Parse PLT stub addresses and names

Viewed 456

I want to parse ELF file from C/C++, which contains .plt section and get PLT functions stub addresses and names, similar output as "objdump -D -j .plt a.out"

enter image description here

I can get .PLT section address from a file, but how to parse it? what kind of structure is there? how to find names? etc.

1 Answers

Each entry of .plt corresponds to an entry in .rela.plt. When you see pushq $0x0 in your screenshot above, that is referring to .rela.plt entry 0.

Here is an example on a binary I have sitting around:

$ objdump --section=.plt -C -d -r -M intel /tmp/upb_binary_stripped | head -20

/tmp/upb_binary_stripped:     file format elf64-x86-64


Disassembly of section .plt:

0000000000001010 <.plt>:
    1010:       ff 35 f2 6f 00 00       push   QWORD PTR [rip+0x6ff2]        # 8008 <_GLOBAL_OFFSET_TABLE_+0x8>
    1016:       ff 25 f4 6f 00 00       jmp    QWORD PTR [rip+0x6ff4]        # 8010 <_GLOBAL_OFFSET_TABLE_+0x10>
    101c:       0f 1f 40 00             nop    DWORD PTR [rax+0x0]

0000000000001020 <longjmp@plt>:
    1020:       ff 25 f2 6f 00 00       jmp    QWORD PTR [rip+0x6ff2]        # 8018 <longjmp>
    1026:       68 00 00 00 00          push   0x0
    102b:       e9 e0 ff ff ff          jmp    1010 <.plt>

0000000000001030 <setjmp@plt>:
    1030:       ff 25 ea 6f 00 00       jmp    QWORD PTR [rip+0x6fea]        # 8020 <setjmp>
    1036:       68 01 00 00 00          push   0x1
    103b:       e9 d0 ff ff ff          jmp    1010 <.plt>

Now if I dump the relocations in .rela.plt you can see the entries for longjmp and setjmp, corresponding to the numbers in the PLT:

$ readelf -r /tmp/upb_binary_stripped
[...]
Relocation section '.rela.plt' at offset 0x618 contains 10 entries:
  Offset          Info           Type           Sym. Value    Sym. Name + Addend
000000008018  000100000007 R_X86_64_JUMP_SLO 0000000000000000 longjmp + 0
000000008020  000200000007 R_X86_64_JUMP_SLO 0000000000000000 setjmp + 0
[...]

The Rela entries are read in the normal way, using Elf64_Rela and ELF64_R_SYM(rela.r_info) to get the symbol name from the linked section (which should be .dynsym).

Related