Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
How We Found Another XSS in Google with Acunetix
Some time ago, Russian security researchers Andrey Leonov and Link found an XSS in Google Cloud with the help of Acunetix. Recently they found another XSS vulnerability. Here is how it happened. Read on Β»



https://preview.redd.it/8k5mfavrfnh41.png?width=910&format=png&auto=webp&s=9f163a59304f45574a3b17b591d48170411d1926
πŸ—£AcunetixLtd


πŸŽ–@malwr
Purpose of `mov edi, edi`?
I was debugging a Windows' built in program and notices that almost all subroutines starts with mov edi, edi. e.g.

subsomething proc near
mov edi, edi
push ebp
mov ebp, esp
;do something...
leave
retn
sub
something endp

AFAIU, that mov edi, edi practically does nothing and affect nothing, and it only wastes space and computing time.

It seems like it's specific to Microsoft based C language compiled modules, cause I also use Delphi to create Windows programs, and none of their functions has such asm code pattern.

So, what's the purpose of that instruction?
πŸ—£jcunews1

It's a nop. It's there for patching. Intel doesn't actually have formal nop instructions! For nops people often write xchg eax, eax, or something like this if they want a longer nop.
πŸ‘€chrisgseaton

It's a no-op, on purpose, that can be overwritten.

Raymond Chen explains it, here: https://devblogs.microsoft.com/oldnewthing/20110921-00/?p=9583
πŸ‘€chunkyks

https://devblogs.microsoft.com/oldnewthing/20110921-00/?p=9583
πŸ‘€jedwardsol


πŸŽ–@malwr