• No se han encontrado resultados

El medievo: nacimiento y recepción, con reparos, de las biblias romanceadas Las dos primeras versiones bíblicas

INTERVENCIÓN DE LA IGLESIA EN LA LABOR TRADUCTORA EL CASO DE LA BIBLIA EN ESPAÑA

3. El medievo: nacimiento y recepción, con reparos, de las biblias romanceadas Las dos primeras versiones bíblicas

Here is what we get in the assembly output (MSVC 2010):

lea eax, DWORD PTR _x$[ebp] push eax

push OFFSET $SG3833 ; '%d', 00H call _scanf

add esp, 8 cmp eax, 1

jne SHORT $LN2@main

mov ecx, DWORD PTR _x$[ebp] push ecx

push OFFSET $SG3834 ; 'You entered %d...', 0aH, 00H call _printf

add esp, 8

jmp SHORT $LN1@main $LN2@main:

push OFFSET $SG3836 ; 'What you entered? Huh?', 0aH, 00H call _printf

add esp, 4 $LN1@main:

xor eax, eax

Thecallerfunction (main()) needs thecalleefunction (scanf()) result, so thecalleereturns it in theEAXregister. We check it with the help of the instructionCMP EAX, 1(CoMPare). In other words, we compare the value in theEAX

register with 1.

4scanf, wscanf:MSDN 5End of file

AJNEconditional jump follows theCMPinstruction.JNEstands forJump if Not Equal.

So, if the value in theEAXregister is not equal to 1, theCPUwill pass the execution to the address mentioned in theJNE

operand, in our case$LN2@main. Passing the control to this address results in theCPUexecutingprintf()with the argumentWhat you entered? Huh?. But if everything is fine, the conditional jump is not be be taken, and another

printf()call is to be executed, with two arguments:'You entered %d...' and the value ofx.

Since in this case the secondprintf()has not to be executed, there is aJMPpreceding it (unconditional jump). It passes the control to the point after the secondprintf()and just before theXOR EAX, EAXinstruction, which implements

return 0.

So, it could be said that comparing a value with another isusuallyimplemented byCMP/Jccinstruction pair, wherecc is condition code. CMPcompares two values and sets processor flags6. Jccchecks those flags and decides to either pass the control to the specified address or not.

This could sound paradoxical, but theCMPinstruction is in factSUB(subtract). All arithmetic instructions set processor flags, not justCMP. If we compare 1 and 1,1−1is 0 so theZFflag would be set (meaning that the last result was 0). In no other circumstancesZFcan be set, except when the operands are equal. JNEchecks only theZFflag and jumps only if it is not set. JNEis in fact a synonym forJNZ(Jump if Not Zero). Assembler translates bothJNEandJNZinstructions into the same opcode. So, theCMPinstruction can be replaced with aSUBinstruction and almost everything will be fine, with the difference thatSUBalters the value of the first operand.CMPisSUB without saving the result, but affecting flags.

7.3.2 MSVC: x86: IDA

It is time to runIDAand try to do something in it. By the way, for beginners it is good idea to use/MDoption in MSVC, which means that all these standard functions are not be linked with the executable file, but are to be imported from the

MSVCR*.DLLfile instead. Thus it will be easier to see which standard function are used and where.

While analysing code inIDA, it is very helpful to leave notes for oneself (and others). In instance, analysing this example, we see thatJNZis to be triggered in case of an error. So it is possible to move the cursor to the label, press “n” and rename it to “error”. Create another label—into “exit”. Here is my result:

.text:00401000 _main proc near .text:00401000

.text:00401000 var_4 = dword ptr -4 .text:00401000 argc = dword ptr 8 .text:00401000 argv = dword ptr 0Ch .text:00401000 envp = dword ptr 10h .text:00401000

.text:00401000 push ebp .text:00401001 mov ebp, esp .text:00401003 push ecx

.text:00401004 push offset Format ; "Enter X:\n" .text:00401009 call ds:printf

.text:0040100F add esp, 4

.text:00401012 lea eax, [ebp+var_4] .text:00401015 push eax

.text:00401016 push offset aD ; "%d" .text:0040101B call ds:scanf

.text:00401021 add esp, 8 .text:00401024 cmp eax, 1 .text:00401027 jnz short error .text:00401029 mov ecx, [ebp+var_4] .text:0040102C push ecx

