2016-05-03 02:14:34 +01:00
# ELF Header
7F 45 4C 46 ## e_ident[EI_MAG0-3] ELF's magic number
02 ## e_ident[EI_CLASS] Indicating 64 bit
01 ## e_ident[EI_DATA] Indicating little endianness
01 ## e_ident[EI_VERSION] Indicating original elf
00 ## e_ident[EI_OSABI] Set at 0 because none cares
00 ## e_ident[EI_ABIVERSION] See above
00 00 00 00 00 00 00 ## e_ident[EI_PAD]
02 00 ## e_type Indicating Executable
3E 00 ## e_machine Indicating AMD64
01 00 00 00 ## e_version Indicating original elf
78 00 60 00 00 00 00 00 ## e_entry Address of the entry point
40 00 00 00 00 00 00 00 ## e_phoff Address of program header table
00 00 00 00 00 00 00 00 ## e_shoff Address of section header table
00 00 00 00 ## e_flags
40 00 ## e_ehsize Indicating our 64 Byte header
38 00 ## e_phentsize size of a program header table
01 00 ## e_phnum number of entries in program table
00 00 ## e_shentsize size of a section header table
00 00 ## e_shnum number of entries in section table
00 00 ## e_shstrndx index of the section names
# Program Header Table
01 00 00 00 ## p_type
06 00 00 00 ## Flags
00 00 00 00 00 00 00 00 ## p_offset
00 00 60 00 00 00 00 00 ## p_vaddr
00 00 00 00 00 00 00 00 ## Undefined
F1 00 00 00 00 00 00 00 ## p_filesz
F1 00 00 00 00 00 00 00 ## p_memsz
00 00 20 00 00 00 00 00 ## Required alignment
# Start
58 # pop %rax
5f # pop %rdi
5f # pop %rdi
48 83 f8 02 # cmp $0x2,%rax
75 5f # jne 6000e0 <Bail>
48 c7 c6 00 00 00 00 # mov $0x0,%rsi
48 c7 c0 02 00 00 00 # mov $0x2,%rax
0f 05 # syscall
48 85 c0 # test %rax,%rax
78 4a # js 6000e0 <Bail>
48 89 c7 # mov %rax,%rdi
# Circle
48 c7 c2 00 00 00 40 # mov $0x40000000,%rdx
48 c7 c6 f0 00 60 00 # mov $0x6000f0,%rsi
48 c7 c0 00 00 00 00 # mov $0x0,%rax
0f 05 # syscall
48 85 c0 # test %rax,%rax
74 1b # je 6000d0 <Done>
48 89 c2 # mov %rax,%rdx
48 89 fc # mov %rdi,%rsp
48 c7 c7 01 00 00 00 # mov $0x1,%rdi
48 c7 c0 01 00 00 00 # mov $0x1,%rax
0f 05 # syscall
48 89 e7 # mov %rsp,%rdi
eb c9 # jmp 600099 <Circle>
# Done
48 c7 c7 00 00 00 00 # mov $0x0,%rdi
48 c7 c0 3c 00 00 00 # mov $0x3c,%rax
0f 05 # syscall
# Bail
48 c7 c7 01 00 00 00 # mov $0x0,%rdi
48 c7 c0 3c 00 00 00 # mov $0x3c,%rax
0f 05 # syscall