mod_cassette.so: file format elf32-i386 Disassembly of section .init: 000009fc <_init>: 9fc: 53 push ebx 9fd: 83 ec 08 sub esp,0x8 a00: e8 eb 01 00 00 call bf0 <__sprintf_chk@plt+0x10> a05: 81 c3 23 25 00 00 add ebx,0x2523 a0b: 8b 83 a4 00 00 00 mov eax,DWORD PTR [ebx+0xa4] a11: 85 c0 test eax,eax a13: 74 05 je a1a <_init+0x1e> a15: e8 f6 00 00 00 call b10 <__gmon_start__@plt> a1a: 83 c4 08 add esp,0x8 a1d: 5b pop ebx a1e: c3 ret Disassembly of section .plt: 00000a20 <__snprintf_chk@plt-0x10>: a20: ff b3 04 00 00 00 push DWORD PTR [ebx+0x4] a26: ff a3 08 00 00 00 jmp DWORD PTR [ebx+0x8] a2c: 00 00 add BYTE PTR [eax],al ... 00000a30 <__snprintf_chk@plt>: a30: ff a3 0c 00 00 00 jmp DWORD PTR [ebx+0xc] a36: 68 00 00 00 00 push 0x0 a3b: e9 e0 ff ff ff jmp a20 <_init+0x24> 00000a40 : a40: ff a3 10 00 00 00 jmp DWORD PTR [ebx+0x10] a46: 68 08 00 00 00 push 0x8 a4b: e9 d0 ff ff ff jmp a20 <_init+0x24> 00000a50 : a50: ff a3 14 00 00 00 jmp DWORD PTR [ebx+0x14] a56: 68 10 00 00 00 push 0x10 a5b: e9 c0 ff ff ff jmp a20 <_init+0x24> 00000a60 : a60: ff a3 18 00 00 00 jmp DWORD PTR [ebx+0x18] a66: 68 18 00 00 00 push 0x18 a6b: e9 b0 ff ff ff jmp a20 <_init+0x24> 00000a70 : a70: ff a3 1c 00 00 00 jmp DWORD PTR [ebx+0x1c] a76: 68 20 00 00 00 push 0x20 a7b: e9 a0 ff ff ff jmp a20 <_init+0x24> 00000a80 : a80: ff a3 20 00 00 00 jmp DWORD PTR [ebx+0x20] a86: 68 28 00 00 00 push 0x28 a8b: e9 90 ff ff ff jmp a20 <_init+0x24> 00000a90 <__stack_chk_fail@plt>: a90: ff a3 24 00 00 00 jmp DWORD PTR [ebx+0x24] a96: 68 30 00 00 00 push 0x30 a9b: e9 80 ff ff ff jmp a20 <_init+0x24> 00000aa0 : aa0: ff a3 28 00 00 00 jmp DWORD PTR [ebx+0x28] aa6: 68 38 00 00 00 push 0x38 aab: e9 70 ff ff ff jmp a20 <_init+0x24> 00000ab0 : ab0: ff a3 2c 00 00 00 jmp DWORD PTR [ebx+0x2c] ab6: 68 40 00 00 00 push 0x40 abb: e9 60 ff ff ff jmp a20 <_init+0x24> 00000ac0 <__cxa_finalize@plt>: ac0: ff a3 30 00 00 00 jmp DWORD PTR [ebx+0x30] ac6: 68 48 00 00 00 push 0x48 acb: e9 50 ff ff ff jmp a20 <_init+0x24> 00000ad0 <__xstat@plt>: ad0: ff a3 34 00 00 00 jmp DWORD PTR [ebx+0x34] ad6: 68 50 00 00 00 push 0x50 adb: e9 40 ff ff ff jmp a20 <_init+0x24> 00000ae0 : ae0: ff a3 38 00 00 00 jmp DWORD PTR [ebx+0x38] ae6: 68 58 00 00 00 push 0x58 aeb: e9 30 ff ff ff jmp a20 <_init+0x24> 00000af0 : af0: ff a3 3c 00 00 00 jmp DWORD PTR [ebx+0x3c] af6: 68 60 00 00 00 push 0x60 afb: e9 20 ff ff ff jmp a20 <_init+0x24> 00000b00 : b00: ff a3 40 00 00 00 jmp DWORD PTR [ebx+0x40] b06: 68 68 00 00 00 push 0x68 b0b: e9 10 ff ff ff jmp a20 <_init+0x24> 00000b10 <__gmon_start__@plt>: b10: ff a3 44 00 00 00 jmp DWORD PTR [ebx+0x44] b16: 68 70 00 00 00 push 0x70 b1b: e9 00 ff ff ff jmp a20 <_init+0x24> 00000b20 : b20: ff a3 48 00 00 00 jmp DWORD PTR [ebx+0x48] b26: 68 78 00 00 00 push 0x78 b2b: e9 f0 fe ff ff jmp a20 <_init+0x24> 00000b30 : b30: ff a3 4c 00 00 00 jmp DWORD PTR [ebx+0x4c] b36: 68 80 00 00 00 push 0x80 b3b: e9 e0 fe ff ff jmp a20 <_init+0x24> 00000b40 : b40: ff a3 50 00 00 00 jmp DWORD PTR [ebx+0x50] b46: 68 88 00 00 00 push 0x88 b4b: e9 d0 fe ff ff jmp a20 <_init+0x24> 00000b50 : b50: ff a3 54 00 00 00 jmp DWORD PTR [ebx+0x54] b56: 68 90 00 00 00 push 0x90 b5b: e9 c0 fe ff ff jmp a20 <_init+0x24> 00000b60 : b60: ff a3 58 00 00 00 jmp DWORD PTR [ebx+0x58] b66: 68 98 00 00 00 push 0x98 b6b: e9 b0 fe ff ff jmp a20 <_init+0x24> 00000b70 : b70: ff a3 5c 00 00 00 jmp DWORD PTR [ebx+0x5c] b76: 68 a0 00 00 00 push 0xa0 b7b: e9 a0 fe ff ff jmp a20 <_init+0x24> 00000b80 : b80: ff a3 60 00 00 00 jmp DWORD PTR [ebx+0x60] b86: 68 a8 00 00 00 push 0xa8 b8b: e9 90 fe ff ff jmp a20 <_init+0x24> 00000b90 : b90: ff a3 64 00 00 00 jmp DWORD PTR [ebx+0x64] b96: 68 b0 00 00 00 push 0xb0 b9b: e9 80 fe ff ff jmp a20 <_init+0x24> 00000ba0 : ba0: ff a3 68 00 00 00 jmp DWORD PTR [ebx+0x68] ba6: 68 b8 00 00 00 push 0xb8 bab: e9 70 fe ff ff jmp a20 <_init+0x24> 00000bb0 : bb0: ff a3 6c 00 00 00 jmp DWORD PTR [ebx+0x6c] bb6: 68 c0 00 00 00 push 0xc0 bbb: e9 60 fe ff ff jmp a20 <_init+0x24> 00000bc0 : bc0: ff a3 70 00 00 00 jmp DWORD PTR [ebx+0x70] bc6: 68 c8 00 00 00 push 0xc8 bcb: e9 50 fe ff ff jmp a20 <_init+0x24> 00000bd0 : bd0: ff a3 74 00 00 00 jmp DWORD PTR [ebx+0x74] bd6: 68 d0 00 00 00 push 0xd0 bdb: e9 40 fe ff ff jmp a20 <_init+0x24> 00000be0 <__sprintf_chk@plt>: be0: ff a3 78 00 00 00 jmp DWORD PTR [ebx+0x78] be6: 68 d8 00 00 00 push 0xd8 beb: e9 30 fe ff ff jmp a20 <_init+0x24> Disassembly of section .text: 00000bf0 <.text>: bf0: 8b 1c 24 mov ebx,DWORD PTR [esp] bf3: c3 ret bf4: 66 90 xchg ax,ax bf6: 66 90 xchg ax,ax bf8: 66 90 xchg ax,ax bfa: 66 90 xchg ax,ax bfc: 66 90 xchg ax,ax bfe: 66 90 xchg ax,ax c00: 55 push ebp c01: 89 e5 mov ebp,esp c03: 53 push ebx c04: e8 e7 ff ff ff call bf0 <__sprintf_chk@plt+0x10> c09: 81 c3 1f 23 00 00 add ebx,0x231f c0f: 83 ec 14 sub esp,0x14 c12: 8d 83 13 04 00 00 lea eax,[ebx+0x413] c18: 8d 93 10 04 00 00 lea edx,[ebx+0x410] c1e: 29 d0 sub eax,edx c20: 83 f8 06 cmp eax,0x6 c23: 77 06 ja c2b <__sprintf_chk@plt+0x4b> c25: 83 c4 14 add esp,0x14 c28: 5b pop ebx c29: 5d pop ebp c2a: c3 ret c2b: 8b 83 88 00 00 00 mov eax,DWORD PTR [ebx+0x88] c31: 85 c0 test eax,eax c33: 74 f0 je c25 <__sprintf_chk@plt+0x45> c35: 89 14 24 mov DWORD PTR [esp],edx c38: ff d0 call eax c3a: eb e9 jmp c25 <__sprintf_chk@plt+0x45> c3c: 8d 74 26 00 lea esi,[esi+eiz*1+0x0] c40: 55 push ebp c41: 89 e5 mov ebp,esp c43: 53 push ebx c44: e8 a7 ff ff ff call bf0 <__sprintf_chk@plt+0x10> c49: 81 c3 df 22 00 00 add ebx,0x22df c4f: 83 ec 14 sub esp,0x14 c52: 8d 83 10 04 00 00 lea eax,[ebx+0x410] c58: 8d 93 10 04 00 00 lea edx,[ebx+0x410] c5e: 29 d0 sub eax,edx c60: c1 f8 02 sar eax,0x2 c63: 89 c1 mov ecx,eax c65: c1 e9 1f shr ecx,0x1f c68: 01 c8 add eax,ecx c6a: d1 f8 sar eax,1 c6c: 75 06 jne c74 <__sprintf_chk@plt+0x94> c6e: 83 c4 14 add esp,0x14 c71: 5b pop ebx c72: 5d pop ebp c73: c3 ret c74: 8b 8b bc 00 00 00 mov ecx,DWORD PTR [ebx+0xbc] c7a: 85 c9 test ecx,ecx c7c: 74 f0 je c6e <__sprintf_chk@plt+0x8e> c7e: 89 44 24 04 mov DWORD PTR [esp+0x4],eax c82: 89 14 24 mov DWORD PTR [esp],edx c85: ff d1 call ecx c87: eb e5 jmp c6e <__sprintf_chk@plt+0x8e> c89: 8d b4 26 00 00 00 00 lea esi,[esi+eiz*1+0x0] c90: 55 push ebp c91: 89 e5 mov ebp,esp c93: 53 push ebx c94: e8 57 ff ff ff call bf0 <__sprintf_chk@plt+0x10> c99: 81 c3 8f 22 00 00 add ebx,0x228f c9f: 83 ec 14 sub esp,0x14 ca2: 80 bb 18 04 00 00 00 cmp BYTE PTR [ebx+0x418],0x0 ca9: 75 24 jne ccf <__sprintf_chk@plt+0xef> cab: 8b 83 9c 00 00 00 mov eax,DWORD PTR [ebx+0x9c] cb1: 85 c0 test eax,eax cb3: 74 0e je cc3 <__sprintf_chk@plt+0xe3> cb5: 8b 83 d8 00 00 00 mov eax,DWORD PTR [ebx+0xd8] cbb: 89 04 24 mov DWORD PTR [esp],eax cbe: e8 fd fd ff ff call ac0 <__cxa_finalize@plt> cc3: e8 38 ff ff ff call c00 <__sprintf_chk@plt+0x20> cc8: c6 83 18 04 00 00 01 mov BYTE PTR [ebx+0x418],0x1 ccf: 83 c4 14 add esp,0x14 cd2: 5b pop ebx cd3: 5d pop ebp cd4: c3 ret cd5: 8d 74 26 00 lea esi,[esi+eiz*1+0x0] cd9: 8d bc 27 00 00 00 00 lea edi,[edi+eiz*1+0x0] ce0: 55 push ebp ce1: 89 e5 mov ebp,esp ce3: 53 push ebx ce4: e8 07 ff ff ff call bf0 <__sprintf_chk@plt+0x10> ce9: 81 c3 3f 22 00 00 add ebx,0x223f cef: 83 ec 14 sub esp,0x14 cf2: 8b 83 d4 fe ff ff mov eax,DWORD PTR [ebx-0x12c] cf8: 85 c0 test eax,eax cfa: 74 15 je d11 <__sprintf_chk@plt+0x131> cfc: 8b 83 b8 00 00 00 mov eax,DWORD PTR [ebx+0xb8] d02: 85 c0 test eax,eax d04: 74 0b je d11 <__sprintf_chk@plt+0x131> d06: 8d 93 d4 fe ff ff lea edx,[ebx-0x12c] d0c: 89 14 24 mov DWORD PTR [esp],edx d0f: ff d0 call eax d11: 83 c4 14 add esp,0x14 d14: 5b pop ebx d15: 5d pop ebp d16: e9 25 ff ff ff jmp c40 <__sprintf_chk@plt+0x60> d1b: 66 90 xchg ax,ax d1d: 66 90 xchg ax,ax d1f: 90 nop d20: 53 push ebx d21: e8 ca fe ff ff call bf0 <__sprintf_chk@plt+0x10> d26: 81 c3 02 22 00 00 add ebx,0x2202 d2c: 83 ec 18 sub esp,0x18 d2f: 8d 83 78 ea ff ff lea eax,[ebx-0x1588] d35: 89 44 24 04 mov DWORD PTR [esp+0x4],eax d39: 8b 44 24 28 mov eax,DWORD PTR [esp+0x28] d3d: 89 04 24 mov DWORD PTR [esp],eax d40: e8 fb fd ff ff call b40 d45: 85 c0 test eax,eax d47: 8b 83 90 00 00 00 mov eax,DWORD PTR [ebx+0x90] d4d: 74 11 je d60 <__sprintf_chk@plt+0x180> d4f: c7 00 00 00 00 00 mov DWORD PTR [eax],0x0 d55: 83 c4 18 add esp,0x18 d58: 31 c0 xor eax,eax d5a: 5b pop ebx d5b: c3 ret d5c: 8d 74 26 00 lea esi,[esi+eiz*1+0x0] d60: c7 00 01 00 00 00 mov DWORD PTR [eax],0x1 d66: 83 c4 18 add esp,0x18 d69: 31 c0 xor eax,eax d6b: 5b pop ebx d6c: c3 ret d6d: 8d 76 00 lea esi,[esi+0x0] d70: 53 push ebx d71: e8 7a fe ff ff call bf0 <__sprintf_chk@plt+0x10> d76: 81 c3 b2 21 00 00 add ebx,0x21b2 d7c: 83 ec 18 sub esp,0x18 d7f: 8b 83 2c 04 00 00 mov eax,DWORD PTR [ebx+0x42c] d85: 85 c0 test eax,eax d87: 74 1f je da8 <__sprintf_chk@plt+0x1c8> d89: 8b 83 28 04 00 00 mov eax,DWORD PTR [ebx+0x428] d8f: 85 c0 test eax,eax d91: 74 15 je da8 <__sprintf_chk@plt+0x1c8> d93: 8b 83 24 04 00 00 mov eax,DWORD PTR [ebx+0x424] d99: 85 c0 test eax,eax d9b: 74 0b je da8 <__sprintf_chk@plt+0x1c8> d9d: 83 c4 18 add esp,0x18 da0: 5b pop ebx da1: c3 ret da2: 8d b6 00 00 00 00 lea esi,[esi+0x0] da8: 8d 83 30 ea ff ff lea eax,[ebx-0x15d0] dae: 89 04 24 mov DWORD PTR [esp],eax db1: e8 ba fd ff ff call b70 db6: 89 83 2c 04 00 00 mov DWORD PTR [ebx+0x42c],eax dbc: 8d 83 40 ea ff ff lea eax,[ebx-0x15c0] dc2: 89 04 24 mov DWORD PTR [esp],eax dc5: e8 a6 fd ff ff call b70 dca: 89 83 28 04 00 00 mov DWORD PTR [ebx+0x428],eax dd0: 8d 83 4f ea ff ff lea eax,[ebx-0x15b1] dd6: 89 04 24 mov DWORD PTR [esp],eax dd9: e8 92 fd ff ff call b70 dde: 8b 8b 2c 04 00 00 mov ecx,DWORD PTR [ebx+0x42c] de4: 85 c9 test ecx,ecx de6: 89 83 24 04 00 00 mov DWORD PTR [ebx+0x424],eax dec: 74 0e je dfc <__sprintf_chk@plt+0x21c> dee: 8b 93 28 04 00 00 mov edx,DWORD PTR [ebx+0x428] df4: 85 d2 test edx,edx df6: 74 04 je dfc <__sprintf_chk@plt+0x21c> df8: 85 c0 test eax,eax dfa: 75 a1 jne d9d <__sprintf_chk@plt+0x1bd> dfc: c7 04 24 01 00 00 00 mov DWORD PTR [esp],0x1 e03: e8 18 fd ff ff call b20 e08: 