在 Linux 下,strings 是一个从二进制文件、core 文件、内存映像中提取可打印字符串的工具,常用于排错、逆向、取证、调试。下面按“常见错误场景 → 用法 → 实战示例”来说明。
strings 能帮你排错什么?✅ 常见用途:
❌ 不适合:
strings 文件名
示例:
strings ./myapp
strings myapp | grep -i config
可能看到:
/etc/myapp/config.yaml
./config.json
MYAPP_CONFIG
✅ 线索:程序可能在找这些文件
strings myapp | grep -E "http|://|[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+"
示例输出:
http://127.0.0.1:8080/api
redis://10.0.0.5:6379
✅ 用于排查网络问题
strings myapp | grep -i "error\|fail\|exception"
例如:
failed to open file
segmentation fault at
invalid token
✅ 对应代码中的提示信息
strings core.12345 | less
或结合 gdb:
gdb ./myapp core.12345
strings 可快速看崩溃前后残留字符串
strings myapp | grep -i version
v1.2.3
GCC: (Ubuntu 9.4.0)
Build time: 2024-01-01
strings myapp | grep "\.so"
libssl.so.1.1
libcrypto.so.1.1
✅ 缺库时很有用
strings -a -t x myapp
-t x:十六进制偏移-a:扫描整个文件(不只是数据段)strings -n 6 myapp
✅ 过滤短噪声
strings -e l myapp
l:16-bit little endianb:16-bit big endianstrings /proc/<pid>/mem
⚠️ 需要权限(root)
strings myapp | grep -i error | less
strings myapp | grep -A2 -B2 "config"
objdump -s myapp | strings
“程序不说话,strings 帮它说话”
排错流程:
strings 看硬编码信息如果你有具体报错场景(比如某个程序崩溃、起不来、连不上服务),可以把现象发我,我可以直接帮你写 strings 排查命令。