Microcontroller reverse engineer
Microcontroller reverse engineer
Everything they make, We can break! 
  HOME COMPANY PCB COPY MCU HACK FAQ CONTACT US
Disassembler Software   
WHY US ?
World first mcu hack company
In business since 1998
Reversed tens of thousands of chips
Copied thousands of pcbs
Foreseen all pertential problems
Integrity with payments
crack ic
 
 
Introduction to Reverse Engineering Software

Chapter 5. Determining Interesting Functions

Reconstructing Functions & Control Flow

A deep dive into identifying functions, reading assembly, and understanding compiler‑generated code.

Using objdump

The objdump tool is invaluable for disassembly, especially with the -d flag. Without symbols, the output is more cryptic, but still readable. The -j option lets you specify a particular section—most often we target .text, which holds all executable code.

In the disassembly listing, the leftmost column shows hexadecimal addresses—these are the actual runtime memory locations of each instruction. The middle column gives the raw machine code (bytes), and the right column shows the human‑readable mnemonics.

Additionally, objdump -T displays all dynamically linked library functions that the program calls, which can serve as a useful cross‑reference.

The disasm.pl Script

Steve Barker originally wrote a Perl script that post‑processes objdump output to make it far more legible when symbols are missing. Later enhancements added multi‑pass analysis:

  • Pass 1 – builds a symbol table of all called and jumped‑to addresses.
  • Pass 2 – identifies regions between two ret instructions and labels them as potential “unused” functions (though they may still be invoked indirectly via function pointers).
  • Pass 3 – prints the annotated disassembly and generates a function call tree.

Usage is straightforward:

./disasm /path/to/binary > binary.asminfo

An optional --graph flag produces a file named call_graph in a format suitable for the Graphviz dot tool, allowing you to visualise the call hierarchy.

💡 Note: A function marked “unused” simply means it was never directly called; indirect calls (e.g., through function pointers or as a startup entry) are still possible.

Defining Your Objective

Before diving into the code, you must know what you are looking for. “Interesting” functions depend entirely on your goal:

  • Are you investigating copy protection? When does it appear during execution?
  • Are you auditing for security vulnerabilities? Look for sloppy string handling (strcmp, sprintf, etc.) or unsafe memory allocations.
  • Are you trying to understand network behaviour? Trace functions that invoke socket APIs.

Narrowing your search to a handful of relevant functions makes the work manageable.

Locating main()

Even without symbols, finding the entry point is often possible. Under Linux, execution starts at the _start symbol provided by the C runtime (crt0). From there, control passes to __libc_start_main, which initialises each library (calling its _init and any global constructors). Eventually, main is invoked indirectly via a call through the base pointer (ebp).

Practical techniques to pinpoint main:

  • Use ltrace -i to trace library calls with instruction pointers; then cross‑reference those addresses with your disassembly and call tree. You may need to force the program to exit early to avoid deep call stacks.
  • Preload a custom shared library (using LD_PRELOAD) that contains a constructor function; set a breakpoint on a common libc function and step until you recognise the entry of main.
  • Set a breakpoint on __libc_start_main itself (since it is a libc symbol always available), then single‑step until you reach what looks like typical main prologue code.

Even without a frame pointer, you can often obtain an address early in the execution chain that is close enough to main for further analysis.

Finding Other Interesting Functions

Several strategies help you zero in on specific functions:

  • List all functions that call exit – they may represent error or termination paths.
  • Look for functions that reference GUI construction widgets (e.g., dialog boxes for serial numbers).
  • Search for string references – for example, if the program prints “Already registered.”, find which function contains that string.
  • Run the program under a debugger, interrupt it when an interesting operation starts, and use stepi to slow down execution. Alternatively, set a breakpoint on a frequently called function and use continue N to skip until you reach the desired point.
  • Identify functions that invoke BSD socket layer calls – useful for network‑related targets.

Mapping Program Flow

Once you have a list of candidate functions, plot the execution paths from main down to your functions of interest. The disasm.pl script with --graph can generate a call_graph file that you feed into Graphviz’s dot to produce a visual call graph – this is especially enlightening for small to medium‑sized programs.


Understanding Assembly Language

Since most reverse engineering tools emit AT&T syntax (which differs from Intel/MASM style), familiarity with that syntax is essential. Assembly is one level above machine code; to read it, you must understand the underlying hardware.

CPU Registers

The x86 architecture provides a small set of general‑purpose registers:

  • EAX, EBX, ECX, EDX – the four primary integer registers. Each can be accessed as 32‑bit (%eax), 16‑bit (%ax), or as two 8‑bit halves (%al/%ah).
  • ESI, EDI – originally used for string operations, but now often used as general‑purpose registers.
  • ESP – the stack pointer, which points to the top of the stack.
  • EBP – the base pointer (frame pointer), used to reference function parameters and local variables. It can be omitted with -fomit-frame-pointer to free up an extra register.
  • EIP – the instruction pointer, which holds the address of the next instruction to execute; it cannot be modified directly except via jumps and calls.

The Stack

The stack is a Last‑In‑First‑Out (LIFO) memory region that exists for the entire lifetime of a process. It stores local variables, function arguments, return addresses, and saved frame pointers.

On x86, the stack grows downward – pushing a value decrements ESP by the size of the value; popping increments it. Although the stack grows downward, memory addressing within the stack is still upward (e.g., an array char b[4] at ESP=80 has b[0] at 80, b[1] at 81, etc.).

Two primary instructions manipulate the stack:

  • push – places a value onto the stack and decrements ESP.
  • pop – removes the top value and increments ESP.

pusha and popa operate on all registers at once. Arithmetic operations (like add or sub) can also adjust ESP directly to reserve or release stack space.

Function Prologue and Epilogue (GCC style)

Before a function call, arguments are pushed in reverse order. The call instruction pushes the return address (the next EIP) and jumps to the target function.

Inside the callee, a typical prologue does:

push %ebp
    mov %esp, %ebp
    sub $N, %esp      ; allocate space for local variables (N bytes)

This sets up EBP as a fixed reference: parameters are at positive offsets from EBP, locals at negative offsets. The epilogue reverses this:

mov %ebp, %esp
    pop %ebp
    ret

If -fomit-frame-pointer is used, EBP becomes free and ESP is used directly for both parameters and locals, making debugging less straightforward.

Two’s Complement Representation

Most modern systems represent signed integers in two’s complement form. This has several benefits: addition works identically for positive and negative numbers, negation is easy, and the most significant bit indicates sign (0 = positive, 1 = negative).

To negate a number, invert all bits and add one. For example, –13 (binary 0000 1101) becomes 1111 0011.

In disassembly, you often see constants like 0xfffffff8. This is actually –8 in two’s complement, and it is used to decrement the stack pointer (e.g., add $0xfffffff8, %esp effectively subtracts 8).

Byte Ordering (Endianness)

Different architectures store multi‑byte values in different orders:

  • Little‑endian (x86) – least significant byte first.
  • Big‑endian (SPARC, PowerPC) – most significant byte first.

For example, the 32‑bit value 0x075bcd15 stored at address 0xbffff234 appears as bytes 15 cd 5b 07 on little‑endian, but as 07 5b cd 15 on big‑endian. This affects how you interpret memory dumps and cross‑platform network data (network byte order is big‑endian).

Reading Assembly Efficiently

A disciplined approach is to keep a paper record:

  • Draw a table for registers (EAX, EBX, ECX, EDX, ESI, EDI) and update it with each instruction.
  • Maintain a stack diagram with ESP and EBP positions, noting each push/pop and stack‑relative access.

AT&T Syntax Basics – instructions follow the form mnemonic src, dest. Constants are prefixed with $, registers with %, and hexadecimal numbers use 0x prefix. Memory references use disp(%base, %index, scale) where the effective address is disp + %base + %index * scale. Any component may be omitted.

The Intel instruction set is well documented; the key difference is that Intel syntax uses mnemonic dest, src. The actual mnemonics are mostly the same.

