What is this jump instruction for a syscall?

Viewed 368

I wanted to see how a syscall is made under x86 on a x64 Windows system, as I'm already familiar with how it's done on x64.

Anyways, I was going instruction by instruction when I came across this jmp instruction that I don't understand. Here's the callstack I observed:

ntdll.dll!_Wow64SystemServiceCall@0()
ntdll.dll!_NtReadVirtualMemory@20()
KernelBase.dll!ReadProcessMemory()

Then, there's a jmp dword ptr [_Wow64Transition]. Here's where I'm confused. Right after the jump, there's an instruction jmp 0033::77CE7009. Stepping into this instruction will take be back to the end of ntdll.dll!_NtReadVirtualMemory@20() for some reason.

What is this far jump, and what does it do?

1 Answers

You attempted to debug a seg:off jmp with a 32 bit debugger. The instruction trapped in kernel mode by design and trampolined into 64 bit code. The 32 bit debugger is not able to continue debugging and the debugging APIs actually fail until the program returns to 32 bit code again.

If you had a 64 bit debugger you could debug all the way to the system call.

Related