3 ms·
Very nice. I'm up to part 2 (https://yingtongli.me/blog/2021/08/29/drm5-2.html https://yingtongli.me/blog/2021/08/29/drm5-2.html) and I had a thought. The SEH
by philpem 5y ago
Very nice. I'm up to part 2 (https://yingtongli.me/blog/2021/08/29/drm5-2.html https://yingtongli.me/blog/2021/08/29/drm5-2.html) and I had a thought.
The SEH pattern (PUSH 32bit address then RET) should be identifiable with a plugin, and a code flow override should fix the decompilation.
I wonder, did you try this, and did it help fix the Ghidra decompilation?
- RunasSudo 5y agoGood thought! I don't have enough understanding of Ghidra to attempt this myself I think, but it looks like it is already on the radar of the Ghidra folks: https://github.com/NationalSecurityAgency/ghidra/issues/2477 https://github.com/NationalSecurityAgency/ghidra/issues/2477 Sounds like try-catch handling is not implemented in general yet, but is on the cards.