Recognising Compiler‑Generated Constructs

To become fluent in assembly, you must learn to identify common high‑level structures:

  • Function calls – arguments pushed, then call; return value in %eax.
  • if statements – a test followed by a conditional jump; often the jump condition is the negation of the original condition.
  • if..else – conditional jump over one block, then an unconditional jump to skip the else block.
  • while loops – a conditional jump at the top, and an unconditional jump back to the top at the bottom.
  • for loops – similar to while, with initialisation and increment instructions placed accordingly.
  • do..while – the condition check is at the bottom, so the loop body executes at least once.
  • Arrays on the stack – accessed via base + index * scale addressing. For multi‑dimensional arrays, the compiler flattens them into a single linear space, computing offsets as (i * dim1 + j) * element_size.
  • Structs – fields are accessed at fixed offsets from the base address of the struct instance.
  • Returning structs – GCC passes a hidden pointer to the caller‑allocated struct as an extra argument; the function writes the result through that pointer and returns the pointer in %eax.

The document provides numerous example C files and their corresponding assembly outputs for different optimisation levels (-O0, -O2, -O3 -fomit-frame-pointer) using both GCC 2.95 and 3.3.2. These exercises illustrate how the compiler transforms each control structure.

💡 Final advice: The best way to internalise these concepts is to compile small programs yourself, experiment with various optimisation flags, and study the resulting assembly. Over time, you will develop intuition for what kind of C code produced a given assembly sequence. This skill is the bedrock of effective reverse engineering.
📘 Note: The original document contained placeholders (FIXME) for some diagrams, additional examples, and further elaboration on C++ features (classes, inheritance, templates). Those have been omitted or summarised here to maintain focus on the core concepts.

This HTML rendering is based on the “Reconstructing Functions & Control Flow” document. All content is for educational purposes.

