How to figure out second parameter/register in reverse engineering assembly?

Viewed 203

so Im doing a variation of the binary bomb. Heres what the phase is

0x0000000000401205 <+0>:     sub    $0x8,%rsp
0x0000000000401209 <+4>:     cmp    $0x3,%rdi                    #rdi = 3
0x000000000040120d <+8>:     je     0x40121d <phase_2+24>        #if(rdi == 3) skip explosion 
0x000000000040120f <+10>:    callq  0x401c01 <bomb_ignition>
0x0000000000401214 <+15>:    mov    $0xffffffffffffffff,%rax
0x000000000040121b <+22>:    jmp    0x40124c <phase_2+71>
0x000000000040121d <+24>:    xor    $0xffffffffffffff1c,%rsi     #rsi ^= 0xffffffffffffff1c
0x0000000000401224 <+31>:    and    %rsi,%rdx                    #rdx &= rsi
0x0000000000401227 <+34>:    add    $0x1c8,%rdx                  #rdx += 456 
0x000000000040122e <+41>:    cmp    $0x2c5,%rdx                  #rdx == 709
0x0000000000401235 <+48>:    sete   %al 
0x0000000000401238 <+51>:    movzbl %al,%eax
0x000000000040123b <+54>:    cmp    %rcx,%rdx                    #rdx == rcx
0x000000000040123e <+57>:    je     0x40124c <phase_2+71>
0x0000000000401240 <+59>:    callq  0x401c01 <bomb_ignition>
0x0000000000401245 <+64>:    mov    $0xffffffffffffffff,%rax
0x000000000040124c <+71>:    add    $0x8,%rsp
0x0000000000401250 <+75>:    retq

Ive annotated what i think it means next to the asm. What Im stuck on is <+24> where it xors $0xffffffffffffff1c and %rsi. %rsi is the second parameter passed correct? So how do I figure out what it is so i can xor it? Because it then ands it to %rdx which is the third parameter.

So what I think it does it take 4 numbers. 1st is '3' (right?). Then xor the second with 0xffffffffffffff1c. Ands this to the third number. Then third number adds 456, and should be 709. Which is what the 4th number should be. Also Im still a bit confused on sete and movzbl. But I cant figure out what the second and third number should be. Am I correct in my prediction? ANY HELP APPRECIATED. Thanks

1 Answers
Related