90 nop e09: 8d b4 26 00 00 00 00 lea esi,[esi+eiz*1+0x0] e10: 55 push ebp e11: 57 push edi e12: 89 d7 mov edi,edx e14: 56 push esi e15: 89 c6 mov esi,eax e17: 53 push ebx e18: e8 d3 fd ff ff call bf0 <__sprintf_chk@plt+0x10> e1d: 81 c3 0b 21 00 00 add ebx,0x210b e23: 83 ec 1c sub esp,0x1c e26: c7 04 24 80 02 00 00 mov DWORD PTR [esp],0x280 e2d: e8 be fc ff ff call af0 e32: 85 c0 test eax,eax e34: 89 c5 mov ebp,eax e36: 74 6a je ea2 <__sprintf_chk@plt+0x2c2> e38: 89 74 24 0c mov DWORD PTR [esp+0xc],esi e3c: 8d b3 15 eb ff ff lea esi,[ebx-0x14eb] e42: 89 74 24 08 mov DWORD PTR [esp+0x8],esi e46: c7 44 24 04 00 01 00 mov DWORD PTR [esp+0x4],0x100 e4d: 00 e4e: 89 04 24 mov DWORD PTR [esp],eax e51: e8 fa fc ff ff call b50 e56: 8d 85 00 01 00 00 lea eax,[ebp+0x100] e5c: 89 7c 24 0c mov DWORD PTR [esp+0xc],edi e60: 89 74 24 08 mov DWORD PTR [esp+0x8],esi e64: 8d b3 68 eb ff ff lea esi,[ebx-0x1498] e6a: c7 44 24 04 00 01 00 mov DWORD PTR [esp+0x4],0x100 e71: 00 e72: 89 04 24 mov DWORD PTR [esp],eax e75: e8 d6 fc ff ff call b50 e7a: 8d 85 00 02 00 00 lea eax,[ebp+0x200] e80: b9 19 00 00 00 mov ecx,0x19 e85: 89 c7 mov edi,eax e87: 8b 83 94 00 00 00 mov eax,DWORD PTR [ebx+0x94] e8d: f3 a5 rep movs DWORD PTR es:[edi],DWORD PTR ds:[esi] e8f: 8b 10 mov edx,DWORD PTR [eax] e91: 8b 83 a8 00 00 00 mov eax,DWORD PTR [ebx+0xa8] e97: c7 04 d0 00 00 00 00 mov DWORD PTR [eax+edx*8],0x0 e9e: 89 6c d0 04 mov DWORD PTR [eax+edx*8+0x4],ebp ea2: 83 c4 1c add esp,0x1c ea5: 5b pop ebx ea6: 5e pop esi ea7: 5f pop edi ea8: 5d pop ebp ea9: c3 ret eaa: 8d b6 00 00 00 00 lea esi,[esi+0x0] eb0: 56 push esi eb1: 53 push ebx eb2: e8 39 fd ff ff call bf0 <__sprintf_chk@plt+0x10> eb7: 81 c3 71 20 00 00 add ebx,0x2071 ebd: 83 ec 14 sub esp,0x14 ec0: 8b 74 24 20 mov esi,DWORD PTR [esp+0x20] ec4: c7 44 24 0c 14 00 00 mov DWORD PTR [esp+0xc],0x14 ecb: 00 ecc: c7 44 24 08 00 00 00 mov DWORD PTR [esp+0x8],0x0 ed3: 00 ed4: c7 44 24 04 00 00 00 mov DWORD PTR [esp+0x4],0x0 edb: 00 edc: 8d 83 18 e9 ff ff lea eax,[ebx-0x16e8] ee2: 89 04 24 mov DWORD PTR [esp],eax ee5: e8 76 fb ff ff call a60 eea: 8d 83 5e ea ff ff lea eax,[ebx-0x15a2] ef0: 89 44 24 04 mov DWORD PTR [esp+0x4],eax ef4: 89 34 24 mov DWORD PTR [esp],esi ef7: e8 84 fc ff ff call b80 efc: 8d 83 48 de ff ff lea eax,[ebx-0x21b8] f02: 89 04 24 mov DWORD PTR [esp],eax f05: c7 44 24 0c 0a 00 00 mov DWORD PTR [esp+0xc],0xa f0c: 00 f0d: c7 44 24 08 00 00 00 mov DWORD PTR [esp+0x8],0x0 f14: 00 f15: c7 44 24 04 00 00 00 mov DWORD PTR [esp+0x4],0x0 f1c: 00 f1d: e8 8e fb ff ff call ab0 f22: 83 c4 14 add esp,0x14 f25: 8d 93 0a eb ff ff lea edx,[ebx-0x14f6] f2b: 8d 83 7b ea ff ff lea eax,[ebx-0x1585] f31: 5b pop ebx f32: 5e pop esi f33: e9 d8 fe ff ff jmp e10 <__sprintf_chk@plt+0x230> f38: 90 nop f39: 8d b4 26 00 00 00 00 lea esi,[esi+eiz*1+0x0] f40: 53 push ebx f41: e8 aa fc ff ff call bf0 <__sprintf_chk@plt+0x10> f46: 81 c3 e2 1f 00 00 add ebx,0x1fe2 f4c: 83 ec 18 sub esp,0x18 f4f: 8b 83 90 00 00 00 mov eax,DWORD PTR [ebx+0x90] f55: 8b 00 mov eax,DWORD PTR [eax] f57: 85 c0 test eax,eax f59: 74 1f je f7a <__sprintf_chk@plt+0x39a> f5b: e8 80 fb ff ff call ae0 f60: 89 44 24 08 mov DWORD PTR [esp+0x8],eax f64: 8d 83 8c ea ff ff lea eax,[ebx-0x1574] f6a: 89 44 24 04 mov DWORD PTR [esp+0x4],eax f6e: 8b 44 24 20 mov eax,DWORD PTR [esp+0x20] f72: 89 04 24 mov DWORD PTR [esp],eax f75: e8 d6 fa ff ff call a50 f7a: 83 c4 18 add esp,0x18 f7d: 5b pop ebx f7e: c3 ret f7f: 90 nop f80: 57 push edi f81: b9 05 00 00 00 mov ecx,0x5 f86: 56 push esi f87: 53 push ebx f88: 8b 44 24 10 mov eax,DWORD PTR [esp+0x10] f8c: e8 5f fc ff ff call bf0 <__sprintf_chk@plt+0x10> f91: 81 c3 97 1f 00 00 add ebx,0x1f97 f97: 8b 50 48 mov edx,DWORD PTR [eax+0x48] f9a: 8d bb 98 ea ff ff lea edi,[ebx-0x1568] fa0: 89 d6 mov esi,edx fa2: f3 a6 repz cmps BYTE PTR ds:[esi],BYTE PTR es:[edi] fa4: 0f 97 c0 seta al fa7: 0f 92 c1 setb cl faa: 31 f6 xor esi,esi fac: 38 c8 cmp al,cl fae: 74 18 je fc8 <__sprintf_chk@plt+0x3e8> fb0: 0f b6 0a movzx ecx,BYTE PTR [edx] fb3: 83 f9 41 cmp ecx,0x41 fb6: 74 18 je fd0 <__sprintf_chk@plt+0x3f0> fb8: 83 f9 44 cmp ecx,0x44 fbb: 75 2c jne fe9 <__sprintf_chk@plt+0x409> fbd: 80 7a 01 45 cmp BYTE PTR [edx+0x1],0x45 fc1: 74 5d je 1020 <__sprintf_chk@plt+0x440> fc3: 83 ce ff or esi,0xffffffff fc6: 66 90 xchg ax,ax fc8: 89 f0 mov eax,esi fca: 5b pop ebx fcb: 5e pop esi fcc: 5f pop edi fcd: c3 ret fce: 66 90 xchg ax,ax fd0: 80 7a 01 44 cmp BYTE PTR [edx+0x1],0x44 fd4: 75 ed jne fc3 <__sprintf_chk@plt+0x3e3> fd6: 80 7a 02 44 cmp BYTE PTR [edx+0x2],0x44 fda: 75 e7 jne fc3 <__sprintf_chk@plt+0x3e3> fdc: 80 7a 03 00 cmp BYTE PTR [edx+0x3],0x0 fe0: 75 e1 jne fc3 <__sprintf_chk@plt+0x3e3> fe2: be 01 00 00 00 mov esi,0x1 fe7: eb df jmp fc8 <__sprintf_chk@plt+0x3e8> fe9: 8b 83 90 00 00 00 mov eax,DWORD PTR [ebx+0x90] fef: be ff ff ff ff mov esi,0xffffffff ff4: 8b 00 mov eax,DWORD PTR [eax] ff6: 85 c0 test eax,eax ff8: 74 ce je fc8 <__sprintf_chk@plt+0x3e8> ffa: 83 f9 47 cmp ecx,0x47 