GDB DEBUGGER
STARTING GDB#
gdb program # Start debugging program gdb program core # Debug with core dump gdb -p PID # Attach to running process gdb --args program arg1 arg2 # Debug with arguments gdb -q program # Quiet mode (no banner) gdb -tui program # Text user interface mode
RUNNING PROGRAMS#
run # Run program (r) run arg1 arg2 # Run with arguments start # Run and stop at main() continue # Continue execution (c) next # Step over (n) step # Step into (s) finish # Run until function returns until # Run until line until location # Run until location advance location # Continue to location
BREAKPOINTS#
break main # Break at main (b) break function # Break at function break file.c:10 # Break at line 10 break *0x400500 # Break at address break if condition # Conditional breakpoint break function if x > 5 # Break when condition met tbreak location # Temporary breakpoint rbreak regex # Break on regex match
BREAKPOINT MANAGEMENT#
info breakpoints # List breakpoints (i b) delete # Delete all breakpoints delete 1 # Delete breakpoint 1 disable 1 # Disable breakpoint 1 enable 1 # Enable breakpoint 1 clear function # Clear breakpoint at function clear file.c:10 # Clear breakpoint at line
WATCHPOINTS#
watch variable # Break when variable changes watch *0x600a00 # Watch memory address rwatch variable # Break on read awatch variable # Break on read/write info watchpoints # List watchpoints
EXAMINING DATA#
print variable # Print variable (p) print *pointer # Dereference pointer print array[0]@10 # Print 10 array elements print /x variable # Print in hex print /t variable # Print in binary print /d variable # Print as signed decimal print /u variable # Print as unsigned print /c variable # Print as character print /f variable # Print as float print /a address # Print as address print sizeof(type) # Print size of type
DISPLAY (AUTO-PRINT)#
display variable # Auto-print on each stop display /x variable # Auto-print in hex undisplay 1 # Remove display 1 info display # List displays
EXAMINING MEMORY#
x/nfu address # Examine memory
# n=count, f=format, u=unit
# Format specifiers
x/x hexadecimal x/d decimal
x/u unsigned decimal x/o octal
x/t binary x/a address
x/c character x/s string
x/i instruction
# Unit specifiers
x/b byte x/h halfword (2 bytes)
x/w word (4 bytes) x/g giant (8 bytes)
# Examples
x/10x $rsp # 10 hex words at stack pointer
x/20i $rip # 20 instructions at IP
x/s 0x400500 # String at address
x/10gx $rsp # 10 giant (8-byte) hex values
STACK FRAMES#
backtrace # Show call stack (bt) backtrace full # Stack with local variables frame 2 # Select frame 2 (f) up # Move up one frame down # Move down one frame info frame # Current frame info info locals # Local variables info args # Function arguments
REGISTERS#
info registers # All registers (i r) info registers rax rbx # Specific registers print $rax # Print register value print /x $rsp # Stack pointer in hex set $rax = 0 # Set register value # Common x86-64 registers $rax, $rbx, $rcx, $rdx # General purpose $rsi, $rdi # Source/Destination index $rbp, $rsp # Base/Stack pointer $rip # Instruction pointer $eflags # Flags register
MODIFYING DATA#
set variable = value # Set variable value
set var x = 10 # Set x to 10
set {int}0x600a00 = 42 # Set memory at address
set $rax = 0xff # Set register
SOURCE CODE#
list # List source (l) list 10 # List around line 10 list function # List function list file.c:10 # List file at line list - # List previous set listsize 20 # Set lines to show
DISASSEMBLY#
disassemble # Disassemble current function disassemble main # Disassemble main disassemble /r main # With raw bytes disassemble /m main # Mixed source/asm disassemble 0x400500,0x400550 # Address range set disassembly-flavor intel # Intel syntax set disassembly-flavor att # AT&T syntax (default)
THREADS#
info threads # List threads thread 2 # Switch to thread 2 thread apply all bt # Backtrace all threads thread apply 1-3 command # Apply to threads 1-3
PROCESS CONTROL#
