OLD | NEW |
---|---|
(Empty) | |
1 # Test target validity: only accept target RVA in [1000, 3000). | |
2 | |
3 # Processor type | |
4 x64 | |
5 # .text start RVA and end RVA | |
6 1000 | |
7 3000 | |
8 # .reloc start RVA and end RVA | |
9 3800 | |
10 4000 | |
11 # End RVA | |
12 5000 | |
13 | |
14 # Assume ImageBase = 00400000. This does not affect the test. | |
15 Program: | |
16 00401000: 55 push ebp | |
17 00401001: 8B EC mov ebp,esp | |
18 00401003: E8 F8 EF FF FF call 00400000 # RVA start, outside .text | |
19 00401008: E8 F3 FF FF FF call 00401000 | |
20 0040100D: E8 ED FF FF FF call 00400FFF # 1 byte before .text | |
21 00401012: 90 nop # Padding so E8 & E9 ... | |
22 00401013: 90 nop | |
23 00401014: E9 E7 FF FF FF jmp 00401000 # ... don't appear here. | |
24 00401019: E9 E1 FF FF FF jmp 00400FFF # 1 byte before .text | |
25 0040101E: E8 DC 1F 00 00 call 00402FFF | |
26 00401023: E8 D8 1F 00 00 call 00403000 # 1 byte after .text | |
27 00401028: 0F 87 D1 1F 00 00 ja 00402FFF | |
28 0040102E: 0F 88 CC 1F 00 00 js 00403000 # 1 byte after .text | |
29 00401034: E8 C6 3F 00 00 call 00404FFF # In image, outside .text | |
30 00401039: E8 C2 3F 00 00 call 00405000 # Outside image | |
31 0040103E: E8 BE 3F 00 00 call 00405001 # Outside image | |
32 00401043: E8 88 88 88 88 call 88C898D0 # Far away | |
33 00401048: FF 15 B1 EF FF FF call [rip-0000104F] # 003FFFFF | |
34 # 1 byte before image | |
35 0040104E: FF 15 AC EF FF FF call [rip-00401054] # 00400000 | |
36 # In image | |
37 00401054: FF 15 A5 3F 00 00 call [rip+00003FA5] # 00404FFF | |
38 # 1 byte before end | |
39 0040105A: FF 15 A0 3F 00 00 call [rip+00003FA0] # 00405000 | |
40 # Outside image | |
41 00401060: FF 15 6A 88 C8 88 call [rip+88C8886A] # 88C898D0 | |
huangs
2016/06/01 20:57:21
NIT: # 88C898D0 is incorrect. Note that we're add
etiennep
2016/06/03 15:39:40
Done.
| |
42 # Far away | |
43 00401066: FF 25 93 EF FF FF jmp [rip+FFFFEF93] # 003FFFFF | |
44 # 1 byte before image | |
45 0040106C: FF 25 8E EF FF FF jmp [rip+FFFFEF8E] # 00400000 | |
46 # In image | |
47 00401072: FF 25 87 3F 00 00 jmp [rip+00003F87] # 00404FFF | |
48 # 1 byte before end | |
49 00401078: FF 25 82 3F 00 00 jmp [rip+00003F82] # 00405000 | |
50 # Outside image | |
51 0040107E: 8D 05 7B EF FF FF lea eax,[rip-00001085] # 003FFFF | |
huangs
2016/06/01 20:57:20
NIT: missing F:
003FFFFF
etiennep
2016/06/03 15:39:40
Done.
| |
52 # 1 byte before image | |
53 00401084: 8D 05 76 EF FF FF lea eax,[rip-0000108A] # 00400000 | |
54 # In image | |
55 0040108A: 8D 05 6F 3F 00 00 lea eax,[rip+00003F6F] # 00404FFF | |
56 # 1 byte before end | |
57 00401090: 8D 05 6A 3F 00 00 lea eax,[rip+00003F6A] # 00405000 | |
58 # Outside image | |
59 00401096: 5D pop ebp | |
60 00401097: C3 ret | |
61 | |
62 Abs32: | |
63 | |
64 Expected: | |
65 1009 | |
66 1015 | |
67 101F | |
68 102A | |
69 1050 | |
70 1056 | |
71 106E | |
72 1074 | |
huangs
2016/06/01 20:57:21
1074 # x64 parsing ignores .text boundaries. TODO
etiennep
2016/06/03 15:39:40
Added comment but no need to fix.
| |
73 # 1086 Not yet detected. | |
74 # 108C Not yet detected. | |
OLD | NEW |