ffd: 75 c9 jne fc8 <__sprintf_chk@plt+0x3e8> fff: 80 7a 01 45 cmp BYTE PTR [edx+0x1],0x45 1003: 75 c3 jne fc8 <__sprintf_chk@plt+0x3e8> 1005: 80 7a 02 54 cmp BYTE PTR [edx+0x2],0x54 1009: 75 bd jne fc8 <__sprintf_chk@plt+0x3e8> 100b: 31 c0 xor eax,eax 100d: 80 7a 03 00 cmp BYTE PTR [edx+0x3],0x0 1011: 0f 95 c0 setne al 1014: 89 c6 mov esi,eax 1016: f7 de neg esi 1018: eb ae jmp fc8 <__sprintf_chk@plt+0x3e8> 101a: 8d b6 00 00 00 00 lea esi,[esi+0x0] 1020: 80 7a 02 4c cmp BYTE PTR [edx+0x2],0x4c 1024: 75 9d jne fc3 <__sprintf_chk@plt+0x3e3> 1026: 80 7a 03 00 cmp BYTE PTR [edx+0x3],0x0 102a: 75 97 jne fc3 <__sprintf_chk@plt+0x3e3> 102c: be 02 00 00 00 mov esi,0x2 1031: eb 95 jmp fc8 <__sprintf_chk@plt+0x3e8> 1033: 8d b6 00 00 00 00 lea esi,[esi+0x0] 1039: 8d bc 27 00 00 00 00 lea edi,[edi+eiz*1+0x0] 1040: 55 push ebp 1041: 57 push edi 1042: 56 push esi 1043: 53 push ebx 1044: e8 a7 fb ff ff call bf0 <__sprintf_chk@plt+0x10> 1049: 81 c3 df 1e 00 00 add ebx,0x1edf 104f: 81 ec 8c 10 00 00 sub esp,0x108c 1055: 65 a1 14 00 00 00 mov eax,gs:0x14 105b: 89 84 24 7c 10 00 00 mov DWORD PTR [esp+0x107c],eax 1062: 31 c0 xor eax,eax 1064: 8b 84 24 a0 10 00 00 mov eax,DWORD PTR [esp+0x10a0] 106b: 8d 7c 24 7c lea edi,[esp+0x7c] 106f: c7 44 24 0c 00 10 00 mov DWORD PTR [esp+0xc],0x1000 1076: 00 1077: 8b b4 24 a4 10 00 00 mov esi,DWORD PTR [esp+0x10a4] 107e: c7 44 24 08 01 00 00 mov DWORD PTR [esp+0x8],0x1 1085: 00 1086: 8b ac 24 a8 10 00 00 mov ebp,DWORD PTR [esp+0x10a8] 108d: c7 44 24 04 00 10 00 mov DWORD PTR [esp+0x4],0x1000 1094: 00 1095: 89 44 24 18 mov DWORD PTR [esp+0x18],eax 1099: 8d 83 9d ea ff ff lea eax,[ebx-0x1563] 109f: 89 44 24 14 mov DWORD PTR [esp+0x14],eax 10a3: 8d 83 b3 ea ff ff lea eax,[ebx-0x154d] 10a9: 89 44 24 10 mov DWORD PTR [esp+0x10],eax 10ad: 89 3c 24 mov DWORD PTR [esp],edi 10b0: e8 7b f9 ff ff call a30 <__snprintf_chk@plt> 10b5: 8b 83 30 04 00 00 mov eax,DWORD PTR [ebx+0x430] 10bb: 85 c0 test eax,eax 10bd: 0f 84 cd 00 00 00 je 1190 <__sprintf_chk@plt+0x5b0> 10c3: 8b 00 mov eax,DWORD PTR [eax] 10c5: 8d 93 b8 ea ff ff lea edx,[ebx-0x1548] 10cb: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 10cf: 8d 83 c9 ea ff ff lea eax,[ebx-0x1537] 10d5: 89 54 24 18 mov DWORD PTR [esp+0x18],edx 10d9: 89 04 24 mov DWORD PTR [esp],eax 10dc: 89 7c 24 1c mov DWORD PTR [esp+0x1c],edi 10e0: 89 6c 24 14 mov DWORD PTR [esp+0x14],ebp 10e4: c7 44 24 10 00 00 00 mov DWORD PTR [esp+0x10],0x0 10eb: 00 10ec: c7 44 24 0c 02 00 00 mov DWORD PTR [esp+0xc],0x2 10f3: 00 10f4: c7 44 24 04 9f 00 00 mov DWORD PTR [esp+0x4],0x9f 10fb: 00 10fc: e8 8f fa ff ff call b90 1101: 8d 44 24 24 lea eax,[esp+0x24] 1105: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 1109: 89 7c 24 04 mov DWORD PTR [esp+0x4],edi 110d: c7 04 24 03 00 00 00 mov DWORD PTR [esp],0x3 1114: e8 b7 f9 ff ff call ad0 <__xstat@plt> 1119: 8b 4c 24 34 mov ecx,DWORD PTR [esp+0x34] 111d: 31 c0 xor eax,eax 111f: 81 e1 00 f0 00 00 and ecx,0xf000 1125: 81 f9 00 80 00 00 cmp ecx,0x8000 112b: 74 1b je 1148 <__sprintf_chk@plt+0x568> 112d: 8b 94 24 7c 10 00 00 mov edx,DWORD PTR [esp+0x107c] 1134: 65 33 15 14 00 00 00 xor edx,DWORD PTR gs:0x14 113b: 75 5d jne 119a <__sprintf_chk@plt+0x5ba> 113d: 81 c4 8c 10 00 00 add esp,0x108c 1143: 5b pop ebx 1144: 5e pop esi 1145: 5f pop edi 1146: 5d pop ebp 1147: c3 ret 1148: 85 f6 test esi,esi 114a: 74 e1 je 112d <__sprintf_chk@plt+0x54d> 114c: 89 3c 24 mov DWORD PTR [esp],edi 114f: 31 ed xor ebp,ebp 1151: c7 44 24 04 00 00 00 mov DWORD PTR [esp+0x4],0x0 1158: 00 1159: e8 d2 f9 ff ff call b30 115e: 89 c7 mov edi,eax 1160: b8 00 00 40 00 mov eax,0x400000 1165: 29 e8 sub eax,ebp 1167: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 116b: 8d 04 2e lea eax,[esi+ebp*1] 116e: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1172: 89 3c 24 mov DWORD PTR [esp],edi 1175: e8 c6 f8 ff ff call a40 117a: 01 c5 add ebp,eax 117c: 85 c0 test eax,eax 117e: 7f e0 jg 1160 <__sprintf_chk@plt+0x580> 1180: 89 3c 24 mov DWORD PTR [esp],edi 1183: e8 48 fa ff ff call bd0 1188: 89 e8 mov eax,ebp 118a: eb a1 jmp 112d <__sprintf_chk@plt+0x54d> 118c: 8d 74 26 00 lea esi,[esi+eiz*1+0x0] 1190: b8 ff ff ff ff mov eax,0xffffffff 1195: e9 2b ff ff ff jmp 10c5 <__sprintf_chk@plt+0x4e5> 119a: e8 91 07 00 00 call 1930 <__sprintf_chk@plt+0xd50> 119f: 90 nop 11a0: 55 push ebp 11a1: 57 push edi 11a2: 56 push esi 11a3: 53 push ebx 11a4: 83 ec 1c sub esp,0x1c 11a7: 8b 44 24 30 mov eax,DWORD PTR [esp+0x30] 11ab: e8 40 fa ff ff call bf0 <__sprintf_chk@plt+0x10> 11b0: 81 c3 78 1d 00 00 add ebx,0x1d78 11b6: 8b 7c 24 34 mov edi,DWORD PTR [esp+0x34] 11ba: 8b 74 24 38 mov esi,DWORD PTR [esp+0x38] 11be: 85 c0 test eax,eax 11c0: 75 16 jne 11d8 <__sprintf_chk@plt+0x5f8> 11c2: 83 c4 1c add esp,0x1c 11c5: 89 f2 mov edx,esi 11c7: 5b pop ebx 11c8: 89 f8 mov eax,edi 11ca: 5e pop esi 11cb: 5f pop edi 11cc: 5d pop ebp 11cd: e9 3e fc ff ff jmp e10 <__sprintf_chk@plt+0x230> 11d2: 8d b6 00 00 00 00 lea esi,[esi+0x0] 11d8: c7 04 