Cat*_*tie 8 x86 assembly disassembly switch-statement
我正在查看switch语句的汇编语言代码.
我理解代码如何工作以及案例是什么.我的问题是我如何决定案件名称?
下面是汇编语言代码,我将对其进行解释.我基本上只需要使用跳转表并填写案例名称.
1 8048420: push %ebp
2 8048421: mov %esp, $ebp
3 8048423: mov 0x8(%ebp), %eax // x
4 8048426: mov 0xc(%ebp), %edx // n
5 8048429: sub $0x32, %edx // so least value of case is 32
6 804842c: cmp $0x5, %edx // max value is 37
7 804842f: ja 8048448 <switch+0x28> // if >37, go to default
8 8048431: jmp *0x80485d0(, %edx, 4) //THIS RIGHT HERE ?
9 8048438: shl $0x2, %eax // CASE A
10 804843b: jmp 804844b <switch+0x2b> //break;
11 804843d: sar $0x2, %eax //CASE B
12 8048440: jmp 804844b <switch+0x2b> //break
13 8048442: lea (%eax, %eax, 2), %eax //CASE C
14 8048445: imul %eax, %eax
15 8048448: add $0xa, %eax //fall through to default
16 804844b: pop %ebp //return
17 804844c: ret
Run Code Online (Sandbox Code Playgroud)
gdb命令创建的跳转表:我正在做x/6w 0x80485d0
0x80485d0: 0x08048438 0x08048448 0x08048438 0x0804843d
0x80485e0: 0x08048442 0x08048445
Run Code Online (Sandbox Code Playgroud)
我的解释:
int result = x;
switch(n) {
case __:
x = x << 2;
break;
case __:
x = x >> 2
break;
case __:
x = 4*x;
x = x*x
case __: //default
x += 0xa
return x;
}
Run Code Online (Sandbox Code Playgroud)
我只是不明白如何查找跳转表并确定32到37之间的n值适合哪种情况下的空白.
任何帮助,将不胜感激.谢谢.
正如奥利所说,没有更多的事要做.n-50
存储在%edx中,然后切换+ 0x11跳转到存储的地址0x80485d0 + %edx * 4
.看一下表,当n == 50或52时,开关+ 0x18,当n == 51时切换+ 0x28,当n == 53时切换+ 0x1d,当n == 54时切换+ 0x22,当n =时切换+ 0x25 = 55.