attach PID # Attach to process detach # Detach from process kill # Kill program signal SIGINT # Send signal handle SIGALRM nostop # Don't stop on SIGALRM
REVERSE DEBUGGING#
record # Start recording record stop # Stop recording reverse-next # Reverse step over reverse-step # Reverse step into reverse-continue # Reverse continue reverse-finish # Reverse finish
SCRIPTING#
source script.gdb # Run GDB script
define mycommand # Define custom command
print $rax
info registers
end
set logging on # Log output
set logging file gdb.log # Set log file
TUI MODE#
tui enable # Enable TUI tui disable # Disable TUI layout src # Source layout layout asm # Assembly layout layout split # Source + assembly layout regs # Add registers focus cmd # Focus command window focus src # Focus source window refresh # Refresh display Ctrl+x a # Toggle TUI mode Ctrl+x 2 # Toggle second window Ctrl+L # Refresh screen
USEFUL COMMANDS#
info functions # List all functions info variables # List global variables info types # List all types info sharedlibrary # List shared libraries info files # List loaded files whatis variable # Show variable type ptype struct # Show struct definition show convenience # Show convenience variables
GDB INIT FILE (~/.gdbinit)#
set disassembly-flavor intel set pagination off set confirm off set history save on set history filename ~/.gdb_history set print pretty on
EXPLOIT DEVELOPMENT#
# Find offset for buffer overflow pattern create 200 # Create pattern (pwndbg/gef) pattern offset 0x41414141 # Find offset # Check protections checksec # Check security (pwndbg/gef) # Common exploit helpers (with pwndbg/gef) vmmap # Memory mappings heap # Heap information canary # Show canary value got # GOT entries plt # PLT entries
COMMON SHORTCUTS#
Enter # Repeat last command Ctrl+C # Interrupt execution Ctrl+L # Clear screen Ctrl+D # Quit GDB
GDB DEBUGGER CHEATSHEET
=======================
Source: https://cheatsheet.johlem.net
STARTING GDB
------------
gdb program # Start debugging program
gdb program core # Debug with core dump
gdb -p PID # Attach to running process
gdb --args program arg1 arg2 # Debug with arguments
gdb -q program # Quiet mode (no banner)
gdb -tui program # Text user interface mode
RUNNING PROGRAMS
----------------
run # Run program (r)
run arg1 arg2 # Run with arguments
start # Run and stop at main()
continue # Continue execution (c)
next # Step over (n)
step # Step into (s)
finish # Run until function returns
until # Run until line
until location # Run until location
advance location # Continue to location
BREAKPOINTS
-----------
break main # Break at main (b)
break function # Break at function
break file.c:10 # Break at line 10
break *0x400500 # Break at address
break if condition # Conditional breakpoint
break function if x > 5 # Break when condition met
tbreak location # Temporary breakpoint
rbreak regex # Break on regex match
BREAKPOINT MANAGEMENT
---------------------
info breakpoints # List breakpoints (i b)
delete # Delete all breakpoints
delete 1 # Delete breakpoint 1
disable 1 # Disable breakpoint 1
enable 1 # Enable breakpoint 1
clear function # Clear breakpoint at function
clear file.c:10 # Clear breakpoint at line
WATCHPOINTS
-----------
watch variable # Break when variable changes
watch *0x600a00 # Watch memory address
rwatch variable # Break on read
awatch variable # Break on read/write
info watchpoints # List watchpoints
EXAMINING DATA
--------------
print variable # Print variable (p)
print *pointer # Dereference pointer
print array[0]@10 # Print 10 array elements
print /x variable # Print in hex
print /t variable # Print in binary
print /d variable # Print as signed decimal
print /u variable # Print as unsigned
print /c variable # Print as character
print /f variable # Print as float
print /a address # Print as address
print sizeof(type) # Print size of type
DISPLAY (AUTO-PRINT)
--------------------
display variable # Auto-print on each stop
display /x variable # Auto-print in hex
undisplay 1 # Remove display 1
info display # List displays
EXAMINING MEMORY
----------------
x/nfu address # Examine memory
