#1 لماذا 98% من المبرمجين مخطئون؟ تشريح الذاكرة، ROP، ومحاذاة المكدس في x64 | سلسلة

أهلاً بك في المنطقة العميقة من هندسة البرمجيات.
هذا الفيديو ليس درسًا عابرًا، بل المدخل التأسيسي لسلسلة التقنيات المتقدمة منخفضة المستوى؛ السلسلة التي ستعيد تشكيل فهمك للكود، الذاكرة، والمعالج من منظور معماري حقيقي.

في هذه الحلقة الضخمة، نغادر عالم البرمجة عالية المستوى (High-Level) وننزل إلى الطبقة الفيزيائية للتنفيذ (Low-Level)، حيث لا وجود للتجريدات المريحة، بل عناوين، بايتات، ومحاذاة تتحكم فعليًا بمصير البرنامج.

ستتعلم كيف تُستغل نفس آليات النظام “الآمنة” لإعادة توجيه تدفق التنفيذ، وكيف تتحول الأخطاء المنطقية البسيطة إلى سيطرة كاملة على العملية
(Process Control Flow Hijacking).


🔥 محاور الفيديو:

The Cut-up Theory (نظرية القصاصات)
Memory Layout & Process Anatomy
API vs ABI (كسر الوهم البرمجي)
ROP & Ret2Libc Exploitation
Stack Alignment & MOVAPS Crashes
Machine Code, Opcodes, ModR/M
Little Endian & CPU Reality
Shadow Space & Windows x64 ABI

هذا المحتوى تأسيسي عميق، وليس موجّهًا للمشاهدة السريعة.


🛑 تنبيه مهم قبل المتابعة:
في هذه المرحلة، الهدف ليس الاعتماد على الأدوات الجاهزة مثل (IDA / Ghidra)، بل بناء عين تحليلية معمارية تفهم ما يحدث على مستوى البايت قبل أي واجهة رسومية.
الأدوات ستأتي لاحقًا، لكن الفهم هنا هو الأساس.


⏱️ الـ Timeline – خريطة الرحلة الكاملة للفيديو

00:00:00 المقدمة
00:00:46 تحذير الاستخدام
00:02:02 نظرية القصاصات (The Cut-up Theory)
00:03:13 بنية الذاكرة (Memory Layout)
00:12:09 أقسام الملف التنفيذي (PE Sections)
00:16:17 المكدس (Stack)
00:19:04 بنية وحدة المعالج (CPU Architecture)
00:22:22 المسجلات (Registers)
00:29:06 إطار المكدس (Stack Frame)
00:40:02 اتجاه الكتابة الخطية في الذاكرة (Linear Memory Writing)
00:48:06 بناء برنامج Assembly بسيط
01:01:03 البرمجة الموجهة للعودة (ROP)
01:07:29 خارطة طريق Ret2Libc وتجاوز NX
01:11:47 API – واجهة برمجة التطبيقات
01:15:48 القيود المنطقية vs الفيزيائية
01:22:02 ABI – واجهة التطبيق الثنائية
01:28:04 شرح عملي لاتفاقية ABI
01:32:40 التجريد وهندسة Ret2Libc
01:41:41 لماذا 98% من المبرمجين مخطئون
01:44:24 كيف يرى المعالج متغيراتك فعليًا
01:48:01 كيف تتحول return إلى C3
01:50:45 لماذا لا يجب أن تتعلم Assembly كمبرمج
01:54:45 تشريح Opcode و ModR/M
02:03:31 سر Little Endian
02:07:21 تحليل كود الآلة x64 يدويًا
02:16:39 صناعة ROP Gadgets عبر Misalignment
02:21:08 إخفاء الكود داخل البيانات (تعليمي)
02:23:25 عين المحلل vs عين المبرمج
02:26:46 بنية الدالة (Prologue & Epilogue)
02:31:03 Shadow Space & Stack Alignment (Windows x64 ABI)
02:35:13 التحكم في RIP بهجمات ROP
02:40:29 استخراج Gadgets و system باستخدام x64dbg
02:45:49 بناء الـ Payload يدويًا (HxD)
02:53:22 MOVAPS، XMM، SIMD
02:56:30 هرمية الذاكرة و Cache Line (64 Byte)
03:00:54 لماذا تتطابق كتل الكاش مع SIMD
03:03:39 CALL vs RET ولماذا تفشل المحاذاة
03:06:33 كيف تعيد PUSH RBP استقرار المكدس
03:08:07 خدعة Extra RET لإصلاح المحاذاة
03:10:51 تشغيل الشل وتجاوز مشكلة محاذاة المكدس نهائيًا
03:16:45 تشغيل calc عبر payload.bin يدويًا
03:23:06 MOV (C7) vs ADD (81) في الذاكرة
03:25:42 تشريح Opcode 81
03:28:08 نقل الاستغلال إلى Linux (POP RDI)
03:29:08 كن أنت الـ Disassembler

