Confusing hook..

Posts 16–23 of 23 · Page 2 of 2
zeco I love it when you end up answering your own questions. xD

Cracks me up every time I read ur posts. cuz its like ur thinking out loud
Quote Originally Posted by why06 View Post
zeco I love it when you end up answering your own questions. xD

Cracks me up every time I read ur posts. cuz its like ur thinking out loud
Damnit. . . I was hoping that no-one saw that. . . >_>

Well, In my defense, it wasn't that stupid of a question this time. It's just that I decided to test it out, and surprisingly got very nice results.

Edit: Oh, never mind, you did not see it. I was just being overly paranoid. You are just referring to the first part of my post that i forgot about. ^_^"

I've edited my previous post like 6 times. I even had an elaborate example at one point, before I found the answer myself.

But either way, it wasn't very surprising that i couldn't use Labels like addresses in C++, but it was quite a pleasant surprise that you could do so in the inline assembler. Very useful indeed, That way, i could technically put labels on both ends of code i might want to move somewhere, it definitely makes copying large blocks of code with WriteProcessMemory a lot easier. Well. . . A lot easier than finding the Opcodes yourself and putting it in a byte array. Actually. I think I want to try putting random code in byte arrays now.
Quote Originally Posted by zeco View Post
Actually. I think I want to try putting random code in byte arrays now.
Yeh same. I think it looks something like this:

BYTE byteArray[] = {0x34}, {0x9A}, {0xB1};

somethin like that. probably an address thrown in.

I think its really cool that at the asm level code directly turn in to numbers. with no added crap.
Quote Originally Posted by why06 View Post
Yeh same. I think it looks something like this:

BYTE byteArray[] = {0x34}, {0x9A}, {0xB1};

somethin like that. probably an address thrown in.

I think its really cool that at the asm level code directly turn in to numbers. with no added crap.
Hmmm or this way. Much simpler. I think yours also works also but i'm not sure.


BYTE byteArray[] = {0x34, 0x9A, 0xB1};
Quote Originally Posted by zeco View Post
Hmmm or this way. Much simpler. I think yours also works also but i'm not sure.


BYTE byteArray[] = {0x34, 0x9A, 0xB1};
Idk... I always screw up on notation, but I get the concept.
Quote Originally Posted by why06 View Post
Idk... I always screw up on notation, but I get the concept.
Actually, that leads me to another question, how does the CPU, and Olly, know in which combination the bytes go together? The opcodes are bytes in a certain way (like E9 -- -- -- -- for jump), but how does it tell which bytes go together to make an opcode? Like which ones to group together.
Well it accepts the opcode first. Then it knows what kind of argument to take after it.

so a mov instruction would have a couple different opcodes for different sizes of data, or sizes of registers. Least I think that's how it would work. Im prbly wrong ;l Good question.
Quote Originally Posted by why06 View Post
Well it accepts the opcode first. Then it knows what kind of argument to take after it.

so a mov instruction would have a couple different opcodes for different sizes of data, or sizes of registers. Least I think that's how it would work. Im prbly wrong ;l Good question.
That sounds like a reasonable enough answer for me to stop thinking about it. Good answer.
Posts 16–23 of 23 · Page 2 of 2
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?