From: "class 101" Date: Wed, 9 Mar 2005 10:01:57 +0100
Here is the result of comparing some huge list of pop/pop/ret of XP SP1, SP1a, SP2 ENGLISH
I got 2 universal offsets accross those 3 Os
SP2 ENGLISH
0x71ABE325 pop esi - pop - retbis - WS2_32.DLL 0x77E7F69E pop ebx - pop - retbis - RPCRT4.DLL
SP1a ENGLISH
0x71ABE325 pop edi - pop - retbis - WS2_32.DLL 0x77E7F69E pop ebx - pop - retbis - KERNEL32.DLL
SP1 ENGLISH
0x71ABE325 pop edi - pop - retbis - WS2_32.DLL 0x77E7F69E pop ebx - pop - retbis - KERNEL32.DLL
enjoy :)
0:003> u 0x71ABE325 WS2_32!CopyBlobIndirect+0x71: 71abe325 5f pop edi 71abe326 5e pop esi 71abe327 c20400 ret 0x4
cheers, DaveK -- Can't think of a witty .sigline today....
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://www.secunia.com/