTARG, value of last option argument OPTIND, index of the next argument to process (user must reset) OPTERR, display errors if set to 1 getopts [] specifies the names of supported options, eg f:c f: means -f option with an argument c means -c option without an argument specifies a variable name which getopts fills with the last parsed option argument optionally specify argument string to parse, by default getopts parses $@","breadcrumbs":"Tools » Argument parsing with getopts","id":"20","title":"Argument parsing with getopts"},"200":{"body":"A pattern rule contains the % char (exactly one of them) and look like this example: %.o : %.c $(CC) -c $(CFLAGS) $(CPPFLAGS) $< -o $@ The target matches files of the pattern %.o, where % matches any none-empty substring and other character match just them self. The substring matched by % is called the stem. % in the prerequisite stands for the matched stem in the target.","breadcrumbs":"Development » Pattern rules","id":"200","title":"Pattern rules"},"201":{"body":"As targets and prerequisites in pattern rules can't be spelled explicitly in the recipe, make provides a set of automatic variables to work with: $@: Name of the target that triggered the rule. $<: Name of the first prerequisite. $^: Names of all prerequisites (without duplicates). $+: Names of all prerequisites (with duplicates). $*: Stem of the pattern rule. # file: Makefile all: foobar blabla foo% bla%: aaa bbb bbb @echo \"@ = $@\" @echo \"< = $<\" @echo \"^ = $^\" @echo \"+ = $+\" @echo \"* = $*\" @echo \"----\" aaa:\nbbb: Running above Makefile gives: @ = foobar\n< = aaa\n^ = aaa bbb\n+ = aaa bbb bbb\n* = bar\n----\n@ = blabla\n< = aaa\n^ = aaa bbb\n+ = aaa bbb bbb\n* = bla\n----","breadcrumbs":"Development » Automatic variables","id":"201","title":"Automatic variables"},"202":{"body":"","breadcrumbs":"Development » Useful functions","id":"202","title":"Useful functions"},"203":{"body":"Substitute strings matching pattern in a list. in := a.o l.a c.o\nout := $(in:.o=.c)\n# => out = a.c l.a c.c","breadcrumbs":"Development » Substitution references","id":"203","title":"Substitution references"},"204":{"body":"Keep strings matching a pattern in a list. in := a.a b.b c.c d.d\nout := $(filter %.b %.c, $(in))\n# => out = b.b c.c","breadcrumbs":"Development » filter","id":"204","title":"filter"},"205":{"body":"Remove strings matching a pattern from a list. in := a.a b.b c.c d.d\nout := $(filter-out %.b %.c, $(in))\n# => out = a.a d.d","breadcrumbs":"Development » filter-out","id":"205","title":"filter-out"},"206":{"body":"Resolve each file name as absolute path (don't resolve symlinks). $(abspath fname1 fname2 ..) ### `realpath`\nResolve each file name as canonical path.\n```make\n$(realpath fname1 fname2 ..)","breadcrumbs":"Development » abspath","id":"206","title":"abspath"},"207":{"body":"","breadcrumbs":"Development » ld.so(8)","id":"207","title":"ld.so(8)"},"208":{"body":"LD_PRELOAD= colon separated list of libso's to be pre loaded LD_DEBUG= comma separated list of debug options =help list available options =libs show library search path =files processing of input files =symbols show search path for symbol lookup =bindings show against which definition a symbol is bound","breadcrumbs":"Development » Environment Variables","id":"208","title":"Environment Variables"},"209":{"body":"Libraries specified in LD_PRELOAD are loaded from left-to-right but initialized from right-to-left. > ldd ./main >> libc.so.6 => /usr/lib/libc.so.6 > LD_PRELOAD=liba.so:libb.so ./main --> preloaded in this order <-- initialized in this order The preload order determines: the order libraries are inserted into