24 80 05 00 00 mov DWORD PTR [esp],0x580 11df: e8 0c f9 ff ff call af0 11e4: 85 c0 test eax,eax 11e6: 89 c5 mov ebp,eax 11e8: 74 6a je 1254 <__sprintf_chk@plt+0x674> 11ea: 89 7c 24 0c mov DWORD PTR [esp+0xc],edi 11ee: 8d bb 15 eb ff ff lea edi,[ebx-0x14eb] 11f4: 89 7c 24 08 mov DWORD PTR [esp+0x8],edi 11f8: c7 44 24 04 00 01 00 mov DWORD PTR [esp+0x4],0x100 11ff: 00 1200: 89 04 24 mov DWORD PTR [esp],eax 1203: e8 48 f9 ff ff call b50 1208: 8d 85 00 01 00 00 lea eax,[ebp+0x100] 120e: 89 74 24 0c mov DWORD PTR [esp+0xc],esi 1212: 8d b3 cc eb ff ff lea esi,[ebx-0x1434] 1218: 89 7c 24 08 mov DWORD PTR [esp+0x8],edi 121c: c7 44 24 04 00 04 00 mov DWORD PTR [esp+0x4],0x400 1223: 00 1224: 89 04 24 mov DWORD PTR [esp],eax 1227: e8 24 f9 ff ff call b50 122c: 8d 85 00 05 00 00 lea eax,[ebp+0x500] 1232: b9 17 00 00 00 mov ecx,0x17 1237: 89 c7 mov edi,eax 1239: 8b 83 94 00 00 00 mov eax,DWORD PTR [ebx+0x94] 123f: f3 a5 rep movs DWORD PTR es:[edi],DWORD PTR ds:[esi] 1241: 8b 10 mov edx,DWORD PTR [eax] 1243: 8b 83 a8 00 00 00 mov eax,DWORD PTR [ebx+0xa8] 1249: c7 04 d0 01 00 00 00 mov DWORD PTR [eax+edx*8],0x1 1250: 89 6c d0 04 mov DWORD PTR [eax+edx*8+0x4],ebp 1254: 83 c4 1c add esp,0x1c 1257: 5b pop ebx 1258: 5e pop esi 1259: 5f pop edi 125a: 5d pop ebp 125b: c3 ret 125c: 8d 74 26 00 lea esi,[esi+eiz*1+0x0] 1260: 55 push ebp 1261: 57 push edi 1262: 56 push esi 1263: 53 push ebx 1264: 81 ec 3c 08 00 00 sub esp,0x83c 126a: e8 81 f9 ff ff call bf0 <__sprintf_chk@plt+0x10> 126f: 81 c3 b9 1c 00 00 add ebx,0x1cb9 1275: 8b b4 24 50 08 00 00 mov esi,DWORD PTR [esp+0x850] 127c: 65 a1 14 00 00 00 mov eax,gs:0x14 1282: 89 84 24 2c 08 00 00 mov DWORD PTR [esp+0x82c],eax 1289: 31 c0 xor eax,eax 128b: 8d 44 24 28 lea eax,[esp+0x28] 128f: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1293: 89 34 24 mov DWORD PTR [esp],esi 1296: e8 65 f8 ff ff call b00 129b: 8d 83 d8 ea ff ff lea eax,[ebx-0x1528] 12a1: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 12a5: 8b 44 24 28 mov eax,DWORD PTR [esp+0x28] 12a9: 89 04 24 mov DWORD PTR [esp],eax 12ac: e8 cf f7 ff ff call a80 12b1: 85 c0 test eax,eax 12b3: 89 c7 mov edi,eax 12b5: 0f 84 8d 00 00 00 je 1348 <__sprintf_chk@plt+0x768> 12bb: c7 04 24 01 00 40 00 mov DWORD PTR [esp],0x400001 12c2: e8 29 f8 ff ff call af0 12c7: 89 74 24 08 mov DWORD PTR [esp+0x8],esi 12cb: 89 3c 24 mov DWORD PTR [esp],edi 12ce: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 12d2: 89 c5 mov ebp,eax 12d4: e8 67 fd ff ff call 1040 <__sprintf_chk@plt+0x460> 12d9: 85 c0 test eax,eax 12db: 75 33 jne 1310 <__sprintf_chk@plt+0x730> 12dd: 89 2c 24 mov DWORD PTR [esp],ebp 12e0: e8 8b f7 ff ff call a70 12e5: b8 94 01 00 00 mov eax,0x194 12ea: 8b 8c 24 2c 08 00 00 mov ecx,DWORD PTR [esp+0x82c] 12f1: 65 33 0d 14 00 00 00 xor ecx,DWORD PTR gs:0x14 12f8: 0f 85 6b 02 00 00 jne 1569 <__sprintf_chk@plt+0x989> 12fe: 81 c4 3c 08 00 00 add esp,0x83c 1304: 5b pop ebx 1305: 5e pop esi 1306: 5f pop edi 1307: 5d pop ebp 1308: c3 ret 1309: 8d b4 26 00 00 00 00 lea esi,[esi+eiz*1+0x0] 1310: 8d 93 de ea ff ff lea edx,[ebx-0x1522] 1316: 89 54 24 04 mov DWORD PTR [esp+0x4],edx 131a: 89 34 24 mov DWORD PTR [esp],esi 131d: 89 44 24 1c mov DWORD PTR [esp+0x1c],eax 1321: e8 7a f7 ff ff call aa0 1326: 8b 44 24 1c mov eax,DWORD PTR [esp+0x1c] 132a: 89 74 24 08 mov DWORD PTR [esp+0x8],esi 132e: 89 2c 24 mov DWORD PTR [esp],ebp 1331: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1335: e8 66 f8 ff ff call ba0 133a: 89 2c 24 mov DWORD PTR [esp],ebp 133d: e8 2e f7 ff ff call a70 1342: 31 c0 xor eax,eax 1344: eb a4 jmp 12ea <__sprintf_chk@plt+0x70a> 1346: 66 90 xchg ax,ax 1348: 8d 83 28 eb ff ff lea eax,[ebx-0x14d8] 134e: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1352: 8b 44 24 28 mov eax,DWORD PTR [esp+0x28] 1356: 89 04 24 mov DWORD PTR [esp],eax 1359: e8 22 f7 ff ff call a80 135e: 90 nop 135f: 85 c0 test eax,eax 1361: 0f 84 d1 00 00 00 je 1438 <__sprintf_chk@plt+0x858> 1367: c7 44 24 08 0a 00 00 mov DWORD PTR [esp+0x8],0xa 136e: 00 136f: c7 44 24 04 00 00 00 mov DWORD PTR [esp+0x4],0x0 1376: 00 1377: 89 04 24 mov DWORD PTR [esp],eax 137a: e8 41 f8 ff ff call bc0 137f: 89 c7 mov edi,eax 1381: b8 94 01 00 00 mov eax,0x194 1386: 85 ff test edi,edi 1388: 0f 88 5c ff ff ff js 12ea <__sprintf_chk@plt+0x70a> 138e: 8b 93 94 00 00 00 mov edx,DWORD PTR [ebx+0x94] 1394: 39 3a cmp DWORD PTR [edx],edi 1396: 0f 8c 4e ff ff ff jl 12ea <__sprintf_chk@plt+0x70a> 139c: 8d 83 e8 ea ff ff lea eax,[ebx-0x1518] 13a2: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 13a6: 89 34 24 mov DWORD PTR [esp],esi 13a9: e8 f2 f6 ff ff call aa0 13ae: 8b 83 a8 00 00 00 mov eax,DWORD PTR [ebx+0xa8] 13b4: 8b 6c f8 04 mov ebp,DWORD PTR [eax+edi*8+0x4] 13b8: 83 3c f8 01 cmp DWORD PTR [eax+edi*8],0x1 13bc: 8d 47 01 lea eax,[edi+0x1] 13bf: 89 44 24 14 mov DWORD PTR [esp+0x14],eax 13c3: 89 6c 24 18 mov DWORD PTR [esp+0x18],ebp 13c7: 0f 84 36 01 00 00 je 1503 <__sprintf_chk@plt+0x923> 13cd: 8b 83 a0 00 00 00 mov