Linux objdump Command

Linux 命令大全Linux Command Encyclopedia


objdump is an important command-line tool in the GNU Binutils toolset, used to display various information about object files and executable files. It is a powerful tool for binary analysis, reverse engineering, and debugging on Linux systems.

The main functions of objdump include:

  • Disassemble binary files
  • View file header information
  • Display section contents
  • View the symbol table
  • Display relocation information
  • Analyze file structure

Basic Syntax

The basic command format of objdump is as follows:

objdump [选项] 文件名

If no options are specified, objdump displays the section header information of the file.


Detailed Explanation of Common Options

Disassembly-Related Options

Example

-d, --disassemble        # Disassemble sections containing code
-D, --disassemble-all    # Disassemble all sections
-S, --source             # Mixed display of source code and assembly code (requires -g option at compile time)
--prefix-addresses       # Display full addresses during disassembly
--no-addresses           # Do not display address information

Section Information Options

Example

-h, --section-headers    # Display section header information
-j, --section=name# Display only the contents of the specified section

Symbol Table Options

Example

-t, --syms               # Display the symbol table
-T, --dynamic-syms       # Display the dynamic symbol table

File Header Information

-f, --file-headers       # 显示文件头部信息

Other Useful Options

Example

-l, --line-numbers       # Display line number information (requires debug information)
-r, --reloc              # Display relocation entries
-R, --dynamic-reloc      # Display dynamic relocation entries
-s, --full-contents      # Display the complete contents of all sections

Practical Examples

Example 1: Viewing the Structure of an Executable File

objdump -h /bin/ls

Sample output:

/bin/ls:     file format elf64-x86-64

Sections:
Idx Name          Size      VMA               LMA               File off  Algn
  0 .interp       0000001c  0000000000400238  0000000000400238  00000238  2**0
                  CONTENTS, ALLOC, LOAD, READONLY, DATA
  1 .note.ABI-tag 00000020  0000000000400254  0000000000400254  00000254  2**2
                  CONTENTS, ALLOC, LOAD, READONLY, DATA
  ...

Example 2: Disassembling an Executable File

objdump -d /bin/ls

Sample output (partial):

0000000000405a50 :
  405a50:       31 ed                   xor    %ebp,%ebp
  405a52:       49 89 d1                mov    %rdx,%r9
  405a55:       5e                      pop    %rsi
  405a56:       48 89 e2                mov    %rsp,%rdx
  405a59:       48 83 e4 f0             and    $0xfffffffffffffff0,%rsp
  ...

Example 3: Viewing the Symbol Table

objdump -t myprogram.o

Sample output:

myprogram.o:     file format elf64-x86-64

SYMBOL TABLE:
0000000000000000 l    df *ABS*  0000000000000000 myprogram.c
0000000000000000 l    d  .text  0000000000000000 .text
0000000000000000 g     F .text  0000000000000015 main
0000000000000000         *UND*  0000000000000000 printf

Example 4: Mixed Display of Source Code and Assembly Code

objdump -S myprogram

Sample output:

Example

int main() {
  400526:       55                      push   %rbp
  400527:       48 89 e5                mov    %rsp,%rbp
    printf("Hello, World!n");
  40052a:       bf d4 05 40 00          mov    $0x4005d4,%edi
  40052f:       e8 cc fe ff ff          callq  400400
    return 0;
  400534:       b8 00 00 00 00          mov    $0x0,%eax
}

Practical Application Scenarios

Scenario 1: Debugging Program Crashes

When a program crashes, you can use objdump to view the code near the crash address:

objdump -d --start-address=0x400526 --stop-address=0x400536 myprogram

Scenario 2: Analyzing Library Function Calls

View which dynamic library functions the program calls:

objdump -T myprogram | grep UND

Scenario 3: Learning Assembly Language

Learn assembly language by disassembling simple C programs:

Example

gcc -o simple simple.c
objdump -d simple

Notes

  1. Debug information: To obtain source-level information, you need to add-goption
  2. Optimization impact: Compiler optimization affects the generated assembly code; be careful when analyzing
  3. Architecture differences: Different CPU architectures have different assembly instructions; make sure to use the correct disassembly options
  4. Permission issues: Analyzing system files may require root privileges
  5. File format: objdump is mainly for ELF-format files; other formats may require special handling

Advanced Tips

Using with Other Tools

Example

# Use grep to filter specific functions
objdump -d myprogram | grep -A20 "main>:"

# Calculate function sizes
objdump -d myprogram | awk '/^[0-9a-f]+ :/ {print $1,$2}'

Creating a Disassembly Script

Example

#!/bin/bash
# Disassembly script example
if [ $# -ne 1 ]; then
    echo "Usage: $0 "
    exit 1
fi

echo "=== File Header Information ==="
objdump -f $1

echo -e "n=== Section Information ==="
objdump -h $1

echo -e "n=== Disassembly Code ==="
objdump -d $1

Summary

objdump is a powerful binary analysis tool on Linux systems. Mastering it allows you to:

  • Deeply understand program execution mechanisms
  • Quickly locate program issues
  • Learn assembly language and system knowledge
  • Perform basic reverse engineering analysis

With the basic usage and practical examples introduced in this article, you should already be able to start using objdump for basic binary file analysis. As you accumulate practical experience, you will discover more of its clever uses in system programming and debugging.


Linux 命令大全Linux Command Encyclopedia

Other Extensions