.text:0040102D push offset aYou ; "You entered %d...\n" .text:00401032 call ds:printf

.text:00401038 add esp, 8 .text:0040103B jmp short exit .text:0040103D

.text:0040103D error: ; CODE XREF: _main+27

.text:0040103D push offset aWhat ; "What you entered? Huh?\n" .text:00401042 call ds:printf

.text:00401048 add esp, 4 .text:0040104B

.text:0040104B exit: ; CODE XREF: _main+3B .text:0040104B xor eax, eax .text:0040104D mov esp, ebp .text:0040104F pop ebp

.text:00401050 retn .text:00401050 _main endp

Now it is slightly easier to understand the code. However, it is not a good idea to comment on every instruction.

You could also hide(collapse) parts of a function inIDA. To do that mark the block, then press “–” on the numerical pad and enter the text to be displayed instead.

Let’s hide two blocks and give them names:

.text:00401000 _text segment para public 'CODE' use32 .text:00401000 assume cs:_text

.text:00401000 ;org 401000h .text:00401000 ; ask for X

.text:00401012 ; get X

.text:00401024 cmp eax, 1 .text:00401027 jnz short error .text:00401029 ; print result

.text:0040103B jmp short exit .text:0040103D

.text:0040103D error: ; CODE XREF: _main+27

.text:0040103D push offset aWhat ; "What you entered? Huh?\n" .text:00401042 call ds:printf

.text:00401048 add esp, 4 .text:0040104B

.text:0040104B exit: ; CODE XREF: _main+3B .text:0040104B xor eax, eax

.text:0040104D mov esp, ebp .text:0040104F pop ebp .text:00401050 retn .text:00401050 _main endp

By pressing “space”, we can see howIDArepresents a function as a graph:

Figure 7.7: Graph mode in IDA

There are two arrows after each conditional jump: green and red. The green arrow points to the block which executes if the jump is triggered, and red if otherwise.

It is possible to fold nodes in this mode and give them names as well (“group nodes”). Let’s do it for 3 blocks:

Figure 7.8: Graph mode in IDA with 3 nodes folded

That is very useful. It could be said that a very important part of the reverse engineers’ job (and any other researcher as well) is to reduce the amount of information they deal with.

7.3.3 MSVC: x86 + OllyDbg

Let’s try to hack our program in OllyDbg, forcing it to thinkscanf()always works without error.

When an address of a local variable is passed intoscanf(), the variable initially contains some random garbage, in this case0x6E494714:

Whilescanf()executes, in the console we enter something that is definitely not a number, like “asdasd”.scanf()finishes with 0 inEAX, which indicates that an error has occurred:

Figure 7.10: OllyDbg: scanf()returning error

We can also check the local variable in the stack and note that it has not changed. Indeed, what wouldscanf()write there? It simply did nothing except returning zero.

Let’s try to “hack” our program. Right-click onEAX, Among the options there is “Set to 1”. This is what we need.

We now have 1 inEAX, so the following check is to be executed as intended, andprintf()will print the value of the variable in the stack.

When we run the program (F9) we can see the following in the console window:

Figure 7.11: console window

7.3.4 MSVC: x86 + Hiew

This can also be used as a simple example of executable file patching. We may try to patch the executable so the program would always print the input, no matter what we enter.

Assuming that the executable is compiled against externalMSVCR*.DLL(i.e., with/MDoption)7, we see themain()function at the beginning of the.textsection. Let’s open the executable in Hiew and find the beginning of the.textsection (Enter, F8, F6, Enter, Enter).

We can see this:

Figure 7.12: Hiew:main()function

Hiew findsASCIIZ8strings and displays them, as it does with the imported functions’ names.

7that’s what also called “dynamic linking” 8ASCII Zero (null-terminated ASCII string)

Move the cursor to address.00401027(where theJNZinstruction, we have to bypass, is located), press F3, and then type “9090”(, meaning twoNOPs):

Figure 7.13: Hiew: replacingJNZwith twoNOPs

Then press F9 (update). Now the executable is saved to the disk. It will behave as we wanted.

TwoNOPs are probably not the most æsthetic approach. Another way to patch this instruction is to write just 0 to the second opcode byte (jump offset), so thatJNZwill always jump to the next instruction.

