Secure Coding mailing list archives
Source or Binary
From: Paco at cigital.com (Paco Hope)
Date: Thu, 30 Jul 2009 10:08:37 -0400
On 7/29/09 8:08 PM, "silky" <michaelslists at gmail.com> wrote:
Of course it's a binary, it "runs by itself", when there is a java vm to run it. Just like you need a win32 vm to run a typical .exe.
You misunderstand the notion of virtual machines if you think of Win32 as a virtual machine. There is nothing "virtual" about windows. It runs on the real hardware (ignoring things like VMWare). Your Windows EXEs (except those running in the .NET CLR) also run on the real x86 hardware. I.e., your variables are loaded into CPU registers and operated on, etc. The Java Virtual Machine is a theoretical machine, and Java code is compiled down to Java bytecode that runs on this theoretical machine. The Java VM is the actual Windows EXE that runs on the real hardware. It reads these bytecodes and executes them. There is a very significant level of abstraction between a Java program running in a Java virtual machine and native code that has been compiled to a native object format (e.g., an .exe).
Realizing that java "binaries" hold a lot more is a mental shift that probably must be actively kept in mind.Hold a lot more what? This doesn't make sense.
It makes a lot of sense. Because Java is a string-based language, a great deal of symbolic information (e.g., class names, method names, inheritance hierarchies) remains in the class file, literally in string format, after you compile. If you're in the C++ world and you compile and then strip your binaries, that symbolic information is reduced a lot. If you use a java decompiler (e.g., jad, jode, etc.), you can get .java files from .class files and they are remarkably usable. While C++ decompilation is possible, the fidelity of decompiled Java programs is significantly higher. I.e., they match their original source, sometimes in astonishing accuracy. Take a look at java decompilation and compare it to what you know about native code decompilation. It is absolutely true that (ignoring anti-reversing techniques like obfuscation), Java binaries carry a lot more usable information to help in the dissection and understanding of their execution than an equivalent native-code program would. Paco -- Paco Hope, CISSP, CSSLP Technical Manager, Cigital, Inc http://www.cigital.com/ ? +1.703.585.7868 Software Confidence. Achieved.
Current thread:
- IBM Acquires Ounce Labs, Inc., (continued)
- IBM Acquires Ounce Labs, Inc. Prasad Shenoy (Jul 28)
- IBM Acquires Ounce Labs, Inc. Matt Fisher (Jul 28)
- IBM Acquires Ounce Labs, Inc. Tom Brennan (Jul 28)
- IBM Acquires Ounce Labs, Inc. Arian J. Evans (Jul 28)
- IBM Acquires Ounce Labs, Inc. Jim Manico (Jul 28)
- IBM Acquires Ounce Labs, Inc. ljknews (Jul 28)
- IBM Acquires Ounce Labs, Inc. John Steven (Jul 29)
- Source or Binary Brad Andrews (Jul 29)
- Source or Binary Kenneth Van Wyk (Jul 29)
- Source or Binary silky (Jul 29)
- Source or Binary Paco Hope (Jul 30)
- Source or Binary Wall, Kevin (Jul 30)
- Static Vs. Binary John Steven (Jul 30)
- Static Vs. Binary Pravir Chandra (Jul 30)
- Static Vs. Binary Kenneth Van Wyk (Jul 30)
- Static Vs. Binary John Steven (Aug 04)
- IBM Acquires Ounce Labs, Inc. Arian J. Evans (Aug 04)
- IBM Acquires Ounce Labs, Inc. Chris Wysopal (Aug 04)
- IBM Acquires Ounce Labs, Inc. Arian J. Evans (Aug 04)
- IBM Acquires Ounce Labs, Inc. Wall, Kevin (Aug 04)
- IBM Acquires Ounce Labs, Inc. Arian J. Evans (Aug 04)