# n=count, f=format, u=unit
# Format specifiers
x/x hexadecimal x/d decimal
x/u unsigned decimal x/o octal
x/t binary x/a address
x/c character x/s string
x/i instruction
# Unit specifiers
x/b byte x/h halfword (2 bytes)
x/w word (4 bytes) x/g giant (8 bytes)
# Examples
x/10x $rsp # 10 hex words at stack pointer
x/20i $rip # 20 instructions at IP
x/s 0x400500 # String at address
x/10gx $rsp # 10 giant (8-byte) hex values
STACK FRAMES
------------
backtrace # Show call stack (bt)
backtrace full # Stack with local variables
frame 2 # Select frame 2 (f)
up # Move up one frame
down # Move down one frame
info frame # Current frame info
info locals # Local variables
info args # Function arguments
REGISTERS
---------
info registers # All registers (i r)
info registers rax rbx # Specific registers
print $rax # Print register value
print /x $rsp # Stack pointer in hex
set $rax = 0 # Set register value
# Common x86-64 registers
$rax, $rbx, $rcx, $rdx # General purpose
$rsi, $rdi # Source/Destination index
$rbp, $rsp # Base/Stack pointer
$rip # Instruction pointer
$eflags # Flags register
MODIFYING DATA
--------------
set variable = value # Set variable value
set var x = 10 # Set x to 10
set {int}0x600a00 = 42 # Set memory at address
set $rax = 0xff # Set register
SOURCE CODE
-----------
list # List source (l)
list 10 # List around line 10
list function # List function
list file.c:10 # List file at line
list - # List previous
set listsize 20 # Set lines to show
DISASSEMBLY
-----------
disassemble # Disassemble current function
disassemble main # Disassemble main
disassemble /r main # With raw bytes
disassemble /m main # Mixed source/asm
disassemble 0x400500,0x400550 # Address range
set disassembly-flavor intel # Intel syntax
set disassembly-flavor att # AT&T syntax (default)
THREADS
-------
info threads # List threads
thread 2 # Switch to thread 2
thread apply all bt # Backtrace all threads
thread apply 1-3 command # Apply to threads 1-3
PROCESS CONTROL
---------------
attach PID # Attach to process
detach # Detach from process
kill # Kill program
signal SIGINT # Send signal
handle SIGALRM nostop # Don't stop on SIGALRM
REVERSE DEBUGGING
-----------------
record # Start recording
record stop # Stop recording
reverse-next # Reverse step over
reverse-step # Reverse step into
reverse-continue # Reverse continue
reverse-finish # Reverse finish
SCRIPTING
---------
source script.gdb # Run GDB script
define mycommand # Define custom command
print $rax
info registers
end
set logging on # Log output
set logging file gdb.log # Set log file
TUI MODE
--------
tui enable # Enable TUI
tui disable # Disable TUI
layout src # Source layout
layout asm # Assembly layout
layout split # Source + assembly
layout regs # Add registers
focus cmd # Focus command window
focus src # Focus source window
refresh # Refresh display
Ctrl+x a # Toggle TUI mode
Ctrl+x 2 # Toggle second window
Ctrl+L # Refresh screen
USEFUL COMMANDS
---------------
info functions # List all functions
info variables # List global variables
info types # List all types
info sharedlibrary # List shared libraries
info files # List loaded files
whatis variable # Show variable type
ptype struct # Show struct definition
show convenience # Show convenience variables
GDB INIT FILE (~/.gdbinit)
--------------------------
set disassembly-flavor intel
set pagination off
set confirm off
set history save on
set history filename ~/.gdb_history
set print pretty on
EXPLOIT DEVELOPMENT
-------------------
# Find offset for buffer overflow
pattern create 200 # Create pattern (pwndbg/gef)
pattern offset 0x41414141 # Find offset
# Check protections
checksec # Check security (pwndbg/gef)
# Common exploit helpers (with pwndbg/gef)
vmmap # Memory mappings
heap # Heap information
canary # Show canary value
got # GOT entries
plt # PLT entries
COMMON SHORTCUTS
----------------
Enter # Repeat last command
Ctrl+C # Interrupt execution
Ctrl+L # Clear screen
Ctrl+D # Quit GDB
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.