Master the fundamental concepts of binary formats through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksThe Executable and Linkable Format (ELF) is the standard binary format for executables, object files, shared libraries, and core dumps on Unix-like systems. Every Linux binary you run, every .o file the linker processes, and every core dump from a crash follows this layout.
The ELF header starts with the e_ident array:
EI_MAG0-3: Magic bytes 0x7F 'E' 'L' 'F'EI_CLASS: 1 = 32-bit, 2 = 64-bitEI_DATA: 1 = little endian, 2 = big endiane_type: 1 = relocatable, 2 = executable, 3 = shared, 4 = coree_machine: 0x3E = x86-64, 0x28 = ARMe_entry: Virtual address where execution startsFor example, a typical x86-64 executable has e_entry pointing to _start in the C runtime, not your main function directly.
You will implement a parser that reads an ELF header from disk, verifies the magic bytes, and prints the key fields. Tools like readelf automate this, but knowing the raw structure matters when you encounter corrupted, packed, or malware-modified ELF files that standard tools cannot parse.
Your parser opens the file, reads the first 64 bytes into an Elf64_Ehdr struct, and validates each field before trusting it. The e_phoff and e_shoff fields tell you where to seek for program and section headers. Malware sometimes corrupts these offsets to crash analysis tools, so defensive parsers check that offsets fall within the file size before dereferencing them.
Parse a 64-byte ELF64 file header by hand. Every multi-byte field is little-endian at a fixed offset:
| Offset | Field | Size |
|---|---|---|
| 0-3 | magic, must be 7F 45 4C 46 | 4 |
| 4 | class (1 = 32-bit, 2 = 64-bit) | 1 |
| 5 | data encoding (1 = little-endian, 2 = big-endian) | 1 |
| 6 | version | 1 |
| 16 | e_type | 2 |
| 18 | e_machine | 2 |
| 24 | e_entry | 8 |
| 32 | e_phoff | 8 |
| 40 | e_shoff | 8 |
| 48 | e_flags | 4 |
| 52 | e_ehsize | 2 |
| 54 | e_phentsize | 2 |
| 56 | e_phnum | 2 |
| 58 | e_shentsize | 2 |
| 60 | e_shnum | 2 |
| 62 | e_shstrndx | 2 |
N (64 to 4096), then N bytes in hexadecimal.
If the magic is wrong, a single line with the four bytes found: NOT_ELF magic=00 45 4C 46. Otherwise seven lines:
cLoading…
machine is at least 2 uppercase hex digits; entry and flags are uppercase hex without leading zeros; everything else is decimal.