🧭 خارطة الفيديو المعمارية (Video Roadmap)

لمن يريد رؤية الصورة الكاملة للفيديو كوحدة هندسية واحدة،
قمت ببناء خارطة معمارية تربط جميع المفاهيم، المراحل، ونقاط التحول داخل هذا الفيديو
من تشريح الذاكرة ← ROP ← محاذاة المكدس ← السيطرة على RIP.

🔗 خارطة الفيديو التفاعلية:
https://physihack.com/roadmap/

هذه الخارطة ليست مسارًا تعليميًا عامًا،
بل تمثل البنية الداخلية لهذا الفيديو تحديدًا وكيف تتصل أجزاؤه ببعضها معماريًا.


🔗 الأدوات والموارد المستخدمة:

Code::Blocks (بيئة تطوير):
https://www.codeblocks.org/downloads/binaries/

Detect It Easy (DIE) – تحليل الملفات التنفيذية:
https://github.com/horsicq/DIE-engine/releases

x64dbg – Debugger لمعمارية x64:
https://x64dbg.com/

Flat Assembler (FASM) – Assembly Compiler:
https://flatassembler.net/download.php


📘 مراجع مهمة مرافقة للفيديو:

📊 تقرير العوائد الاستراتيجية للمسار التقني (Career ROI):
https://physihack.com/report/

📚 مرجع المصطلحات والتعليمات (Opcodes, Instructions, ABI, …):
https://physihack.com/reference/


☕ دعم المحتوى واستمراريته:
إذا وجدت المحتوى مفيدًا وتريد دعم استمراره:
https://buymeacoffee.com/physihack

هذا المحتوى صعب، وهذا مقصود.
الصعوبة هنا فلتر وليست عائقًا.
إذا أنهيت هذا الفيديو بفهم حقيقي، فأنت بالفعل داخل المسار الصحيح للنخبة التقنية.

شرح كامل لثغرات Buffer Overflow و ROP Chain على أنظمة Windows و Linux بمعمارية x86_64.

#Exploitation #ROP #ReverseEngineering #MemoryAlignment
#x64 #CyberSecurity #LowLevel #PhysiHack #BinaryExploitation Receive SMS online on sms24.me

TubeReader video aggregator is a website that collects and organizes online videos from the YouTube source. Video aggregation is done for different purposes, and TubeReader take different approaches to achieve their purpose.

Our try to collect videos of high quality or interest for visitors to view; the collection may be made by editors or may be based on community votes.

Another method is to base the collection on those videos most viewed, either at the aggregator site or at various popular video hosting sites.

TubeReader site exists to allow users to collect their own sets of videos, for personal use as well as for browsing and viewing by others; TubeReader can develop online communities around video sharing.

Our site allow users to create a personalized video playlist, for personal use as well as for browsing and viewing by others.

@YouTubeReaderBot allows you to subscribe to Youtube channels.

By using @YouTubeReaderBot Bot you agree with YouTube Terms of Service.

Use the @YouTubeReaderBot telegram bot to be the first to be notified when new videos are released on your favorite channels.

Look for new videos or channels and share them with your friends.

You can start using our bot from this video, subscribe now to #1 لماذا 98% من المبرمجين مخطئون؟ تشريح الذاكرة، ROP، ومحاذاة المكدس في x64 | سلسلة

What is YouTube?

YouTube is a free video sharing website that makes it easy to watch online videos. You can even create and upload your own videos to share with others. Originally created in 2005, YouTube is now one of the most popular sites on the Web, with visitors watching around 6 billion hours of video every month.

Top 5 Videos