0x01: The “Same-Arch” Trap
By default, compilers like gcc are “Native.” They assume the code you write is meant to run on the machine you are currently using.
- If you run
gccon an Intel (x86_64) laptop, it spits out x86_64 machine code. - If you run it on a Raspberry Pi (ARM), it spits out ARM machine code.
In the field, we often need to generate code for a target that has a different architecture than our development station. This is where the Cross-Compiler comes in.
0x02: The Cross-Compiler Toolchain
A cross-compiler is a specialized version of the GCC suite. Instead of just calling gcc, we call the specific toolchain for our target.
| Toolchain Name | Target Architecture | Use Case |
aarch64-linux-gnu-gcc | ARM 64-bit | Modern Smartphones, Servers, M1/M2/M3 Mac virtualization. |
arm-linux-gnueabihf-gcc | ARM 32-bit | Legacy IoT, Industrial controllers, older Raspberry Pis. |
0x03: Tactical Verification with file
As a reverse engineer, the file command is your first reconnaissance tool. It inspects the ELF Header to reveal the binary’s “DNA.”
Example Recon:
user@ocsaly:~$ file a64.so
a64.so: ELF 64-bit LSB pie executable, ARM aarch64, version 1 (SYSV)If the output says aarch64, you know you cannot execute it directly on your Intel machine. You must use an emulator (like QEMU) or a debugger that supports remote ARM targets.
0x04: The Interactive Lab (Toolchain Deployment)
You are tasked with arming your station for an ARM-based mission. You must select the correct toolchain and verify the resulting binary.
OBJECTIVE: Install the 64-bit ARM cross-compiler and build ‘payload.c’ for the target.
0x05: Mission Task
Current Objective: Once you have installed the cross-compiler, run the following:
aarch64-linux-gnu-gcc main.c -o a64.binThen, use the command
file a64.bin. Challenge: Copy the exact string thatfilereturns regarding the “interpreter” or “machine” type and save it in your mission log.