the link map the initialization order for libraries For the example listed above the resulting link map will look like the following: +------+ +------+ +------+ +------+ | main | -> | liba | -> | libb | -> | libc | +------+ +------+ +------+ +------+ This can be seen when running with LD_DEBUG=files: > LD_DEBUG=files LD_PRELOAD=liba.so:libb.so ./main # load order (-> determines link map) >> file=liba.so [0]; generating link map >> file=libb.so [0]; generating link map >> file=libc.so.6 [0]; generating link map # init order >> calling init: /usr/lib/libc.so.6 >> calling init: /libb.so >> calling init: /liba.so >> initialize program: ./main To verify the link map order we let ld.so resolve the memcpy(3) libc symbol (used in main ) dynamically, while enabling LD_DEBUG=symbols,bindings to see the resolving in action. > LD_DEBUG=symbols,bindings LD_PRELOAD=liba.so:libb.so ./main >> symbol=memcpy; lookup in file=./main [0] >> symbol=memcpy; lookup in file=/liba.so [0] >> symbol=memcpy; lookup in file=/libb.so [0] >> symbol=memcpy; lookup in file=/usr/lib/libc.so.6 [0] >> binding file ./main [0] to /usr/lib/libc.so.6 [0]: normal symbol `memcpy' [GLIBC_2.14]","breadcrumbs":"Development » LD_PRELOAD: Initialization Order and Link Map","id":"209","title":"LD_PRELOAD: Initialization Order and Link Map"},"21":{"body":"#!/bin/bash\nfunction parse_args() { while getopts \"f:c\" PARAM; do case $PARAM in f) echo \"GOT -f $OPTARG\";; c) echo \"GOT -c\";; *) echo \"ERR: print usage\"; exit 1;; esac done # users responsibility to reset OPTIND OPTIND=0\n} parse_args -f xxx -c\nparse_args -f yyy","breadcrumbs":"Tools » Example","id":"21","title":"Example"},"210":{"body":"Dynamic linking basically works via one indirect jump. It uses a combination of function trampolines (.plt section) and a function pointer table (.got.plt section). On the first call the trampoline sets up some metadata and then jumps to the ld.so runtime resolve function, which in turn patches the table with the correct function pointer. .plt ....... procedure linkage table, contains function trampolines, usually located in code segment (rx permission) .got.plt ... global offset table for .plt, holds the function pointer table Using radare2 we can analyze this in more detail: [0x00401040]> pd 4 @ section..got.plt ;-- section..got.plt: ;-- .got.plt: ; [22] -rw- section size 32 named .got.plt ;-- _GLOBAL_OFFSET_TABLE_: [0] 0x00404000 .qword 0x0000000000403e10 ; section..dynamic [1] 0x00404008 .qword 0x0000000000000000 ; CODE XREF from section..plt @ +0x6 [2] 0x00404010 .qword 0x0000000000000000 ;-- reloc.puts: ; CODE XREF from sym.imp.puts @ 0x401030 [3] 0x00404018 .qword 0x0000000000401036 ; RELOC 64 puts [0x00401040]> pd 6 @ section..plt ;-- section..plt: ;-- .plt: ; [12] -r-x section size 32 named .plt ┌─> 0x00401020 ff35e22f0000 push qword [0x00404008] ╎ 0x00401026 ff25e42f0000 jmp qword [0x00404010] ╎ 0x0040102c 0f1f4000 nop dword [rax] ┌ 6: int sym.imp.puts (const char *s); └ ╎ 0x00401030 ff25e22f0000 jmp qword [reloc.puts] ╎ 0x00401036 6800000000 push 0 └─< 0x0040103b e9e0ffffff jmp sym..plt At address 0x00401030 in the .plt section we see the indirect jump for puts using the function pointer in _GLOBAL_OFFSET_TABLE_[3] (GOT). GOT[3] initially points to instruction after the puts trampoline 0x00401036. This pushes the relocation index 0 and then jumps to the first trampoline 0x00401020. The first trampoline jumps to GOT[2] which will be filled at program startup by the ld.so with its resolve function. The ld.so resolve function fixes the relocation referenced by the relocation index pushed by the puts trampoline. The relocation