4 ms·
I would be really interested to see how often malicious software utilized undocumented opcodes that disassemblers incorrectly interpret and thus lead a security
by skunkworker 5y ago
I would be really interested to see how often malicious software utilized undocumented opcodes that disassemblers incorrectly interpret and thus lead a security researcher down a rabbit hole while the actual opcode does something different. Like the
66e9xxxxxxxx and 66e8xxxxxxxx opcodes in x86_64 [1]
If my understanding is correct, Stuxnet incorporated bytecode for the PLCs in S7comm, a protocol that was not open at the time. Though this is different then including undocumented opcodes for the system being targeted directly.
[1] https://youtu.be/KrksBdWcZgQ?t=1767 https://youtu.be/KrksBdWcZgQ?t=1767