Chromium Code Reviews| OLD | NEW |
|---|---|
| 1 # Test target validity: only accept target RVA in [1000, 3000). | 1 # Test target validity: only accept target RVA in [1000, 3000). |
| 2 | 2 |
| 3 # Processor type | |
| 4 x64 | |
| 3 # .text start RVA and end RVA | 5 # .text start RVA and end RVA |
| 4 1000 | 6 1000 |
| 5 3000 | 7 3000 |
| 6 # .reloc start RVA and end RVA | 8 # .reloc start RVA and end RVA |
| 7 3800 | 9 3800 |
| 8 4000 | 10 4000 |
| 9 # End RVA | 11 # End RVA |
| 10 5000 | 12 5000 |
| 11 | 13 |
| 12 # Assume ImageBase = 00400000. This does not affect the test. | 14 # Assume ImageBase = 00400000. This does not affect the test. |
| 13 Program: | 15 Program: |
| 14 00401000: 55 push ebp | 16 00401000: 55 push ebp |
| 15 00401001: 8B EC mov ebp,esp | 17 00401001: 8B EC mov ebp,esp |
| 16 00401003: E8 F8 EF FF FF call 00400000 # RVA start, outside .text | 18 00401003: E8 F8 EF FF FF call 00400000 # RVA start, outside .text |
| 17 00401008: E8 F3 FF FF FF call 00401000 | 19 00401008: E8 F3 FF FF FF call 00401000 |
| 18 0040100D: E8 ED FF FF FF call 00400FFF # 1 byte before .text | 20 0040100D: E8 ED FF FF FF call 00400FFF # 1 byte before .text |
| 19 00401012: 90 nop # Padding so E8 & E9 ... | 21 00401012: 90 nop # Padding so E8 & E9 ... |
| 20 00401013: 90 nop | 22 00401013: 90 nop |
| 21 00401014: E9 E7 FF FF FF jmp 00401000 # ... don't appear here. | 23 00401014: E9 E7 FF FF FF jmp 00401000 # ... don't appear here. |
| 22 00401019: E9 E1 FF FF FF jmp 00400FFF # 1 byte before .text | 24 00401019: E9 E1 FF FF FF jmp 00400FFF # 1 byte before .text |
| 23 0040101E: E8 DC 1F 00 00 call 00402FFF | 25 0040101E: E8 DC 1F 00 00 call 00402FFF |
| 24 00401023: E8 D8 1F 00 00 call 00403000 # 1 byte after .text | 26 00401023: E8 D8 1F 00 00 call 00403000 # 1 byte after .text |
| 25 00401028: 0F 87 D1 1F 00 00 ja 00402FFF | 27 00401028: 0F 87 D1 1F 00 00 ja 00402FFF |
| 26 0040102E: 0F 88 CC 1F 00 00 js 00403000 # 1 byte after .text | 28 0040102E: 0F 88 CC 1F 00 00 js 00403000 # 1 byte after .text |
| 27 00401034: E8 C6 3F 00 00 call 00404FFF # In image, outside .text | 29 00401034: E8 C6 3F 00 00 call 00404FFF # In image, outside .text |
| 28 00401039: E8 C2 3F 00 00 call 00405000 # Outside image | 30 00401039: E8 C2 3F 00 00 call 00405000 # Outside image |
| 29 0040103E: E8 BE 3F 00 00 call 00405001 # Outside image | 31 0040103E: E8 BE 3F 00 00 call 00405001 # Outside image |
| 30 00401043: E8 88 88 88 88 call 88C898D0 # Far away | 32 00401043: E8 88 88 88 88 call 88C898D0 # Far away |
| 31 00401048: 5D pop ebp | 33 00401048: FF 15 B1 EF FF FF call 003FFFFF # 1 byte before image |
|
huangs
2016/05/30 18:14:48
These are indirect, RIP-relative calls, i.e., load
etiennep
2016/06/01 17:23:41
Done.
| |
| 32 00401049: C3 ret | 34 0040104E: FF 15 AC EF FF FF call 00400000 # In image |
| 35 00401054: FF 15 A5 3F 00 00 call 00404FFF # 1 byte before end | |
| 36 0040105A: FF 15 A0 3F 00 00 call 00405000 # Outside image | |
| 37 00401060: FF 15 6A 88 C8 88 call 88C898D0 # Far away | |
| 38 00401066: FF 25 93 EF FF FF jmp 003FFFFF | |
| 39 0040106C: FF 25 8E EF FF FF jmp 00400000 | |
| 40 00401072: FF 25 87 3F 00 00 jmp 00404FFF | |
| 41 00401078: FF 25 82 3F 00 00 jmp 00405000 | |
| 42 0040107E: 8D 05 7B EF FF FF lea eax,[rip-00001085] | |
|
huangs
2016/05/30 18:14:48
I mentioned that "rip+..." should be used, but hav
etiennep
2016/06/01 17:23:41
Done.
| |
| 43 # 1 byte before image | |
| 44 00401084: 8D 05 76 EF FF FF lea eax,[rip-0000108A] # In image | |
| 45 0040108A: 8D 05 6F 3F 00 00 lea eax,[rip+00003F6F] | |
| 46 # 1 byte before end | |
| 47 00401090: 8D 05 6A 3F 00 00 lea eax,[rip+00003F6A] # Outside image | |
| 48 00401096: 5D pop ebp | |
| 49 00401097: C3 ret | |
| 33 | 50 |
| 34 Abs32: | 51 Abs32: |
| 35 | 52 |
| 36 Expected: | 53 Expected: |
| 37 1009 | 54 1009 |
| 38 1015 | 55 1015 |
| 39 101F | 56 101F |
| 40 102A | 57 102A |
| 58 1050 | |
| 59 1056 | |
| 60 106E | |
| 61 1074 | |
| 62 # 1086 Not yet detected. | |
| 63 # 108C Not yet detected. | |
| OLD | NEW |