  • Mikatech mcu reverse engineer list:
Actel Integrated Circuit (ic) Hack view more types...
  ProASI plus series integrated circuit ic hack: APA075 APA150 APA300 APA450 APA600 APA750 APA1000 ...
SX-A series integrated circuit ic hack: A54SX08A A54SX16A A54SX32A A54SX72A ...
MX series integrated circuit ic hack: A40MX02 A40MX04 A42MX09 A42MX16 A42MX24 A42MX36 ...
ACT series integrated circuit ic unlock: A1415A A14V15A A1425A A14V25A A1440A A14V40A A1460A A14V60A A14100A A14V100A A1225A A1240A A1280A A1010B A10V10B A1020B A1020B ...
ProASIC3 series integrated circuit ic lockbit read out: A3P015 A3P030 A3P060 A3P125 A3P250 A3P400 A3P600 A3P1000 A3PE600 A3PE1500 A3PE3000 ...
ProASIC3 Nano series integrated circuit ic unlock: A3PN010 A3PN015 A3PN020 A3PN0301 A3PN060 A3PN125 A3PN250 ...
ProASIC3L series integrated circuit ic hack: A3P250L A3P600L A3P1000L A3PE600L1 A3PE3000L ...
Cypress Integrated Circuit (ic) Crack view more types...
  CY2xx series integrated circuit ic crack: CY2071A CY2077FZ CY2291F CY2292F CY2292FZ CY22050F CY22150F CY22381F CY22392F CY22393F CY22394F CY22395F CY25100FS CY2907F14 CY2907F8 ...
CY6xx series integrated circuit ic crack: CY63000 CY63001 CY63100 CY63101 CY63200 CY63201 CY63221 CY63231 CY63410 CY63411 CY63412 CY63413 CY63510 CY63511 CY63512 CY63612 CY63613 CY63722 CY63723 CY63742 CY63743 CY63823... CY64XXX Series: CY64011 CY64012 CY64013 ...
CY7Cxx series integrated circuit ic lockbit crack: CY7C63000 CY7C63001 CY7C63100 CY7C63101 CY7C63200 CY7C63201 CY7C63221 CY7C63231 CY7C63231 CY7C63410 CY7C63411 CY7C63412 CY7C63413 CY7C63510 CY7C63511 CY7C63512 CY7C63513 CY7C63612 CY7C63613 CY7C63722 CY7C63723 CY7C63742 CY7C63743 CY7C63801 CY7C63813 CY7C63823 CY7C64011 CY7C64012 CY7C64111 CY7C64112 CY7C64113 CY7C65013 CY7C65113 ...
CY8Cxx series integrated circuit ic crack: CY8C21001 CY8C21234 CY8C21323 CY8C21334 CY8C21434 CY8C21634 CY8C9520 CY8C9540 CY8C9560 CY8C22113 CY8C24094 CY8C24123 CY8C24123 CY8C24223 CY8C24223 CY8C24423 CY8C24423 CY8C24794 CY8C24894 CY8C24994 CY8C24123A CY8C24223A CY8C24423A CY8C25122 CY8C26233 CY8C26443 CY8C27143 CY8C27143 CY8C27243 CY8C27243 CY8C27443 CY8C27466 CY8C27543 CY8C27566 CY8C27643 CY8C27643 CY8C27666 CY8C29466 CY8C29566 CY8C29666 CY8C29866 CY8C21534 CY8C22213 ...
PAL10/12/14/16xx series integrated circuit ic crack: PAL10HI8 PAL10L8 PAL10P8 PAL12HI6 PAL12L6 PAL12L10 PAL12P6 PAL14L4 PAL14L8 PAL14P4 PAL14P8 PAL14H4 PAL14H8 PAL16R4 PAL16R6 PAL16R8 PAL16H2 PAL16H6 PAL16P6 PAL16L2 PAL16L6 PAL16L8 PAL16P2 PAL16P8 PAL16V8 PAL16V8B PAL16RP4 PAL16RP6 PAL16RP8 PAL16A4 PAL16C1 PAL16X4 PAL16RA8 ...
PAL18/20/22xx series integrated circuit ic crack: PAL18L4 PAL18H4 PAL18P4 PAL18P8 PAL20C1 PAL20H2 PAL20L2 PAL20L4 PAL20L6 PAL20L8 PAL20L10 PAL20X10 PAL20R2 PAL20R4 PAL20R6 PAL20R8 PAL20V8 PAL20V8H PAL20R10 PAL20P1 PAL20P2 PAL20P8 PAL20RS4 PAL20RS8 PAL20RS10 PAL20RP4 PAL20RP6 PAL20RP8 PAL20RP10 PAL22V8 PAL22V10 PAL22V10D ...
Elan Integrated Circuit (ic) firmware Attack view more types...
  EMC EM78xx series integrated circuit ic attack: EM78156E EM78447S EM78448C EM78806B EM78448 EM78450 EM78451 EM78458 EM78576 EM78568 EM78569 EM78459 EM78800 EM78806 EM78808 EM78810 EM78811 EM78813 EM78815 EM78820 EM78860 EM78861 EM78862 EM78863 EM78865 EM78870 EM78911 EM78912 ...
EMC EM78Pxx series integrated circuit ic lockbit attack: EM78P153 EM78P156 EM78P257 EM78P447 EM78P451 EM78P452 EM78P458 EM78P459 EM78P468 EM78P5839 EM78P5840 EM78P5841 EM78P5842 EM78P154N EM78P156N EM78P157N EM78P159N EM78P259N EM78P259N EM78P260N EM78P417N EM78P418N EM78P419N EM78P447N EM78P468N EM78P468L EM78P510N EM78P809N EM78P5840N EN78P5841N EM78P5842N EM78P565 EM78P566 EM78P567 EM78P568 EM78P569 EM78P5830 EM78P806 EM78P808 EM78P811 EM78P813 EM78P870 EM78P911 ...
Fujitsu MCU Dump view more types...
  MB90F3XX Series controller duplicate: MB90F334 MB90F335 MB90F337 MB90F342 MB90F343 MB90F345 MB90F346 MB90F347 MB90F349 MB90F394HA MB90F351 MB90F352 MB90F356 MB90F357 ...
