Static disassembly is powerful, but a debugger shows you the actual values as the program runs. This assignment covers how to inspect registers, stack arguments, and memory locations at a breakpoint so you can confirm what you guessed from the disassembly.
Imagine you set a breakpoint at encrypt_func right after the function prologue (so ebp is set up). The function signature and local variables are:
plaintext_buffer_pointer dword ptr 8
plaintext_buffer_length dword ptr 0Ch
buffer_1_pointer dword ptr 10h
buffer_2_pointer dword ptr 14h
arg_10 dword ptr 18h
enable_xor byte ptr 1Ch
You observe in the debugger:
- ebp = 0x0019F400
- ecx = 0x03A20C40
- The bytes at memory address 0x0019F408 are 42 00 00 00
- The bytes at memory address 0x0019F41C are 01 00 00 00
- The bytes at memory address 0x0019F414 are A0 3C B2 00
Practice reading these values and interpreting them as arguments.