Chromium Code Reviews| OLD | NEW |
|---|---|
| 1 # Test target validity: only accept target RVA in [1000, 3000). | 1 # Test target validity: only accept target RVA in [1000, 3000). |
| 2 | 2 |
| 3 # .text start RVA and end RVA | 3 # .text start RVA and end RVA |
| 4 1000 | 4 1000 |
| 5 3000 | 5 3000 |
| 6 # .reloc start RVA and end RVA | 6 # .reloc start RVA and end RVA |
| 7 3800 | 7 3800 |
| 8 4000 | 8 4000 |
| 9 # End RVA | 9 # End RVA |
| 10 5000 | 10 5000 |
| (...skipping 10 matching lines...) Expand all Loading... | |
| 21 00401014: E9 E7 FF FF FF jmp 00401000 # ... don't appear here. | 21 00401014: E9 E7 FF FF FF jmp 00401000 # ... don't appear here. |
| 22 00401019: E9 E1 FF FF FF jmp 00400FFF # 1 byte before .text | 22 00401019: E9 E1 FF FF FF jmp 00400FFF # 1 byte before .text |
| 23 0040101E: E8 DC 1F 00 00 call 00402FFF | 23 0040101E: E8 DC 1F 00 00 call 00402FFF |
| 24 00401023: E8 D8 1F 00 00 call 00403000 # 1 byte after .text | 24 00401023: E8 D8 1F 00 00 call 00403000 # 1 byte after .text |
| 25 00401028: 0F 87 D1 1F 00 00 ja 00402FFF | 25 00401028: 0F 87 D1 1F 00 00 ja 00402FFF |
| 26 0040102E: 0F 88 CC 1F 00 00 js 00403000 # 1 byte after .text | 26 0040102E: 0F 88 CC 1F 00 00 js 00403000 # 1 byte after .text |
| 27 00401034: E8 C6 3F 00 00 call 00404FFF # In image, outside .text | 27 00401034: E8 C6 3F 00 00 call 00404FFF # In image, outside .text |
| 28 00401039: E8 C2 3F 00 00 call 00405000 # Outside image | 28 00401039: E8 C2 3F 00 00 call 00405000 # Outside image |
| 29 0040103E: E8 BE 3F 00 00 call 00405001 # Outside image | 29 0040103E: E8 BE 3F 00 00 call 00405001 # Outside image |
| 30 00401043: E8 88 88 88 88 call 88C898D0 # Far away | 30 00401043: E8 88 88 88 88 call 88C898D0 # Far away |
| 31 00401048: 5D pop ebp | 31 00401048: FF 15 B1 EF FF FF call 003FFFFF # 1 byte before image |
| 32 00401049: C3 ret | 32 0040104E: FF 15 AC EF FF FF call 00400000 # In image |
| 33 00401054: FF 15 A5 3F 00 00 call 00404FFF # 1 byte before end | |
| 34 0040105A: FF 15 A0 3F 00 00 call 00405000 # Outside image | |
| 35 00401060: FF 15 6A 88 C8 88 call 88C898D0 # Far away | |
| 36 00401066: FF 25 93 EF FF FF jmp 003FFFFF | |
| 37 0040106C: FF 25 8E EF FF FF jmp 00400000 | |
| 38 00401072: FF 25 87 3F 00 00 jmp 00404FFF | |
| 39 00401078: FF 25 82 3F 00 00 jmp 00405000 | |
| 40 0040107E: 8D 05 7B EF FF FF lea eax, 003FFFFF | |
|
huangs
2016/05/30 05:48:35
lea eax, [eip-00001085] # 1 byte before image
e
etiennep
2016/05/30 17:07:31
Done.
| |
| 41 00401084: 8D 05 76 EF FF FF lea eax, 00400000 | |
| 42 0040108A: 8D 05 6F 3F 00 00 lea eax, 00404FFF | |
| 43 00401090: 8D 05 6A 3F 00 00 lea eax, 00405000 | |
| 44 00401096: 5D pop ebp | |
| 45 00401097: C3 ret | |
| 33 | 46 |
| 34 Abs32: | 47 Abs32: |
| 35 | 48 |
| 36 Expected: | 49 Expected: |
| 37 1009 | 50 1009 |
| 38 1015 | 51 1015 |
| 39 101F | 52 101F |
| 40 102A | 53 102A |
| 54 1050 | |
| 55 1056 | |
| 56 106E | |
| 57 1074 | |
| 58 # 1086 Not yet detected. | |
| 59 # 108C Not yet detected. | |
| OLD | NEW |