View Single Post
  #3  
Old 08-03-2003, 16:13
ArC ArC is offline
VIP
 
Join Date: Jan 2003
Location: NTOSKRNL.EXE
Posts: 172
Rept. Given: 0
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 5
Thanks Rcvd at 17 Times in 12 Posts
ArC Reputation: 1
Sorry, everything is ok:
Inside that call there's a pointer pointing
to the return address.
However, there's an AND [pointer],0 executed
which causes that the return address is "removed"

However, it's still a bit strange, cause the return address
is duplicated on the stack. You can say that it is stored
twice.
But when we come to the RET of the call, the stack points
to the old return address which was removed with the AND
I mentioned above....

However, thx for your reply
Reply With Quote