MB90F4XX Series mcu lockbit dump: MB90MF408 MB90F423 MB90F428 MB90F443G MB90F438L MB90F439 MB90F455 MB90F456 MB90F457 MB90F462 MB90F463 MB90F481B MB90F482B MB90F488B MB90F489B MB90F497G MB90F498G...
MB90F5XX Series controller duplicate: MB90F543G MB90F548G MB90F549G MB90F546G MB90F562 MB90F568 MB90F591G MB90F594G MB90F598G...
MB90F5XX Series mcu dump: MB90F804 MB90F809 MB90F822B MB90F823B MB90F828B MB90F867E MB90F882A MB90F883B MB90F883BH MB90F883C MB90F884B MB90F884BH MB90F884C MB90F897 ...
Freescale/Motorola MCU Crack view more types...
  HC908 Series MCU Hack: HC908AB32 HC908AP8 HC908AP16 HC908AP32 HC908AP64 HC908AZ60 HC908JK1 HC908JK3 HC908JK8 HC908JK32 HC908JW16 HC908JW32 HC908LK24 HC908MR8 HC908GR8 HC908QT1 HC908QT2 HC908QT4 HC908QY1 HC908QY2 HC908QY4 HC908RF2 HC908RK2 ...
MC908 Series MCU Reverse Engineer: MC908AB32 MC908AP8 MC908AP16 MC908AP32 MC908AP48 MC908AP64 MC908AS32 MC908AS60 MC908AZ32 MC908AZ60 MC908BD48 MC908EY8 MC908EY16 MC908GR16 MC908GR32 MC908GR48 MC908GR60 MC908GZ16 MC908GZ32 MC908GZ48 MC908GZ60 MC908GP8 MC908GP16 MC908GP32 MC908GR4 MC908GR8 MC908GR16 MC908GR32 MC908GR48 MC908GR60 MC908GT8 MC908GT16 ...
MC68HC05 Series MCU Hack: MC68HC05B6 MC68HC05B8 MC68HC05B16 MC68HC05B32 MC68HC05BD3 MC68HC05BD5 MC68HC05BD7 MC68HC05BD24 MC68HC05BD32 MC68HC05C0 MC68HC05C2 MC68HC05C4 MC68HC05C8 MC68HC05C9 MC68HC05C12 MC68HC05CC MC68HC05CJ4 MC68HC05CL1 MC68HC05CL4 MC68HC05D9 MC68HC05D32 MC68HC05E0 MC68HC05E5 MC68HC05E6 MC68HC05F4 MC68HC05F8 MC68HC05F12 MC68HC05F24 MC68HC05G3 ...
MC68HC705 Series controller Reverse Engineer: MC68HC705B16 MC68HC705C4 MC68HC705C8 MC68HC705C9 MC68HC705CCVFB MC68HC705CJ4 MC68HC705CL4 MC68HC705CT4 MC68HC705J1 MC68HC705J2 MC68HC705J5 MC68HC705JB2 MC68HC705JB4 MC68HC705JJ7 MC68HC705JP7 MC68HC705K1 MC68HC705KJ1CDW ...
MC68HC11 Series MCU read out memory: MC68HC11A0 MC68HC11A1 MC68HC11A8 MC68HC11C0 MC68HC11L0 MC68HC11L1 MC68HC11L2 MC68HC11M2 MC68HC11D0 MC68HC11D3 MC68HC11E0 MC68HC11E1 MC68HC11E8 MC68HC11E9 MC68HC11E18 MC68HC11E20 MC68HC11EA9 MC68HC11ED0 MC68HC11EVBU2 MC68HC11F1 MC68HC11FC0 MC68HC11FL0 ...
MC68HC711 Series MCU retreive source code: MC68HC711D3 MC68HC711E9 MC68HC711E20 MCMC68HC711M2 MCMC68HC711MA8 MC68HC711K4 MC68HC711KA2 MC68HC711KS2 MC68HC711KS8 MCMC68HC711L6 MCMC68HC711P2 MCMC68HC711SA2FG MCMC68HC711FA2 ...
MC68HC08 Series controller Hack: MC68HC08AB16A MC68HC08AB32 MC68HC08AS32 68HC08AS32A MC68HC08AZ16 MC68HC08AZ24 MC68HC08AZ32 MC68HC08AZ48 MC68HC08AZ60 MC68HC08BD24 MC68HC08GP8 MC68HC08GP16 MC68HC08GP32 MC68HC08JB1 MC68HC08JB8 MC68HC08JB16 ...
MC68HC908 Series MCU duplication: MC68HC908AP64 MC68HC908AP32 MC68HC908AP16 MC68HC908AP8 MC68HC908AS32A MC68HC908AZ60A MC68HC908AS60A MC68HC908AZ60E MC68HC908AS60 MC68HC908BD48 MC68HC908EY16A MC68HC908EY8A MC68HC908GR4 MC68HC908GR8 MC68HC908GR16 MC68HC908GT8 MC68HC908GT16 ...
MC9S08 Series MCU Hack: MC9S08AC8 MC9S08AC16 MC9S08AC32 MC9S08AC48 MC9S08AC60 MC9S08AC96 MC9S08AC128 MC9S08AW16 MC9S08AW32 MC9S08AW48 MC9S08AW60 MC9S08DN16 MC9S08DN32 MC9S08DN48 MC9S08DN60 MC9S08DV16 MC9S08DV32 MC9S08DV48 MC9S08DV60 MC9S08DV96 MC9S08DV128 MC9S08DZ16 MC9S08DZ32 MC9S08DZ48 MC9S08DZ60 ...
MC9S12 Series controller Reverse Engineer: MC9S12A32 MC9S12A64 MC9S12A128 MC9S12A256 MC9S12A512 MC9S12B32 MC9S12B64 MC9S12B96 MC9S12B128 MC9S12B256 MC9S12C32 MC9S12C64 MC9S12C96 MC9S12C128 MC9S12D32 MC9S12D64 MC9S12D96 MC9S12DB64 MC9S12DB128 MC9S12DG128 MC9S12DG256 MC9S12DJ64 MC9S12DJ128 MC9S12DJ256 ...
DSP56 Series MCU read memory: DSP56F801X DSP56F802X DSP56F803X DSP56852 DSP56853 DSP56854 DSP56855 DSP56857 DSP56858 DSP56F801 DSP56F801FA60 DSP56F802 DSP56F802TA60 DSP56F803 DSP56F805 DSP56F807 ...
MC56F Series MCU Reverse Engineer: MC56F801X MC56F802X MC56F803X MC56F800X MC56F8023M MC56F8023V MC56F8025M MC56F8025V MC56F8027M MC56F8027V MC56F8033M MC56F8033V MC56F8035M MC56F8035V MC56F8036M MC56F8036V MC56F8037M MC56F8037V ...
 
