Hacker News new | past | comments | ask | show | jobs | submit login

requires overwriting the instruction

Not quite. Some processors, including X86, have hardware support for breakpoints (http://en.wikipedia.org/wiki/X86_debug_register). It may also be possible to (mis)use virtual memory hardware for setting breakpoints. Also [pedantic], one overwrites a byte, not an instruction.

Using a single byte is necessary because the program could jump to (address+1). If that address contained part of the breakpoint code, program semantics could change. O, and jumping to (address+1) could even be useful if address contains a multi-byte instruction.




Could you elaborate on your "jump to (address+1)" argument? Why does this make a single-byte "int 3" necessary?


Give a sequence like (using Intel mnemonics):

        mov eax,[x]
        or  eax,eax
        jz  foo
        dec eax
    foo call bar
The instruction "dec eax" is one byte in size. If you want to place a breakpoint there, and you used the two byte form of "int 3", then when the code did the "jz foo" (jump if the previous result was zero to location foo) the "call bar" instruction would be partially overwritten and form a new instruction. If the condition leading the breakpoint isn't taken, you now have some other instruction (it ends up being an "add" instruction) which is bad.

That's why there's a one byte version of "int 3", because there are one byte instructions.


Yep, this is what I meant in my own comment: http://news.ycombinator.net/item?id=2132005

Just thought you're referring to something else. Thanks for clearing this up; I hope you don't mind if I use your example in the next part of the series. :-)


Consider this sequence:

     0041301E  33 D2     xor edx, edx
     00413020  83 E8 02  sub eax, 2
     00413023  74 01     jz loc_00413026
     00413025  4A        dec edx
     00413026  ...
Without a single-byte int 3, a break on dec edx will mess up everything if that branch is not taken.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: