1581, 9/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   zen0c1de
   http://dieuhouse.tistory.com
   [Reverse Engineering] ¸®¹ö½ÌÀÇ ±âÃÊ - ¹ü¿ë ·¹Áö½ºÅÍ¿Í Assembly(Pop,Mov)

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=7892 [º¹»ç]


EAX (Accumulator)

        - »ê¼ú, ³í¸® ¿¬»êÀÇ Áß½ÉÀÌ µÇ´Â ·¹Áö½ºÅÍÀÌ´Ù.

        - »ê¼ú, ³í¸® ¿¬»êÀ» ÇÒ ¶§ EAX¿¡ ¸¹ÀÌ ³Ö°í »ç¿ëÇÑ´Ù.

        - ÇÔ¼öÀÇ ¸®ÅÏ °ªÀ» ÀúÀåÇÏ´Â ·¹Áö½ºÅÍÀÌ´Ù.

        (Áï EAX´Â ÇϳªÀ̱⠶§¹®¿¡ ¸®ÅÏ °ªÀº 2°³ ÀÌ»óÀÌ µÉ ¼ö ¾ø´Ù.)



        EBX (Base Register)

        - °£Á¢ ¹øÁö ÁöÁ¤ ½Ã »ç¿ëµÈ´Ù.



        ¡Ø °£Á¢ ¹øÁö : int array[]={1,3,5}; ¿¡¼­ 3À̶ó´Â º¯¼ö¸¦ ¾²°í½ÍÀ¸¸é array[1]À» »ç¿ëÇؼ­ À妽º¿¡ Á¢±ÙÇØ ÁÖ

        ´Âµ¥ ¿©±â¼­ 1ÀÌ °£Á¢ ¹øÁöÀÌ´Ù. array[1]À» Ç®¾î¼­ ¾²¸é

        *(array+2)°¡ µÈ´Ù.



        ECX (Count Register)

        - ·çÇÁ¿Í °°Àº ¸í·ÉÀÇ ¹Ýº¹¼öÇàÀÌ ÇÊ¿ä·Î ÇÒ ‹š ¹Ýº¹È½¼ö ÁöÁ¤¿¡ ÁÖ·Î »ç¿ëÇÑ´Ù.

        - C¿¡¼­ »ç¿ëÇÏ´Â while, for¹®ÀÇ ¹Ýº¹¹®°ú´Â ´Ù¸£´Ù.(Assembly¿¡¼­ »ç¿ëÇÏ´Â ¹Ýº¹)

        - ECX¿¡ nÀ» ³ÖÀ¸¸é n¹ø µ·´Ù´Â ¶æÀÌ´Ù.




        EDX (Data Register)

        - °£Á¢ ¹øÁö ÁöÁ¤¿¡ »ç¿ëµÇ¸ç, °ö¼À ³ª´°¼ÀÀ» ÇÒ ¶§¿¡´Â º¸Á¶ Accumulator·Î »ç¿ë µÇ¾î        Áö±âµµÇÔ.

        - EAX¸¦ µµ¿ÍÁشٴ ´À³¦ÀÌ °­ÇÏ´Ù.

        - 2ÀÇ 32½ÂÀº ´ë·« 42¾ï Á¤µµ°¡ µÇ´Âµ¥, ¾î¶² °ªÀ» °öÇßÀ» ¶§ ±× °á°ú°¡ 42¾ïÀÌ ³Ñ¾î°¡¸é, EAXÀÇ ¾Õ¿¡ EDX°¡ ºÙ¾î¼­

        µµ¿ÍÁØ´Ù. (¹ü¿ë ·¹Áö½ºÅÍ´Â 32bit¶ó¼­ EAX·Î´Â 2ÀÇ 32½Â,         ¾à 42¾ï Á¤µµ ¹Û¿¡ Ç¥ÇöÇÏÁö ¸øÇÑ´Ù.



Æ÷ÀÎÅÍ ·¹Áö½ºÅÍ(Pointer Register)

- ½ºÅðú °ü·ÃÀÌ ÀÖ´Â ·¹Áö½ºÅÍÀÌ´Ù.