We could also do the opposite: replace first byte withEBwhile not touching the second byte (jump offset). We would get an unconditional jump that is always triggered. In this case the error message would be printed every time, no matter the input.

7.3.5 MSVC: x64

Since we work here withint-typed variables, which are still 32-bit in x86-64, we see how the 32-bit part of the registers (prefixed withE-) are used here as well. While working with pointers, however, 64-bit register parts are used, prefixed with

R-.

Listing 7.12: MSVC 2012 x64

_DATA SEGMENT

$SG2924 DB 'Enter X:', 0aH, 00H $SG2926 DB '%d', 00H

$SG2927 DB 'You entered %d...', 0aH, 00H $SG2929 DB 'What you entered? Huh?', 0aH, 00H _DATA ENDS

_TEXT SEGMENT x$ = 32

main PROC $LN5:

sub rsp, 56

lea rcx, OFFSET FLAT:$SG2924 ; 'Enter X:' call printf

lea rdx, QWORD PTR x$[rsp]

lea rcx, OFFSET FLAT:$SG2926 ; '%d' call scanf

cmp eax, 1

jne SHORT $LN2@main

mov edx, DWORD PTR x$[rsp]

lea rcx, OFFSET FLAT:$SG2927 ; 'You entered %d...' call printf

jmp SHORT $LN1@main $LN2@main:

lea rcx, OFFSET FLAT:$SG2929 ; 'What you entered? Huh?' call printf

$LN1@main:

; return 0 xor eax, eax add rsp, 56 ret 0 main ENDP _TEXT ENDS END

7.3.6 ARM

ARM: Optimizing Keil 6/2013 (Thumb mode)

Listing 7.13: Optimizing Keil 6/2013 (Thumb mode)

var_8 = -8

PUSH {R3,LR}

ADR R0, aEnterX ; "Enter X:\n" BL __2printf MOV R1, SP ADR R0, aD ; "%d" BL __0scanf CMP R0, #1 BEQ loc_1E

ADR R0, aWhatYouEntered ; "What you entered? Huh?\n" BL __2printf

loc_1A ; CODE XREF: main+26

MOVS R0, #0 POP {R3,PC}

loc_1E ; CODE XREF: main+12

LDR R1, [SP,#8+var_8]

ADR R0, aYouEnteredD___ ; "You entered %d...\n" BL __2printf

B loc_1A

The new instructions here areCMPandBEQ9.

CMPis analogous to the x86 instruction with the same name, it subtracts one of the arguments from the other and updates the conditional flags if needed.

BEQ jumps to another address if the operands were equal to each other, or, if the result of the last computation was 0, or if the Z flag is 1. It behaves asJZin x86.

Everything else is simple: the execution flow forks in two branches, then the branches converge at the point where 0 is written into theR0as a function return value, and then the function ends.

ARM64

Listing 7.14: Non-optimizing GCC 4.9.1 ARM64 1 .LC0: 2 .string "Enter X:" 3 .LC1: 4 .string "%d" 5 .LC2:

6 .string "You entered %d...\n" 7 .LC3:

8 .string "What you entered? Huh?" 9 f6:

10 ; save FP and LR in stack frame: 11 stp x29, x30, [sp, -32]! 12 ; set stack frame (FP=SP)

13 add x29, sp, 0

14 ; load pointer to the "Enter X:" string:

15 adrp x0, .LC0

16 add x0, x0, :lo12:.LC0 17 bl puts

18 ; load pointer to the "%d" string:

19 adrp x0, .LC1

20 add x0, x0, :lo12:.LC1

21 ; calculate address of x variable in the local stack

22 add x1, x29, 28

23 bl __isoc99_scanf

24 ; scanf() returned result in W0. 25 ; check it:

26 cmp w0, 1

27 ; BNE is Branch if Not Equal

28 ; so if W0<>0, jump to L2 will be occurred 29 bne .L2

30 ; at this moment W0=1, meaning no error 31 ; load x value from the local stack

32 ldr w1, [x29,28]

33 ; load pointer to the "You entered %d...\n" string:

34 adrp x0, .LC2

35 add x0, x0, :lo12:.LC2

36 bl printf

37 ; skip the code, which print the "What you entered? Huh?" string:

38 b .L3

39 .L2:

40 ; load pointer to the "What you entered? Huh?" string:

41 adrp x0, .LC3 42 add x0, x0, :lo12:.LC3 43 bl puts 44 .L3: 45 ; return 0 46 mov w0, 0 47 ; restore FP and LR: 48 ldp x29, x30, [sp], 32 49 ret

Code flow in this case forks with the use of CMP/BNE (Branch if Not Equal) instructions pair.

