Dissassemblers/Debuggers

Posts 1–12 of 12 · Page 1 of 1
Dissassemblers/Debuggers
Another annoying question From Zeco =) Yaaaaay!

In disassemblers and debuggers, what do the addresses refer to? Or Does the computer memory actually hold things like assembly instructions in addition to data? Actually, thinking things through, that kinda makes more sense... So when using a disassembler/debugger, we are seeing theoretical, virtual memory locations? So when the program actually launches, that's how it's memory will be laid out, just in a different location? And if this is the case, how do we know what is data in a disassemblers, like the data that is usually changed When someone plays with a memory editor.

Sorry if this makes absolutely no sense. Ask for Clarification if need be >_<
Certain registers will often store data such as EAX/ AX/ AH. Also data is just literally assigned to certain address locations and you can see what those are in the disassembler

add eax, 0x8329FC23

This would add eax to the value in that memory location and then save the new value to 0x8329FC23
Quote Originally Posted by why06 View Post
Certain registers will often store data such as EAX/ AX/ AH. Also data is just literally assigned to certain address locations and you can see what those are in the disassembler

add eax, 0x8329FC23

This would add eax to the value in that memory location and then save the new value to 0x8329FC23
Not sure which syntax you're using, but it looks like intel, and if so, it's actually

add eax, DWORD [location In memory]

DWORD specifies how many bytes to read from that location. It can be WORD and BYTE as well. Then the result is stored in the first parameter(eax register).

The only difference between the data section of a program, and the code section, is that the code section has different permissions with a different name, containing different data. If a program is meant to be run in a VM, then the code segments don't actually contain executable code, but byte code which is translated into something readable by the processor. Java does this. Otherwise, yes, those opcodes are thrown at the processor, and processed by the processor.
So im assuming then that means everything else i said is correct? Or people don't like me =<
Quote Originally Posted by zeco View Post
So im assuming then that means everything else i said is correct? Or people don't like me =<
Probably both. =\
Hmm OK let's try this again.... When in a disassembler, there are what seems to be memory addresses to the side. I'm assuming that it means when the program actually starts, it will keep its structure, but the addresses will be different. That brings me to 2 questions

A.) What is the significance of the numbers that are there before the program starts? When in a debugger all the addresses are high up (77******) but when in a disassembler the addresses are in a low register (00******)

The disassembler addresses kind of make more sense because i recognize the number 00461000. It was the lowest address that isn't used by the system right? Or the base address for executables. but the one in the debugger seems kind of arbitrary

B.) Does that mean, when you run a program, everything you see in the disassembly window goes into RAM? That would kind of make sense seeing as you are not only able to change address values of processes, but also do things like code injections.

I think, that is all

Debugger : Ollydbg
Disassembler : IDA pro
Please god tell me you're using a warez version of IDA Pro Zeco. Because if I remember correctly, they're licensed version is like $2300.
No Comment. For anything i say may hold up in the court of law.

Actually i'm using a free version. When they make a new version, the previous ones become free.

I have no idea how to pirate

Now back to my question s'il vous plait
Quote Originally Posted by zeco View Post
No Comment. For anything i say may hold up in the court of law.

Actually i'm using a free version. When they make a new version, the previous ones become free.

I have no idea how to pirate
God that's good to hear. I was gonna say if you have $2300 to blow on a disassembler, why are you here at MPGH? You should be at some ritzy college learning this stuff. xD
>_> Screw you J.
Hmm i just realised that this thread is in the wrong section.... Can't bother reposting it. But yeah someone answer please =).

And i love you too J <3
Now J, teach me all your programming. >_>
Posts 1–12 of 12 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us