![]() |
|
|
|
#1
|
|||
|
|||
|
just so you know - MS did not implement inline asm in x64 because it is 'unsafe'. apparently they are very concerned about noobs who have no clue what they are doing. they did same with default values for methods in c# - no such thing there because 'it might confuse programmer'.
regarding inline asm 'black box' theory - is all crap. i made a testcase just to see this, because it even sounds so much unreasonable. Code:
00FD1045 sub edi,1 while(i != 0) 00FD1048 jne main+22h (0FD1022h) } __asm xor ebx, ebx // should be restored after asm block 00FD104A xor ebx,ebx char naughtyNumber[255]; itoa(a + b, naughtyNumber, 16); 00FD104C push 10h 00FD104E lea eax,[esp+10h] 00FD1052 push eax 00FD1053 add esi,ecx 00FD1055 push esi 00FD1056 call _itoa (0FD7258h) 00FD105B add esp,0Ch |
| The Following User Says Thank You to rox For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#2
|
||||
|
||||
|
AFAIK, EBX is the one register not used in most WINAPI functions.
M$ like when programmers do things 'their way' ... whether or not they have valid reason is subject of debate, I think =) Removing inline assembly from x64 just made a pain in the ass. Just like how they not document many ntapi functions... leaving the reverser/programmer to spend much time looking finding their hidden known. -Fyyre |
| The Following User Says Thank You to Fyyre For This Useful Post: | ||
Indigo (07-19-2019) | ||
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| inline patche | hp3 | Source Code | 3 | 06-04-2021 14:48 |
| How to inline x64 asm in vs2017 ? | Mahmoudnia | General Discussion | 25 | 07-22-2018 01:04 |
| Inline Patching | MaRKuS-DJM | General Discussion | 1 | 01-24-2004 23:03 |