eax,DWORD PTR [ebx+0xa0] 13d3: 83 ef 01 sub edi,0x1 13d6: 89 7c 24 10 mov DWORD PTR [esp+0x10],edi 13da: 8d 7c 24 2c lea edi,[esp+0x2c] 13de: c7 44 24 08 00 08 00 mov DWORD PTR [esp+0x8],0x800 13e5: 00 13e6: c7 44 24 04 01 00 00 mov DWORD PTR [esp+0x4],0x1 13ed: 00 13ee: 89 44 24 0c mov DWORD PTR [esp+0xc],eax 13f2: 89 3c 24 mov DWORD PTR [esp],edi 13f5: e8 e6 f7 ff ff call be0 <__sprintf_chk@plt> 13fa: 8d 83 15 eb ff ff lea eax,[ebx-0x14eb] 1400: 89 7c 24 08 mov DWORD PTR [esp+0x8],edi 1404: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1408: 89 34 24 mov DWORD PTR [esp],esi 140b: e8 40 f6 ff ff call a50 1410: 8d 85 00 01 00 00 lea eax,[ebp+0x100] 1416: 81 c5 00 02 00 00 add ebp,0x200 141c: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 1420: 89 6c 24 04 mov DWORD PTR [esp+0x4],ebp 1424: 89 34 24 mov DWORD PTR [esp],esi 1427: e8 24 f6 ff ff call a50 142c: 31 c0 xor eax,eax 142e: e9 b7 fe ff ff jmp 12ea <__sprintf_chk@plt+0x70a> 1433: 90 nop 1434: 8d 74 26 00 lea esi,[esi+eiz*1+0x0] 1438: 8d 83 e8 ea ff ff lea eax,[ebx-0x1518] 143e: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1442: 89 34 24 mov DWORD PTR [esp],esi 1445: e8 56 f6 ff ff call aa0 144a: 8b 83 b0 00 00 00 mov eax,DWORD PTR [ebx+0xb0] 1450: 89 34 24 mov DWORD PTR [esp],esi 1453: 89 44 24 18 mov DWORD PTR [esp+0x18],eax 1457: 8b 83 98 00 00 00 mov eax,DWORD PTR [ebx+0x98] 145d: 89 44 24 14 mov DWORD PTR [esp+0x14],eax 1461: 8b 83 ac 00 00 00 mov eax,DWORD PTR [ebx+0xac] 1467: 89 44 24 10 mov DWORD PTR [esp+0x10],eax 146b: 8b 83 80 00 00 00 mov eax,DWORD PTR [ebx+0x80] 1471: 89 44 24 0c mov DWORD PTR [esp+0xc],eax 1475: 8b 83 84 00 00 00 mov eax,DWORD PTR [ebx+0x84] 147b: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 147f: 8d 83 f2 ea ff ff lea eax,[ebx-0x150e] 1485: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1489: e8 c2 f5 ff ff call a50 148e: 8d 83 7b ea ff ff lea eax,[ebx-0x1585] 1494: 89 44 24 10 mov DWORD PTR [esp+0x10],eax 1498: 8b 83 a0 00 00 00 mov eax,DWORD PTR [ebx+0xa0] 149e: c7 44 24 0c 01 00 00 mov DWORD PTR [esp+0xc],0x1 14a5: 00 14a6: c7 44 24 08 ff ff ff mov DWORD PTR [esp+0x8],0xffffffff 14ad: ff 14ae: 89 34 24 mov DWORD PTR [esp],esi 14b1: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 14b5: e8 96 f5 ff ff call a50 14ba: 8d 83 02 eb ff ff lea eax,[ebx-0x14fe] 14c0: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 14c4: 8b 83 7c 00 00 00 mov eax,DWORD PTR [ebx+0x7c] 14ca: 89 34 24 mov DWORD PTR [esp],esi 14cd: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 14d1: e8 7a f5 ff ff call a50 14d6: 8b 83 b4 00 00 00 mov eax,DWORD PTR [ebx+0xb4] 14dc: 89 34 24 mov DWORD PTR [esp],esi 14df: 89 44 24 0c mov DWORD PTR [esp+0xc],eax 14e3: 8b 83 8c 00 00 00 mov eax,DWORD PTR [ebx+0x8c] 14e9: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 14ed: 8d 83 12 eb ff ff lea eax,[ebx-0x14ee] 14f3: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 14f7: e8 54 f5 ff ff call a50 14fc: 31 c0 xor eax,eax 14fe: e9 e7 fd ff ff jmp 12ea <__sprintf_chk@plt+0x70a> 1503: 8b 83 a0 00 00 00 mov eax,DWORD PTR [ebx+0xa0] 1509: 83 ef 01 sub edi,0x1 150c: 89 7c 24 10 mov DWORD PTR [esp+0x10],edi 1510: 8d 7c 24 2c lea edi,[esp+0x2c] 1514: c7 44 24 08 00 08 00 mov DWORD PTR [esp+0x8],0x800 151b: 00 151c: c7 44 24 04 01 00 00 mov DWORD PTR [esp+0x4],0x1 1523: 00 1524: 89 44 24 0c mov DWORD PTR [esp+0xc],eax 1528: 89 3c 24 mov DWORD PTR [esp],edi 152b: e8 b0 f6 ff ff call be0 <__sprintf_chk@plt> 1530: 8d 83 15 eb ff ff lea eax,[ebx-0x14eb] 1536: 89 7c 24 08 mov DWORD PTR [esp+0x8],edi 153a: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 153e: 89 34 24 mov DWORD PTR [esp],esi 1541: e8 0a f5 ff ff call a50 1546: 8d 85 00 01 00 00 lea eax,[ebp+0x100] 154c: 81 c5 00 05 00 00 add ebp,0x500 1552: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 1556: 89 6c 24 04 mov DWORD PTR [esp+0x4],ebp 155a: 89 34 24 mov DWORD PTR [esp],esi 155d: e8 ee f4 ff ff call a50 1562: 31 c0 xor eax,eax 1564: e9 81 fd ff ff jmp 12ea <__sprintf_chk@plt+0x70a> 1569: e8 c2 03 00 00 call 1930 <__sprintf_chk@plt+0xd50> 156e: 66 90 xchg ax,ax 1570: 55 push ebp 1571: 57 push edi 1572: 56 push esi 1573: 53 push ebx 1574: 83 ec 3c sub esp,0x3c 1577: e8 74 f6 ff ff call bf0 <__sprintf_chk@plt+0x10> 157c: 81 c3 ac 19 00 00 add ebx,0x19ac 1582: 8b 74 24 50 mov esi,DWORD PTR [esp+0x50] 1586: 8d 44 24 2c lea eax,[esp+0x2c] 158a: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 158e: 89 34 24 mov DWORD PTR [esp],esi 1591: e8 6a f5 ff ff call b00 1596: 8d 83 18 eb ff ff lea eax,[ebx-0x14e8] 159c: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 15a0: 8b 44 24 2c mov eax,DWORD PTR [esp+0x2c] 15a4: 89 04 24 mov DWORD PTR [esp],eax 15a7: e8 d4 f4 ff ff call a80 15ac: 89 c5 mov ebp,eax 15ae: 8d 83 1c eb ff ff lea eax,[ebx-0x14e4] 15b4: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 15b8: 8b 44 24 2c mov eax,DWORD PTR [esp+0x2c] 15bc: 89 04 24 mov DWORD PTR [esp],eax 15bf: e8 bc f4 