7.3.7 MIPS

Listing 7.15: Optimizing GCC 4.4.5 (IDA)

.text:004006A0 main: .text:004006A0 .text:004006A0 var_18 = -0x18 .text:004006A0 var_10 = -0x10 .text:004006A0 var_4 = -4 .text:004006A0 .text:004006A0 lui $gp, 0x42 .text:004006A4 addiu $sp, -0x28 .text:004006A8 li $gp, 0x418960

.text:004006AC sw $ra, 0x28+var_4($sp) .text:004006B0 sw $gp, 0x28+var_18($sp)

.text:004006B4 la $t9, puts

.text:004006B8 lui $a0, 0x40

.text:004006BC jalr $t9 ; puts

.text:004006C0 la $a0, aEnterX # "Enter X:" .text:004006C4 lw $gp, 0x28+var_18($sp)

.text:004006C8 lui $a0, 0x40

.text:004006CC la $t9, __isoc99_scanf .text:004006D0 la $a0, aD # "%d" .text:004006D4 jalr $t9 ; __isoc99_scanf

.text:004006D8 addiu $a1, $sp, 0x28+var_10 # branch delay slot

.text:004006DC li $v1, 1

.text:004006E0 lw $gp, 0x28+var_18($sp) .text:004006E4 beq $v0, $v1, loc_40070C

.text:004006E8 or $at, $zero # branch delay slot, NOP

.text:004006EC la $t9, puts

.text:004006F0 lui $a0, 0x40

.text:004006F4 jalr $t9 ; puts

.text:004006F8 la $a0, aWhatYouEntered # "What you entered? Huh?" .text:004006FC lw $ra, 0x28+var_4($sp)

.text:00400700 move $v0, $zero

.text:00400704 jr $ra

.text:00400708 addiu $sp, 0x28 .text:0040070C loc_40070C:

.text:0040070C la $t9, printf

.text:00400710 lw $a1, 0x28+var_10($sp)

.text:00400714 lui $a0, 0x40

.text:00400718 jalr $t9 ; printf

.text:0040071C la $a0, aYouEnteredD___ # "You entered %d...\n" .text:00400720 lw $ra, 0x28+var_4($sp)

.text:00400724 move $v0, $zero

.text:00400728 jr $ra

.text:0040072C addiu $sp, 0x28

scanf()returns the result of its work in register $V0. It is checked at address 0x004006E4 by comparing the values in $V0 with $V1 (1 was stored in $V1 earlier, at 0x004006DC). BEQ stands for “Branch Equal”. If the two values are equal (i.e., success), the execution jumps to address 0x0040070C.

7.3.8 Exercise

As we can see, the JNE/JNZ instruction can be easily replaced by the JE/JZ and vice versa (or BNE by BEQ and vice versa). But then the basic blocks must also be swapped. Try to do this in some of the examples.

7.4 Exercise

Chapter 8

Accessing passed arguments

Now we figured out that thecallerfunction is passing arguments to thecalleevia the stack. But how does thecalleeaccess them?

Listing 8.1: simple example

#include <stdio.h>

int f (int a, int b, int c) { return a*b+c; }; int main() { printf ("%d\n", f(1, 2, 3)); return 0; };

8.1

x86

8.1.1

MSVC

Here is what we get after compilation (MSVC 2010 Express):

Listing 8.2: MSVC 2010 Express _TEXT SEGMENT _a$ = 8 ; size = 4 _b$ = 12 ; size = 4 _c$ = 16 ; size = 4 _f PROC push ebp mov ebp, esp

mov eax, DWORD PTR _a$[ebp] imul eax, DWORD PTR _b$[ebp] add eax, DWORD PTR _c$[ebp] pop ebp

ret 0

_f ENDP

_main PROC

push ebp mov ebp, esp

push 3 ; 3rd argument push 2 ; 2nd argument push 1 ; 1st argument call _f add esp, 12 push eax

call _printf add esp, 8 ; return 0 xor eax, eax pop ebp

ret 0

_main ENDP

What we see is that themain()function pushes 3 numbers onto the stack and callsf(int,int,int). Argument access insidef()is organized with the help of macros like:_a$ = 8, in the same way as local variables, but with positive offsets (addressed withplus). So, we are addressing theouterside of thestack frameby adding the_a$macro to the value in the

EBPregister.

