4 ms·
Odd ways to zeroing some x86_64 registers
- Rarebox 11y agoIf you're wondering why this is useful, the reason is buffer overflow exploits. Strings in C are null-terminated, so having a null in your code may stop it from getting copied.
- userbinator 11y agoI think obfuscation is another reason, since the classic "xor reg, reg" (31 C0 is xor eax, eax) does not have any nulls either.
- ithkuil 11y agoyeah, nor it does on x64_64 since it's the same encoding but prefixed by a REX: `48 31 c0 xor %rax,%rax`
- gane5h 11y agoI've used this in the past, in high performance math. If you have data (vectors, matrices, etc.) that doesn't fit neatly into a SIMD block size, you'll have to zero out fields after the calculation. At this point, it's cheaper to generate a zero on the register than load via memory (cheaper as in the number of CPU instructions.)
- geyslan 11y agoIt began as an obsfucation method then I realized more implications.
- geyslan 11y agoNew link: http://hackingbits.github.io/blog/odd-ways-to-zeroing-some-x8664-registers/ http://hackingbits.github.io/blog/odd-ways-to-zeroing-some-x...