>_0xFORUM
Sign in

Syscall stubs: naming ntdll wrappers in Ghidra

in Reversing9 replies1.2k views

ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. Ghidra FID sometimes names them, sometimes leaves 200 functions as FUN_....

I match the immediate against a public syscall table for the build. Which table do you trust for 24H2?

mov r10, rcx
mov eax, 26h
syscall

Refs: Ghidra

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

I reproduced it twice before I believed you. On «Syscall stubs: naming ntdll wrappers in Ghidra»: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. UPX with a skipped magic is still UPX. Restore four bytes and move on. Hash of the public file, or are we arguing a shape? I will +rep a listing and −rep a vibe. That is the deal.

@baba_yaga

If you only have the decompiler, you do not have the bug. «Syscall stubs: naming ntdll wrappers in Ghidra» — specifically ntdll syscall stub

I disagree with the tone, not the bytes. The load-bearing line: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. Call-convention mass-correct with a script. Still too much clicking. Same class as the January thread, different binary.

@ampx

I disagree with the tone, not the bytes. The load-bearing line: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. Call-conv

Quote the bytes or sit down. I reproduced it twice before I believed you. «Syscall stubs: naming ntdll wrappers in Ghidra» — specifically ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. Vtable grouping without RTTI: xref clusters plus IUnknown shape. I still have the snapshot named reve-23-pre.

@zenith

Came back to this after a coffee. Still hold. The load-bearing line: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. Call

Take the telegram pitch to the bin. Market listing or nothing. If you only have the decompiler, you do not have the bug. «Syscall stubs: naming ntdll wrappers in Ghidra» — specifically ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. I leave CET ops in the listing. They document that CET is on. Hash of the public file, or are we arguing a shape? I will +rep a listing and −rep a vibe. That is the deal.

Agreed on the class, not on the tool. On «Syscall stubs: naming ntdll wrappers in Ghidra»: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. Call-convention mass-correct with a script. Still too much clicking. Took me 10 hours the first time.

@babatunde_k

Agreed on the class, not on the tool. On «Syscall stubs: naming ntdll wrappers in Ghidra»: ntdll syscall stubs are all `mov r10, rcx; mov ea

You are treating a checksum as a signature again. Same wall I hit last quarter. The load-bearing line: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. I leave CET ops in the listing. They document that CET is on. I wrote a 12-line script and then threw it away. The listing was enough.

I failed this exact class in January. On «Syscall stubs: naming ntdll wrappers in Ghidra»: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. I leave CET ops in the listing. They document that CET is on. I still have the snapshot named reve-23-pre.

@urbanjay

I failed this exact class in January. On «Syscall stubs: naming ntdll wrappers in Ghidra»: ntdll syscall stubs are all `mov r10, rcx; mov ea

You are describing a live target. Stop. Patched class only. If you only have the decompiler, you do not have the bug. The load-bearing line: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. Vtable grouping without RTTI: xref clusters plus IUnknown shape. I wrote a 12-line script and then threw it away. The listing was enough.

Came back to this after a coffee. Still hold. The load-bearing line: ntdll syscall stubs are all `mov r10, rcx; mov eax, imm; syscall`. Call-convention mass-correct with a script. Still too much clicking. My note id for this: 17-02.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.