incorrect disassemble

Nick Clifton nickc@cambridge.redhat.com
Tue Feb 19 06:54:00 GMT 2002
Hi Michael,

> I'm using GNU objdump 2.11.90.0.19 the target is elf32-i386, its a 
> backdoored ssh daemon. I've included the relevant part of the
> disassembly:
>
> 804c0b8:	8a 04 11             	mov    (%ecx,%edx,1),%al     ; <---
> 804c0bb:	24 0f                	and    $0xf,%al
> 804c0bd:	0c 30                	or     $0x30,%al
> 804c0bf:	88 44 32 01          	mov    %al,0x1(%edx,%esi,1)  ; <---
> 804c0c3:	8a 04 11             	mov    (%ecx,%edx,1),%al
> 804c0c6:	c0 e8 04             	shr    $0x4,%al
> 804c0c9:	0c 30                	or     $0x30,%al
> 804c0cb:	88 04 32             	mov    %al,(%edx,%esi,1)     ; <---
> 804c0ce:	83 c6 fe             	add    $0xfffffffe,%esi

Do you have the original assembler source for these particular
instructions ?  If so please could you post it here ?

Cheers
        Nick



More information about the Binutils mailing list