 
     
 
PCB Copying Service
PCB Projects Overview
PCB Clone
PCB Reverse Engineering
PCB Prototype
PCB Assembly Production
 
 
 
Mcu Hacking Service
Atmel / Analog Mcu Hack
Actel Mcu Attack
Altera Microcontroller Crack
Cygnal Mcu Unlock
Cypress IC Reverse Engineer
Dallas / Elan Mcu Code Extract
Fujitsu Microprocessor Decryption
Freescale IC Code Extraction
Giga Device circuit Hack
Hitachi Mcu Code Extract
Holtek Chip Reverse Engineer
Infineon Microcontroller Dump
Intel Mcu Read Code Protection
ICT Microcontroller Duplication
Lattice Microcontroller Clone
Microchip Source Code Recovery
Motorola Microcontroller Crack
Maxim Mcu Attack
MDT Controller Hack
Megawin Microcontroller Unlock
NEC Mcu Reverse Engineer
NTK Microcontroller Code Extract
Nuvoton Chip Decryption
NXP Semiconductor Code Extraction
Philips integrated circuit Crack
Renesas Microcontroller Dump
ST Processor Reverse Engineer
Silicon Labs Mcu Read Protection
Samsung Mcu Duplication
SST Mcu Clone
Sinowealth Source Code Recovery
SyncMOS Mcu Unlock
Sonix Mcu Read Source Code
STC Microprocessor Code Extract
Tenx Microcontroller Decryption
Texas Instruments MCU Hack
Winbond MCU Code Extraction
Xilinx integrated circuit Crack
Zilog MCU Reverse Engineer
 
     
 
 
More MCU brands we can reverse engineer below, please contact us if yours not listed here:
AMD Feeling LG / Hyundai Myson STK
ChipON Hynix Mitsubishi National Semi Temic
Coreriver ICSI Mosel Vitelic Portek Toshiba
Dallas ISSI MXIC SSSC Gal / Pal / Palce
Copyright © 2013 Mikatech. All rights reserved. Full dedicated reverse engineering company