在 Debian(或任何 Linux)系统里,strings 命令通常用于从一个二进制文件、库或内存转储中提取可打印字符串。结合脚本使用,可以自动化分析、过滤、统计或监控这些信息。
下面从 基础用法 → 脚本结合方式 → 实用示例 逐步说明。
strings /bin/ls
常用参数:
-n <长度>:只显示长度≥n的字符串-e <编码>:指定编码(如 s=7-bit, l=16-bit little endian)-a:扫描整个文件(不仅是可加载段)示例:
strings -n 6 /usr/bin/curl
STR=$(strings /bin/ls)
echo "$STR"
strings file.bin | grep "password"
for f in /bin/*; do
echo "=== $f ==="
strings "$f" | head -n 5
done
#!/bin/bash
# scan.sh
TARGET=$1
KEYWORDS=("password" "token" "secret" "api_key")
for kw in "${KEYWORDS[@]}"; do
echo "== 搜索: $kw =="
strings -n 6 "$TARGET" | grep -i "$kw"
done
使用:
./scan.sh /usr/bin/someapp
#!/bin/bash
# batch_strings.sh
DIR=$1
OUT=strings_report.txt
> "$OUT"
for f in "$DIR"/*; do
if file "$f" | grep -q "ELF"; then
echo "=== $f ===" >> "$OUT"
strings -n 8 "$f" >> "$OUT"
fi
done
#!/bin/bash
file=$1
count=$(strings "$file" | wc -l)
echo "$file 包含 $count 个可打印字符串"
strings /lib/x86_64-linux-gnu/libc.so.6 | grep -i "glibc"
脚本化:
for lib in /lib/x86_64-linux-gnu/*.so*; do
ver=$(strings "$lib" | grep -i "version" | head -n1)
echo "$lib: $ver"
done
strings app | grep "http" | awk '{print $1}'
find . -type f -executable | xargs -I{} sh -c 'echo {}; strings {} | grep -i error'
which strings
# 若没有
sudo apt update
sudo apt install binutils
如果你有具体场景(例如:分析某个程序、做安全扫描、从 core dump 提取信息),可以告诉我,我可以给你更针对性的脚本。