        ESP (Stack Pointer)

        - ½ºÅÃÀÇ °¡Àå À­ ºÎºÐÀ» °¡¸®Å²´Ù.

        - Top Pointer¶ó°íµµ ÇÑ´Ù.

        - Full Descending ¹æ½ÄÀ» »ç¿ëÇÏ´Â Intel ArchitectureÀÇ °æ¿ì, °¡Àå ÃÖ±Ù¿¡ ½ºÅÿ¡ µé¾î¿Â µ¥ÀÌÅ͸¦ °¡¸®Å²´Ù.



        EBP (Base Pointer)

        - ½ºÅÃÀÇ ¹Ù´ÚÀ» °¡¸®Å²´Ù.

        - Stack FrameÀ» »ç¿ëÇÒ °æ¿ì ÇöÀç ½ÇÇàÁßÀÎ ÇÔ¼ö¸¦ È£ÃâÇÑ ÇÔ¼ö°¡ »ç¿ëÇÏ´Â Stack FrameÀÇ ¹Ù´ÚÀ» °¡¸®Å²´Ù.



À妽º ·¹Áö½ºÅÍ (Index Register)

- ¹®ÀÚ¿­°ú °ü·ÃµÈ ·¹Áö½ºÅÍ

- ´Ù¸¥ ¹ü¿ë ·¹Áö½ºÅÍ¿Í ¸¶Âù°¡Áö·Î ¿¬»ê°ú °£Á¢ ¹øÁö ÁöÁ¤¿¡ »ç¿ëµÈ´Ù.

- ¹®ÀÚ¿­À» ºñ±³Çϰųª Àü¼ÛÇÏ´Â ½ºÆ®¸µ ¸í·É¿¡¼­´Â ´ÙÀ½°ú °°ÀÌ »ç¿ëµÈ´Ù.

        

        ESI (Source Index)

        - º¹»ç ȤÀº ºñ±³¸¦ Çϴµ¥ »ç¿ëµÇ´Â Source ¹®ÀÚ¿­À» ³ªÅ¸³½´Ù.



        EDI (Destination Index)

        - º¹»ç ȤÀº ºñ±³¸¦ Çϴµ¥ »ç¿ëµÇ´Â Destination ¹®ÀÚ¿­À» ³ªÅ¸³½´Ù.



------------------------------------------------------------------------------------

¸í·É¾î



POP



ex) POP [Operand]

- ESP°¡ °¡¸£Å°´Â °÷¿¡ ÀúÀåµÈ ³»¿ëÀ» Destination Operand ¿¡ ÀúÀå ÈÄ ESP°ª Á¶Á¤

( Ascending Stack : ESP°ª °¨¼Ò, Descending Stack : ESP °ª Áõ°¡ )



MOV



ex) MOV [Destination], [Source]

- µ¥ÀÌÅÍ º¹»ç ( °ª º¹»ç )

¿ëµµ£º1. ·¹Áö½ºÅÍ -> ¸Þ¸ð¸®·Î º¹»ç

      2. ¸Þ¸ð¸® -> ·¹Áö½ºÅÍ·Î º¹»ç

      3. ·¹Áö½ºÅÍ -> ·¹Áö½ºÅÍ·Î º¹»ç

      4. ¸Þ¸ð¸® or ·¹Áö½ºÅÍ¿¡ °ªÀ» ³ÖÀ½



¡Ø ¸Þ¸ð¸® -> ¸Þ¸ð¸®·Î º¹»ç ½Ã¿¡´Â »ç¿ëÇÏÁö ¾Ê´Â´Ù!

   (¸Þ¸ð¸®¿¡¼­ ¸Þ¸ð¸®·Î´Â º¹»ç°¡ ºÒ°¡´ÉÇÏ´Ù, ¸Þ¸ð¸® -> ·¹Áö½ºÅÍ -> ¸Þ¸ð¸®¿Í °°Àº ¹æ½ÄÀ¸·Î    ÇØ¾ß °¡´ÉÇÏ´Ù

¡Ø Destination Operand¿Í Source OperandÀÇ Å©±â°¡ ´Ù¸¦ ¶§´Â »ç¿ëÇÏÁö ¸øÇÑ´Ù.

