Re: A couple of questions regarding registers etc...



Rod Pemberton wrote:
If 'PUSH mycode.00490344' is pushing only eight bytes total, then ESP+8 is
the pushed ECX and ESP+12 is the pushed EAX. So, ESP+10 is the two bytes of
the high word of ECX and the two bytes of low word of EAX not in a useable
byte order...(this doesn't make sense to me from the posted snippet).

You forget the numbers were in hexadecimal.


Bjarni
--

INFORMATION WANTS TO BE FREE

.