3 ms·
not a bad find, its not unknown that most disassemblers dont do all the things correct. fun when u find one that breaks the further disass tho. intel xed is pr
by sim7c00 1y ago
not a bad find, its not unknown that most disassemblers dont do all the things correct. fun when u find one that breaks the further disass tho.
intel xed is pretty accurate usually but it also doesnt disassemble all possible opcodes.
if you do a jump over some UD but the jmp target is taken from reg value u can also get disassembly to break etc.
its kinda the problem of static analysis. it's not easy to see if someone inserted 1 byte of data, or if it was an unknown opcode u dont handle etc.
definitely fun, will throw off automated tools for analysis especially if you can make the invalid disassembly just call exit or do something valid but short/benign..
may also wanna look if they are known unknown, like this stuff: https://x.com/_markel___/status/1373059797155778562 https://x.com/_markel___/status/1373059797155778562
ive seen now multiple type of either debug or backdoor instructions on x86 based cpus over the past few years
- sapdragon 1y agoYes, but in most cases there is no such large-scale problem, plus we broke even all the popular debuggers here. The jump trick can probably only break Ghydra? But anything can break it(