Winsock fd_set Structure (0x104 Signature)

On 32-bit Windows, the fd_set structure from Winsock (winsock2.h) is exactly 260 bytes, or 0x104. That makes 0x104 a useful signature when reverse engineering.

Structure breakdown:

typedef struct fd_set {
    u_int  fd_count;              // 4 bytes
    SOCKET fd_array[FD_SETSIZE];  // 64 × 4 bytes = 256 bytes
} fd_set;                         // total = 260 = 0x104

When you see assembly like:

lea     eax, [ebp+writefds]
push    104h
push    esi
push    eax
call    _memset

It is very likely clearing a fd_set for select():

memset(&writefds, 0, sizeof(fd_set));   // i.e. FD_ZERO(&writefds);

Common fd_set variable names in disassembly are readfds, writefds, and exceptfds. Combined with timeout and a socket-like argument, this is the classic setup for the select() API.

This is a pattern recognition shortcut, not a guarantee: always verify the calling convention and argument order, and treat 0x104 as a strong clue rather than proof.

Related: x86 CDECL Calling Convention