views:

117

answers:

1

Im currently trying to write a disassembler. I found the following list of opcodes and their meanings, so i decided to parse it at runtime: http://mprolab.teipir.gr/vivlio80X86/pentium.txt

But i am stuck at the opcode 0x00: It is followed by a reg/modbyte. Parsing it was not much of a problem for me. But i'm having trouble with the Scale-Index-Byte: If you actually specify esp as index register, it actually means that there is no index register. The same applys for the base register with ebp. But i've tryed it with c++ inline assembler: It is possible to compile: "add [ebp*2+ebp],cl"

So how can ebp be used as base register when using ebp as base register actually means using no base register at all !?

+1  A: 

The "missing EBP" case apply only in case ModR/M.Mod field has value 00 binary. Ïf you need EBP as a base, the assembler changes the Mod to 01 binary and adds 8-bit displacement with value of zero:

004C6D00 add [ebp+ebp*2], cl

MazeGen
Ok are there other missing registers for 8bit and 32bit displacement values then?Any other strange inordinatenesses?
Floste
Only EBP is "missing". Note that you can encode pure [displacement] addresing because of "missing ESP index" and "missing EBP base" two ways:000D 78563412 add [12345678], cl000C25 78563412 add [12345678], clHowever, in 64-bit mode, the first opcode means:000D 78563412 add [rip+12345678], clEDIT: shit, line breaks were eaten what makes the comment less readable.
MazeGen
Ok, now it works. Big thanks!
Floste