entry at index 0 tells the resolve function which symbol to search for and where to put the function pointer: > readelf -r >> Relocation section '.rela.plt' at offset 0x4b8 contains 1 entry: >> Offset Info Type Sym. Value Sym. Name + Addend >> 000000404018 000200000007 R_X86_64_JUMP_SLO 0000000000000000 puts@GLIBC_2.2.5 + 0 As we can see the offset from relocation at index 0 points to GOT[3].","breadcrumbs":"Development » Dynamic Linking (x86_64)","id":"210","title":"Dynamic Linking (x86_64)"},"211":{"body":"x86_64 arm64","breadcrumbs":"Arch","id":"211","title":"Arch"},"212":{"body":"keywords: x86_64, x86, abi 64bit synonyms: x86_64, x64, amd64, intel 64 32bit synonyms: x86, ia32, i386 ISA type: CISC Endianness: little","breadcrumbs":"Arch » x86_64","id":"212","title":"x86_64"},"213":{"body":"","breadcrumbs":"Arch » Registers","id":"213","title":"Registers"},"214":{"body":"bytes\n[7:0] [3:0] [1:0] [1] [0] desc\n----------------------------------------------------------\nrax eax ax ah al accumulator\nrbx ebx bx bh bl base register\nrcx ecx cx ch cl counter\nrdx edx dx dh dl data register\nrsi esi si - sil source index\nrdi edi di - dil destination index\nrbp ebp bp - bpl base pointer\nrsp esp sp - spl stack pointer\nr8-15 rNd rNw - rNb","breadcrumbs":"Arch » General purpose register","id":"214","title":"General purpose register"},"215":{"body":"bytes\n[7:0] [3:0] [1:0] desc\n---------------------------------------------------\nrflags eflags flags flags register\nrip eip ip instruction pointer","breadcrumbs":"Arch » Special register","id":"215","title":"Special register"},"216":{"body":"rflags\nbits desc\n-----------------------------\n[11] OF overflow flag\n[10] DF direction flag [7] SF sign flag [6] ZF zero flag [4] AF auxiliary carry flag [2] PF parity flag [0] CF carry flag","breadcrumbs":"Arch » FLAGS register","id":"216","title":"FLAGS register"},"217":{"body":"movw [rax], rbx // save val in rbx at [rax]\nmovw [imm], rbx // save val in rbx at [imm]\nmovw rax, [rbx+4*rcx] // load val at [rbx+4*rcx] into rax rip relative addressing: lea rax, [rip+.my_str] // load addr of .my_str into rax\n...\n.my_str:\n.asciz \"Foo\"","breadcrumbs":"Arch » Addressing","id":"217","title":"Addressing"},"218":{"body":"Explicitly specify size of the operation. mov byte ptr [rax], 0xff // save 1 byte(s) at [rax]\nmov word ptr [rax], 0xff // save 2 byte(s) at [rax]\nmov dword ptr [rax], 0xff // save 4 byte(s) at [rax]\nmov qword ptr [rax], 0xff // save 8 byte(s) at [rax]","breadcrumbs":"Arch » Size directives","id":"218","title":"Size directives"},"219":{"body":"","breadcrumbs":"Arch » SysV x86_64 ABI","id":"219","title":"SysV x86_64 ABI"},"22":{"body":"Bash supports regular expression matching with the binary operator =~. The match results can be accessed via the $BASH_REMATCH variable: ${BASH_REMATCH[0]} contains the full match ${BASH_REMATCH[1]} contains match of the first capture group INPUT='title foo : 1234'\nREGEX='^title (.+) : ([0-9]+)$'\nif [[ $INPUT =~ $REGEX ]]; then echo \"${BASH_REMATCH[0]}\" # title foo : 1234 echo \"${BASH_REMATCH[1]}\" # foo echo \"${BASH_REMATCH[2]}\" # 1234\nfi Caution : When specifying a regex in the [[ ]] block directly, quotes will be treated as part of the pattern. [[ $INPUT =~ \"foo\" ]] will match against \"foo\" not foo!","breadcrumbs":"Tools » Regular Expressions","id":"22","title":"Regular Expressions"},"220":{"body":"Integer/Pointer arguments reg arg\n-----------\nrdi 1\nrsi 2\nrdx 3\nrcx 4\nr8 5\nr9 6 Floating point arguments reg arg\n-----------\nxmm0 1 .. ..