kop*_*ich 1 c linux x86-64 inline-assembly
我在linux x86_64上构建了一个用C和内联汇编编写的简短程序.它应该写一个字符串给stdout.我在互联网上的一篇文章中找到了它:
int write_call( int fd, const char * str, int len ){
long __res;
__asm__ volatile ( "int $0x80":
"=a" (__res):"0"(__NR_write),"b"((long)(fd)),"c"((long)(str)),"d"((long)(len)) );
return (int) __res;
}
void do_write( void ){
char * str = "Paragon output string.\n";
int len = strlen( str ), n;
printf( "string for write length = %d\n", len );
n = write_call( 1, str, len );
printf( "write return : %d\n", n );
}
int main( int argc, char * argv[] ){
do_write();
return EXIT_SUCCESS;
}
Run Code Online (Sandbox Code Playgroud)
但是当我运行它时,它工作不正确,输出
"写回报:-14"
如果我在32位Linux上构建并运行它,它就能达到预期效果.
经过一些研究后,我发出指令"int $ 0x80"是一个x86指令,如果在x86_64上调用,则截断寄存器中的参数.
但我找不到x86_64架构的"int $ 0x80"的正确替换.我没有装配经验.
我应该用什么而不是"int $ 0x80"来接收预期的结果?
对于amd64,您需要使用"syscall" - 并使用不同的寄存器 - 而不是"int 0x80":
http://cs.lmu.edu/~ray/notes/linuxsyscalls/
http://blog.rchapman.org/post/36801038863/linux-system-call-table-for-x86-64
http://crypto.stanford.edu/~blynn/rop/
这是一个很好的例子:
如何在内联汇编(x86/amd64 linux)中通过sysenter调用系统调用?
#include <unistd.h>
int main(void)
{
const char hello[] = "Hello World!\n";
const size_t hello_size = sizeof(hello);
ssize_t ret;
asm volatile
(
"movl $1, %%eax\n\t"
"movl $1, %%edi\n\t"
"movq %1, %%rsi\n\t"
"movl %2, %%edx\n\t"
"syscall"
: "=a"(ret)
: "g"(hello), "g"(hello_size)
: "%rdi", "%rsi", "%rdx", "%rcx", "%r11"
);
return 0;
Run Code Online (Sandbox Code Playgroud)
| 归档时间: |
|
| 查看次数: |
1683 次 |
| 最近记录: |