ff ff call a80 15c4: 85 c0 test eax,eax 15c6: 89 c7 mov edi,eax 15c8: 75 0e jne 15d8 <__sprintf_chk@plt+0x9f8> 15ca: b8 a1 01 00 00 mov eax,0x1a1 15cf: 83 c4 3c add esp,0x3c 15d2: 5b pop ebx 15d3: 5e pop esi 15d4: 5f pop edi 15d5: 5d pop ebp 15d6: c3 ret 15d7: 90 nop 15d8: 85 ed test ebp,ebp 15da: 74 ee je 15ca <__sprintf_chk@plt+0x9ea> 15dc: 8b 93 94 00 00 00 mov edx,DWORD PTR [ebx+0x94] 15e2: b8 a1 01 00 00 mov eax,0x1a1 15e7: 8b 0a mov ecx,DWORD PTR [edx] 15e9: 83 f9 7e cmp ecx,0x7e 15ec: 7f e1 jg 15cf <__sprintf_chk@plt+0x9ef> 15ee: 83 c1 01 add ecx,0x1 15f1: 89 0a mov DWORD PTR [edx],ecx 15f3: 89 6c 24 08 mov DWORD PTR [esp+0x8],ebp 15f7: 8d ab 15 eb ff ff lea ebp,[ebx-0x14eb] 15fd: 89 7c 24 04 mov DWORD PTR [esp+0x4],edi 1601: c7 04 24 01 00 00 00 mov DWORD PTR [esp],0x1 1608: 89 54 24 1c mov DWORD PTR [esp+0x1c],edx 160c: e8 8f fb ff ff call 11a0 <__sprintf_chk@plt+0x5c0> 1611: 8d 83 e8 ea ff ff lea eax,[ebx-0x1518] 1617: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 161b: 89 34 24 mov DWORD PTR [esp],esi 161e: e8 7d f4 ff ff call aa0 1623: 8b 83 84 00 00 00 mov eax,DWORD PTR [ebx+0x84] 1629: 89 6c 24 04 mov DWORD PTR [esp+0x4],ebp 162d: 89 34 24 mov DWORD PTR [esp],esi 1630: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 1634: e8 17 f4 ff ff call a50 1639: 8b 54 24 1c mov edx,DWORD PTR [esp+0x1c] 163d: 8b 02 mov eax,DWORD PTR [edx] 163f: 89 7c 24 08 mov DWORD PTR [esp+0x8],edi 1643: 89 34 24 mov DWORD PTR [esp],esi 1646: 89 44 24 0c mov DWORD PTR [esp+0xc],eax 164a: 8d 83 28 ec ff ff lea eax,[ebx-0x13d8] 1650: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1654: e8 f7 f3 ff ff call a50 1659: 89 34 24 mov DWORD PTR [esp],esi 165c: e8 df f8 ff ff call f40 <__sprintf_chk@plt+0x360> 1661: 8b 83 b4 00 00 00 mov eax,DWORD PTR [ebx+0xb4] 1667: 89 6c 24 04 mov DWORD PTR [esp+0x4],ebp 166b: 89 34 24 mov DWORD PTR [esp],esi 166e: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 1672: e8 d9 f3 ff ff call a50 1677: 31 c0 xor eax,eax 1679: e9 51 ff ff ff jmp 15cf <__sprintf_chk@plt+0x9ef> 167e: 66 90 xchg ax,ax 1680: 53 push ebx 1681: 83 ec 28 sub esp,0x28 1684: e8 67 f5 ff ff call bf0 <__sprintf_chk@plt+0x10> 1689: 81 c3 9f 18 00 00 add ebx,0x189f 168f: 8d 44 24 1c lea eax,[esp+0x1c] 1693: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1697: 8b 44 24 30 mov eax,DWORD PTR [esp+0x30] 169b: 89 04 24 mov DWORD PTR [esp],eax 169e: e8 5d f4 ff ff call b00 16a3: 8d 83 28 eb ff ff lea eax,[ebx-0x14d8] 16a9: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 16ad: 8b 44 24 1c mov eax,DWORD PTR [esp+0x1c] 16b1: 89 04 24 mov DWORD PTR [esp],eax 16b4: e8 c7 f3 ff ff call a80 16b9: 85 c0 test eax,eax 16bb: 74 26 je 16e3 <__sprintf_chk@plt+0xb03> 16bd: c7 44 24 08 0a 00 00 mov DWORD PTR [esp+0x8],0xa 16c4: 00 16c5: c7 44 24 04 00 00 00 mov DWORD PTR [esp+0x4],0x0 16cc: 00 16cd: 89 04 24 mov DWORD PTR [esp],eax 16d0: e8 eb f4 ff ff call bc0 16d5: 85 c0 test eax,eax 16d7: 7e 0a jle 16e3 <__sprintf_chk@plt+0xb03> 16d9: 8b 93 94 00 00 00 mov edx,DWORD PTR [ebx+0x94] 16df: 39 02 cmp DWORD PTR [edx],eax 16e1: 7d 0d jge 16f0 <__sprintf_chk@plt+0xb10> 16e3: 83 c4 28 add esp,0x28 16e6: b8 94 01 00 00 mov eax,0x194 16eb: 5b pop ebx 16ec: c3 ret 16ed: 8d 76 00 lea esi,[esi+0x0] 16f0: 8b 93 a8 00 00 00 mov edx,DWORD PTR [ebx+0xa8] 16f6: c7 04 c2 ff ff ff ff mov DWORD PTR [edx+eax*8],0xffffffff 16fd: 83 c4 28 add esp,0x28 1700: 31 c0 xor eax,eax 1702: 5b pop ebx 1703: c3 ret 1704: 8d b6 00 00 00 00 lea esi,[esi+0x0] 170a: 8d bf 00 00 00 00 lea edi,[edi+0x0] 1710: e8 12 02 00 00 call 1927 <__sprintf_chk@plt+0xd47> 1715: 81 c1 13 18 00 00 add ecx,0x1813 171b: 8d 91 0a eb ff ff lea edx,[ecx-0x14f6] 1721: 8d 81 7b ea ff ff lea eax,[ecx-0x1585] 1727: e9 e4 f6 ff ff jmp e10 <__sprintf_chk@plt+0x230> 172c: 8d 74 26 00 lea esi,[esi+eiz*1+0x0] 1730: 57 push edi 1731: 56 push esi 1732: 53 push ebx 1733: e8 b8 f4 ff ff call bf0 <__sprintf_chk@plt+0x10> 1738: 81 c3 f0 17 00 00 add ebx,0x17f0 173e: 83 ec 30 sub esp,0x30 1741: 8b 74 24 40 mov esi,DWORD PTR [esp+0x40] 1745: 8d 7c 24 1c lea edi,[esp+0x1c] 1749: 89 3c 24 mov DWORD PTR [esp],edi 174c: c7 44 24 04 0f 00 00 mov DWORD PTR [esp+0x4],0xf 1753: 00 1754: 65 a1 14 00 00 00 mov eax,gs:0x14 175a: 89 44 24 2c mov DWORD PTR [esp+0x2c],eax 175e: 31 c0 xor eax,eax 1760: c7 44 24 18 00 00 00 mov DWORD PTR [esp+0x18],0x0 1767: 00 1768: e8 43 f4 ff ff call bb0 176d: 89 7c 24 04 mov DWORD PTR [esp+0x4],edi 1771: 8b 06 mov eax,DWORD PTR [esi] 1773: 89 04 24 mov DWORD PTR [esp],eax 1776: e8 e5 f3 ff ff call b60 177b: 89 34 24 mov DWORD PTR [esp],esi 177e: 89 c7 mov edi,eax 1780: 8d 44 24 18 lea eax,[esp+0x18] 1784: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1788: ff 93 2c 04 00 00 call DWORD PTR [ebx+0x42c] 178e: 8d 83 21 eb ff ff lea eax,[ebx-0x14df] 1794: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 1798: 8b 44 24 18 mov eax,DWORD PTR [esp+0x18] 179c: 89 7c 24 0c mov DWORD PTR [esp+0xc],edi 17a0: 89 34 24 