Then the value ofais stored intoEAX. AfterIMULinstruction execution, the value inEAXis aproductof the value inEAX

and the content of _b. After that,ADDadds the value in _ctoEAX. The value inEAXdoes not need to be moved: it is already where it must be. On returning tocaller, it takes theEAXvalue and use it as an argument toprintf().

8.1.2

MSVC + OllyDbg

Let’s illustrate this in OllyDbg. When we trace to the first instruction inf()that uses one of the arguments (first one), we see thatEBPis pointing to thestack frame, which is marked with a red rectangle. The first element of thestack frameis the saved value ofEBP, the second one isRA, the third is the first function argument, then the second and third ones. To access the first function argument, one needs to add exactly 8 (2 32-bit words) toEBP.

OllyDbg is aware about this, so it has added comments to the stack elements like “RETURN from” and “Arg1 = …”, etc. N.B.: Function arguments are not members of the function’s stack frame, they are rather members of the stack frame of the

callerfunction. Hence, OllyDbg marked “Arg” elements as members of another stack frame.

Figure 8.1: OllyDbg: inside off()function

8.1.3

GCC

Let’s compile the same in GCC 4.4.1 and see the results inIDA:

Listing 8.3: GCC 4.4.1 public f f proc near arg_0 = dword ptr 8 arg_4 = dword ptr 0Ch arg_8 = dword ptr 10h push ebp mov ebp, esp

imul eax, [ebp+arg_4] ; 2nd argument add eax, [ebp+arg_8] ; 3rd argument pop ebp

retn

f endp

public main

main proc near

var_10 = dword ptr -10h var_C = dword ptr -0Ch var_8 = dword ptr -8

push ebp mov ebp, esp

and esp, 0FFFFFFF0h sub esp, 10h

mov [esp+10h+var_8], 3 ; 3rd argument mov [esp+10h+var_C], 2 ; 2nd argument mov [esp+10h+var_10], 1 ; 1st argument call f

mov edx, offset aD ; "%d\n" mov [esp+10h+var_C], eax mov [esp+10h+var_10], edx call _printf

mov eax, 0 leave

retn

main endp

The result is almost the same with some minor differences discussed earlier.

Thestack pointeris not set back after the two function calls(f and printf), because the penultimateLEAVE(A.6.2 on page 886) instruction takes care of this at the end.

8.2

x64

The story is a bit different in x86-64. Function arguments (first 4 or first 6 of them) are passed in registers i.e. thecallee

reads them from registers instead of reading them from the stack.

8.2.1

MSVC

Optimizing MSVC: Listing 8.4: Optimizing MSVC 2012 x64 $SG2997 DB '%d', 0aH, 00H main PROC sub rsp, 40 mov edx, 2 lea r8d, QWORD PTR [rdx+1] ; R8D=3 lea ecx, QWORD PTR [rdx-1] ; ECX=1 call f

lea rcx, OFFSET FLAT:$SG2997 ; '%d' mov edx, eax

call printf xor eax, eax add rsp, 40 ret 0 main ENDP f PROC ; ECX - 1st argument ; EDX - 2nd argument ; R8D - 3rd argument imul ecx, edx

lea eax, DWORD PTR [r8+rcx]

ret 0

f ENDP

As we can see, the compact functionf()takes all its arguments from the registers. TheLEAinstruction here is used for addition, apparently the compiler considered it faster thanADD.LEAis also used in themain()function to prepare the first and thirdf()arguments. The compiler must have decided that this would work faster than the usual way of loading values into a register usingMOVinstruction.

Let’s take a look at the non-optimizing MSVC output:

Listing 8.5: MSVC 2012 x64 f proc near ; shadow space: arg_0 = dword ptr 8 arg_8 = dword ptr 10h arg_10 = dword ptr 18h ; ECX - 1st argument ; EDX - 2nd argument ; R8D - 3rd argument mov [rsp+arg_10], r8d mov [rsp+arg_8], edx mov [rsp+arg_0], ecx