lea vs mov [mem] in x86 Assembly

Two instructions look similar in disassembly but do opposite things with memory. | Instruction | What it does | C analogy | |-------------|--------------|-----------| | `mov ecx,…

Decoding IDA-Style Argument Offsets

In 32-bit x86 code compiled with a stack-based calling convention [[x86 Calling Conventions: cdecl vs stdcall]] (`cdecl` or `stdcall`), arguments are accessed as positive offsets …

Function Prologue Decomposition Methodology

# Function Prologue Decomposition Methodology When you open an x86 function, do not read line-by-line. Read the **prologue as one block** and answer these five questions before a…

Big-endian vs little-endian byte order

x86 and x86-64 use **little-endian** [[Endianness in x86/x86_64 Memory]]: the least-significant byte of a multi-byte value is stored at the lowest memory address. ## Reading a va…

Endianness in x86/x86_64 Memory

# Endianness in x86/x86_64 Memory **[[Endianness and Memory Layout|Endianness]]** describes the order in which the bytes of a multi-byte value are stored in memory. ## Little-en…

Endianness and Memory Layout

# Endianness and Memory Layout When a CPU stores a multi-byte integer in memory, it must choose which byte goes at the lowest address. That choice is called **endianness**. ## K…

x86 rand() Calling Convention and Return Value

# x86 `rand()` Calling Convention and Return Value In x86 assembly, the C standard library function `rand()` is called like any other function: ```asm call _rand ``` ## Signatu…

WinDbg Stack Inspection Commands

# WinDbg Stack Inspection Commands Use these commands to inspect values that have been pushed onto the stack, especially right before a function call. ## Core command ```windbg…

Function Thunks and Stubs

# Function Thunks and Stubs A **thunk** (also called a *stub* or *trampoline*) is a tiny function whose only purpose is to forward execution to another function. It does little o…

x86 Calling Conventions: cdecl vs stdcall

# x86 Calling Conventions: cdecl vs stdcall A **calling convention** is the contract between a caller and a callee that answers two questions: 1. How are arguments passed? 2. Wh…