\nxmm7 8 Additional arguments are passed on the stack. Arguments are pushed right-to-left (RTL), meaning next arguments are closer to current rsp.","breadcrumbs":"Arch » Passing arguments to functions","id":"220","title":"Passing arguments to functions"},"221":{"body":"Integer/Pointer return values reg size\n-----------------\nrax 64 bit\nrax+rdx 128 bit Floating point return values: reg size\n-------------------\nxmm0 64 bit\nxmm0+xmm1 128 bit","breadcrumbs":"Arch » Return values from functions","id":"221","title":"Return values from functions"},"222":{"body":"Caller must save these registers if they should be preserved across function calls. rax rcx rdx rsi rdi rsp r8 - r11","breadcrumbs":"Arch » Caller saved registers","id":"222","title":"Caller saved registers"},"223":{"body":"Caller can expect these registers to be preserved across function calls. Callee must must save these registers in case they are used. rbx rbp r12 – r15","breadcrumbs":"Arch » Callee saved registers","id":"223","title":"Callee saved registers"},"224":{"body":"grows downwards frames aligned on 16 byte boundary Hi ADDR | +------------+ | | prev frame | | +------------+ <--- 16 byte aligned (X & ~0xf) | [rbp+8] | saved RIP | | [rbp] | saved RBP | | [rbp-8] | func stack | | | ... | v +------------+\nLo ADDR","breadcrumbs":"Arch » Stack","id":"224","title":"Stack"},"225":{"body":"prologue push rbp // save caller base pointer\nmov rbp, rsp // save caller stack pointer epilogue mov rsp, rbp // restore caller stack pointer\npop rbp // restore caller base pointer Equivalent to leave instruction.","breadcrumbs":"Arch » Function prologue & epilogue","id":"225","title":"Function prologue & epilogue"},"226":{"body":"Small assembler skeleton, ready to use with following properties: use raw Linux syscalls (man 2 syscall for ABI) no C runtime (crt) gnu assembler gas intel syntax # file: greet.s .intel_syntax noprefix .section .text, \"ax\", @progbits .global _start\n_start: mov rdi, 1 # fd lea rsi, [rip + greeting] # buf mov rdx, [rip + greeting_len] # count mov rax, 1 # write(2) syscall nr syscall mov rdi, 0 # exit code mov rax, 60 # exit(2) syscall nr syscall .section .rdonly, \"a\", @progbits\ngreeting: .asciz \"Hi ASM-World!\\n\"\ngreeting_len: .int .-greeting Syscall numbers are defined in /usr/include/asm/unistd.h. To compile and run: > gcc -o greet greet.s -nostartfiles -nostdlib && ./greet\nHi ASM-World!","breadcrumbs":"Arch » ASM skeleton","id":"226","title":"ASM skeleton"},"227":{"body":"SystemV AMD64 ABI AMD64 Vol1: Application Programming AMD64 Vol2: System Programming AMD64 Vol3: General-Purpose & System Instructions X86_64 Cheat-Sheet Intel 64 Vol1: Basic Architecture Intel 64 Vol2: Instruction Set Reference Intel 64 Vol3: System Programming Guide GNU Assembler GNU Assembler Directives","breadcrumbs":"Arch » References","id":"227","title":"References"},"228":{"body":"keywords: arm64, aarch64, abi 64bit synonyms: arm64, aarch64 ISA type: RISC Endianness: little, big","breadcrumbs":"Arch » arm64","id":"228","title":"arm64"},"229":{"body":"","breadcrumbs":"Arch » Registers","id":"229","title":"Registers"},"23":{"body":"The complete builtin is used to interact with the completion system. complete # print currently installed completion handler\ncomplete -F # install as completion handler for \ncomplete -r # uninstall completion handler for Variables available in completion functions: # in\n$1 # \n$2 # current word\n$3 # privous word COMP_WORDS # array with current command line words\nCOMP_CWORD # index into COMP_WORDS with current cursor position # out\nCOMPREPLY # array with possible completions The compgen builtin is used to generate possible matches by comparing word against words generated by option. compgen