#classroom #assignment #homework

Static disassembly is powerful, but a debugger shows you the actual values as the program runs. This assignment covers how to inspect registers, stack arguments, and memory locations at a breakpoint so you can confirm what you guessed from the disassembly.

Imagine you set a breakpoint at encrypt_func right after the function prologue (so ebp is set up). The function signature and local variables are:

plaintext_buffer_pointer  dword ptr  8
plaintext_buffer_length   dword ptr  0Ch
buffer_1_pointer          dword ptr  10h
buffer_2_pointer          dword ptr  14h
arg_10                    dword ptr  18h
enable_xor                byte ptr   1Ch

You observe in the debugger:
- ebp = 0x0019F400
- ecx = 0x03A20C40
- The bytes at memory address 0x0019F408 are 42 00 00 00
- The bytes at memory address 0x0019F41C are 01 00 00 00
- The bytes at memory address 0x0019F414 are A0 3C B2 00

Practice reading these values and interpreting them as arguments.