OLD | NEW |
---|---|
1 # Test target validity: only accept target RVA in [1000, 3000). | 1 # Test target validity: only accept target RVA in [1000, 3000). |
2 | 2 |
3 # Processor type | |
4 x64 | |
3 # .text start RVA and end RVA | 5 # .text start RVA and end RVA |
4 1000 | 6 1000 |
5 3000 | 7 3000 |
6 # .reloc start RVA and end RVA | 8 # .reloc start RVA and end RVA |
7 3800 | 9 3800 |
8 4000 | 10 4000 |
9 # End RVA | 11 # End RVA |
10 5000 | 12 5000 |
11 | 13 |
12 # Assume ImageBase = 00400000. This does not affect the test. | 14 # Assume ImageBase = 00400000. This does not affect the test. |
13 Program: | 15 Program: |
14 00401000: 55 push ebp | 16 00401000: 55 push ebp |
15 00401001: 8B EC mov ebp,esp | 17 00401001: 8B EC mov ebp,esp |
16 00401003: E8 F8 EF FF FF call 00400000 # RVA start, outside .text | 18 00401003: E8 F8 EF FF FF call 00400000 # RVA start, outside .text |
17 00401008: E8 F3 FF FF FF call 00401000 | 19 00401008: E8 F3 FF FF FF call 00401000 |
18 0040100D: E8 ED FF FF FF call 00400FFF # 1 byte before .text | 20 0040100D: E8 ED FF FF FF call 00400FFF # 1 byte before .text |
19 00401012: 90 nop # Padding so E8 & E9 ... | 21 00401012: 90 nop # Padding so E8 & E9 ... |
20 00401013: 90 nop | 22 00401013: 90 nop |
21 00401014: E9 E7 FF FF FF jmp 00401000 # ... don't appear here. | 23 00401014: E9 E7 FF FF FF jmp 00401000 # ... don't appear here. |
22 00401019: E9 E1 FF FF FF jmp 00400FFF # 1 byte before .text | 24 00401019: E9 E1 FF FF FF jmp 00400FFF # 1 byte before .text |
23 0040101E: E8 DC 1F 00 00 call 00402FFF | 25 0040101E: E8 DC 1F 00 00 call 00402FFF |
24 00401023: E8 D8 1F 00 00 call 00403000 # 1 byte after .text | 26 00401023: E8 D8 1F 00 00 call 00403000 # 1 byte after .text |
25 00401028: 0F 87 D1 1F 00 00 ja 00402FFF | 27 00401028: 0F 87 D1 1F 00 00 ja 00402FFF |
26 0040102E: 0F 88 CC 1F 00 00 js 00403000 # 1 byte after .text | 28 0040102E: 0F 88 CC 1F 00 00 js 00403000 # 1 byte after .text |
27 00401034: E8 C6 3F 00 00 call 00404FFF # In image, outside .text | 29 00401034: E8 C6 3F 00 00 call 00404FFF # In image, outside .text |
28 00401039: E8 C2 3F 00 00 call 00405000 # Outside image | 30 00401039: E8 C2 3F 00 00 call 00405000 # Outside image |
29 0040103E: E8 BE 3F 00 00 call 00405001 # Outside image | 31 0040103E: E8 BE 3F 00 00 call 00405001 # Outside image |
30 00401043: E8 88 88 88 88 call 88C898D0 # Far away | 32 00401043: E8 88 88 88 88 call 88C898D0 # Far away |
31 00401048: 5D pop ebp | 33 00401048: FF 15 B1 EF FF FF call 003FFFFF # 1 byte before image |
huangs
2016/05/30 18:14:48
These are indirect, RIP-relative calls, i.e., load
etiennep
2016/06/01 17:23:41
Done.
| |
32 00401049: C3 ret | 34 0040104E: FF 15 AC EF FF FF call 00400000 # In image |
35 00401054: FF 15 A5 3F 00 00 call 00404FFF # 1 byte before end | |
36 0040105A: FF 15 A0 3F 00 00 call 00405000 # Outside image | |
37 00401060: FF 15 6A 88 C8 88 call 88C898D0 # Far away | |
38 00401066: FF 25 93 EF FF FF jmp 003FFFFF | |
39 0040106C: FF 25 8E EF FF FF jmp 00400000 | |
40 00401072: FF 25 87 3F 00 00 jmp 00404FFF | |
41 00401078: FF 25 82 3F 00 00 jmp 00405000 | |
42 0040107E: 8D 05 7B EF FF FF lea eax,[rip-00001085] | |
huangs
2016/05/30 18:14:48
I mentioned that "rip+..." should be used, but hav
etiennep
2016/06/01 17:23:41
Done.
| |
43 # 1 byte before image | |
44 00401084: 8D 05 76 EF FF FF lea eax,[rip-0000108A] # In image | |
45 0040108A: 8D 05 6F 3F 00 00 lea eax,[rip+00003F6F] | |
46 # 1 byte before end | |
47 00401090: 8D 05 6A 3F 00 00 lea eax,[rip+00003F6A] # Outside image | |
48 00401096: 5D pop ebp | |
49 00401097: C3 ret | |
33 | 50 |
34 Abs32: | 51 Abs32: |
35 | 52 |
36 Expected: | 53 Expected: |
37 1009 | 54 1009 |
38 1015 | 55 1015 |
39 101F | 56 101F |
40 102A | 57 102A |
58 1050 | |
59 1056 | |
60 106E | |
61 1074 | |
62 # 1086 Not yet detected. | |
63 # 108C Not yet detected. | |
OLD | NEW |