mov DWORD PTR [esp],esi 17a3: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 17a7: ff 93 24 04 00 00 call DWORD PTR [ebx+0x424] 17ad: 31 c0 xor eax,eax 17af: 8b 54 24 2c mov edx,DWORD PTR [esp+0x2c] 17b3: 65 33 15 14 00 00 00 xor edx,DWORD PTR gs:0x14 17ba: 75 07 jne 17c3 <__sprintf_chk@plt+0xbe3> 17bc: 83 c4 30 add esp,0x30 17bf: 5b pop ebx 17c0: 5e pop esi 17c1: 5f pop edi 17c2: c3 ret 17c3: e8 68 01 00 00 call 1930 <__sprintf_chk@plt+0xd50> 17c8: 90 nop 17c9: 8d b4 26 00 00 00 00 lea esi,[esi+eiz*1+0x0] 17d0: 56 push esi 17d1: 53 push ebx 17d2: e8 19 f4 ff ff call bf0 <__sprintf_chk@plt+0x10> 17d7: 81 c3 51 17 00 00 add ebx,0x1751 17dd: 83 ec 24 sub esp,0x24 17e0: 8b 74 24 30 mov esi,DWORD PTR [esp+0x30] 17e4: 8d 44 24 18 lea eax,[esp+0x18] 17e8: c7 44 24 18 00 00 00 mov DWORD PTR [esp+0x18],0x0 17ef: 00 17f0: c7 44 24 1c 00 00 00 mov DWORD PTR [esp+0x1c],0x0 17f7: 00 17f8: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 17fc: 89 34 24 mov DWORD PTR [esp],esi 17ff: ff 93 2c 04 00 00 call DWORD PTR [ebx+0x42c] 1805: 8d 44 24 1c lea eax,[esp+0x1c] 1809: 89 44 24 0c mov DWORD PTR [esp+0xc],eax 180d: 8d 83 21 eb ff ff lea eax,[ebx-0x14df] 1813: 89 44 24 08 mov DWORD PTR [esp+0x8],eax 1817: 8b 44 24 18 mov eax,DWORD PTR [esp+0x18] 181b: 89 34 24 mov DWORD PTR [esp],esi 181e: 89 44 24 04 mov DWORD PTR [esp+0x4],eax 1822: ff 93 28 04 00 00 call DWORD PTR [ebx+0x428] 1828: 8b 54 24 1c mov edx,DWORD PTR [esp+0x1c] 182c: 31 c0 xor eax,eax 182e: 85 d2 test edx,edx 1830: 0f 94 c0 sete al 1833: 83 c4 24 add esp,0x24 1836: f7 d8 neg eax 1838: 5b pop ebx 1839: 5e pop esi 183a: c3 ret 183b: 90 nop 183c: 8d 74 26 00 lea esi,[esi+eiz*1+0x0] 1840: 55 push ebp 1841: 57 push edi 1842: 56 push esi 1843: 53 push ebx 1844: 83 ec 1c sub esp,0x1c 1847: 8b 6c 24 30 mov ebp,DWORD PTR [esp+0x30] 184b: e8 a0 f3 ff ff call bf0 <__sprintf_chk@plt+0x10> 1850: 81 c3 d8 16 00 00 add ebx,0x16d8 1856: 8b b5 c0 00 00 00 mov esi,DWORD PTR [ebp+0xc0] 185c: 85 f6 test esi,esi 185e: 0f 84 bc 00 00 00 je 1920 <__sprintf_chk@plt+0xd40> 1864: b9 11 00 00 00 mov ecx,0x11 1869: 8d bb 2b eb ff ff lea edi,[ebx-0x14d5] 186f: f3 a6 repz cmps BYTE PTR ds:[esi],BYTE PTR es:[edi] 1871: 0f 85 a9 00 00 00 jne 1920 <__sprintf_chk@plt+0xd40> 1877: 8b 75 48 mov esi,DWORD PTR [ebp+0x48] 187a: b9 06 00 00 00 mov ecx,0x6 187f: 8d bb 3c eb ff ff lea edi,[ebx-0x14c4] 1885: f3 a6 repz cmps BYTE PTR ds:[esi],BYTE PTR es:[edi] 1887: 89 2c 24 mov DWORD PTR [esp],ebp 188a: 0f 97 c2 seta dl 188d: 0f 92 c0 setb al 1890: 38 c2 cmp dl,al 1892: 74 4c je 18e0 <__sprintf_chk@plt+0xd00> 1894: e8 37 ff ff ff call 17d0 <__sprintf_chk@plt+0xbf0> 1899: 85 c0 test eax,eax 189b: 75 23 jne 18c0 <__sprintf_chk@plt+0xce0> 189d: 89 2c 24 mov DWORD PTR [esp],ebp 18a0: e8 db f6 ff ff call f80 <__sprintf_chk@plt+0x3a0> 18a5: 83 f8 01 cmp eax,0x1 18a8: 74 66 je 1910 <__sprintf_chk@plt+0xd30> 18aa: 83 f8 02 cmp eax,0x2 18ad: 74 41 je 18f0 <__sprintf_chk@plt+0xd10> 18af: 85 c0 test eax,eax 18b1: 74 4d je 1900 <__sprintf_chk@plt+0xd20> 18b3: b8 f5 01 00 00 mov eax,0x1f5 18b8: 83 c4 1c add esp,0x1c 18bb: 5b pop ebx 18bc: 5e pop esi 18bd: 5f pop edi 18be: 5d pop ebp 18bf: c3 ret 18c0: 8b 93 90 00 00 00 mov edx,DWORD PTR [ebx+0x90] 18c6: b8 9c 01 00 00 mov eax,0x19c 18cb: 8b 12 mov edx,DWORD PTR [edx] 18cd: 85 d2 test edx,edx 18cf: 75 cc jne 189d <__sprintf_chk@plt+0xcbd> 18d1: 83 c4 1c add esp,0x1c 18d4: 5b pop ebx 18d5: 5e pop esi 18d6: 5f pop edi 18d7: 5d pop ebp 18d8: c3 ret 18d9: 8d b4 26 00 00 00 00 lea esi,[esi+eiz*1+0x0] 18e0: e8 4b fe ff ff call 1730 <__sprintf_chk@plt+0xb50> 18e5: 83 c4 1c add esp,0x1c 18e8: 31 c0 xor eax,eax 18ea: 5b pop ebx 18eb: 5e pop esi 18ec: 5f pop edi 18ed: 5d pop ebp 18ee: c3 ret 18ef: 90 nop 18f0: 89 6c 24 30 mov DWORD PTR [esp+0x30],ebp 18f4: 83 c4 1c add esp,0x1c 18f7: 5b pop ebx 18f8: 5e pop esi 18f9: 5f pop edi 18fa: 5d pop ebp 18fb: e9 80 fd ff ff jmp 1680 <__sprintf_chk@plt+0xaa0> 1900: 89 6c 24 30 mov DWORD PTR [esp+0x30],ebp 1904: 83 c4 1c add esp,0x1c 1907: 5b pop ebx 1908: 5e pop esi 1909: 5f pop edi 190a: 5d pop ebp 190b: e9 50 f9 ff ff jmp 1260 <__sprintf_chk@plt+0x680> 1910: 89 6c 24 30 mov DWORD PTR [esp+0x30],ebp 1914: 83 c4 1c add esp,0x1c 1917: 5b pop ebx 1918: 5e pop esi 1919: 5f pop edi 191a: 5d pop ebp 191b: e9 50 fc ff ff jmp 1570 <__sprintf_chk@plt+0x990> 1920: b8 ff ff ff ff mov eax,0xffffffff 1925: eb 91 jmp 18b8 <__sprintf_chk@plt+0xcd8> 1927: 8b 0c 24 mov ecx,DWORD PTR [esp] 192a: c3 ret 192b: 66 90 xchg ax,ax 192d: 66 90 xchg ax,ax 192f: 90 nop 1930: 53 push ebx 1931: e8 ba f2 ff ff call bf0 <__sprintf_chk@plt+0x10> 1936: 81 c3 f2 15 00 00 add ebx,0x15f2 193c: 83 ec 08 sub esp,0x8 193f: e8 4c f1 ff ff call a90 <__stack_chk_fail@plt> Disassembly of section .fini: 00001944 <_fini>: 1944: 53 push ebx 1945: 83 ec 08 sub esp,0x8 1948: e8 a3 f2 ff ff call bf0 <__sprintf_chk@plt+0x10> 194d: 81 c3 db 15 00 00 add ebx,0x15db 1953: 83 c4 08 add esp,0x8 1956: 5b pop ebx 1957: c3 ret