  Hit : 12581     Date : 2013/07/18 01:51



    
1421   [ÀÚÀÛ] W's ¾ÏÈ£ÇÐ(Cryptology) - ½ºÆĸ£Åº ¾ÏÈ£,½ÃÀú(¾ËÆĺªÄ¡È¯)¾ÏÈ£[11]     williamlee
07/28 12795
1420   ¸Þ¸ð¸® ´ýÇÁ(ºí·ç ½ºÅ©¸°=STOP ½ºÅ©¸°) ÄÚµå ¹× ÇØ°á[1]     ROK.AF
02/09 12746
1419   ¾Ë±â ¾î·Æ°Ô ¼³¸íÇÑ Buffer Overflow[4]     blackcoder
02/17 12738
1418   * ÇØÄ¿°¡ µÇ°í½Í³ª ? *[19]     HackerMapia
03/01 12737
1417   ÇØÄ¿°¡ µÇ±âÀ§ÇØ ¾Ë¾Æ¾ßÇÒ 30°¡Áö Ãâó :ÇØÄ¿´ëÇÐ[5]     asdzxc301
12/12 12711
1416   Ãʺ¸°¡ Àû¾îº» À©µµ¿ì ħÅõ[6]     awsedr45
12/06 12678
1415   c¾ð¾î for¹®      hacs98
06/15 12660
1414   ÇØÅ·±â¹ý? (±â¹ßÇÏ´Ù°í ÇؾßÇϳª,¿ô±â´Ù°í ÇؾßÇϳª)[35]     whqkdnf000
07/31 12594
  [Reverse Engineering] ¸®¹ö½ÌÀÇ ±âÃÊ - ¹ü¿ë ·¹Áö½ºÅÍ¿Í Assembly(Pop,Mov)     zen0c1de
07/18 12580
1412   °³¹ßÀÚ°¡ ¾Ë¾Æ¾ßÇÒ 10°¡Áö º¸¾ÈÆÁÀ¸·Î Äڵ带 º¸È£ÇÏÀÚ.     Ǫ¸¥ÇÏ´Ã
09/01 12529
1411   C¾ð¾î ±âº»±¸Á¶[1]     ±«µµjs
07/02 12492
1410   ping¾Æ´Â Ä«Æä ÇØÅ· °í¼ö´Ô¿¡°Ô µéÀº ¼Ò¸®ÀÔ´Ï´Ù[21]     Àå¼¼¸¸
07/14 12489
1409   [Æß]ÇØÄ¿µéÀÇ ÈçÀûÁö¿ì´Â¹æ¹ý[28]     starztp
10/08 12449
1408   C¾ð¾î(Áø¹ý)[9]     whqkdnf000
02/25 12396
1407   ¿Ø¸¸ÇÑ»ç¶÷µéÀº´Ù¾ËÁöµµ¸ð¸£°ÚÁö¸¸[6]     ¹é·æÃâÇØ
03/17 12265
1406   trozan(Æ®·ÎÀ̸ñ¸¶) Æ÷Æ® ¸ñ·Ï[2]     whqkdnf000
02/22 12256
1405   c++ °­ÁÂ[7]     jhon55
08/12 12210
1404   [Æß] ÇØÅ·ÀÇ ¿ª»ç     dzhfldk
08/22 12175
1403   ¸®´ª½º ¸í·É¾î ÇѲ¨¹ø¿¡(¼ÒÀ¯´Ô²¨)[11]     ssakura
07/07 12134
1402   ³×Æ®¿öÅ© °³³ä ÈÖ¾îÀâ±â 7[8]     ¼ÒÀ¯
09/16 12104
[1][2][3][4][5][6][7][8] 9 [10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org