call cs:label instruction

Viewed 299

What does this syntax mean?

call cs:label

For example I've run into such instruction:

call cs:MessageBoxA

why isn't it like:

call MessageBoxA?


I've found that instruction in the IDA Pro (v6.8) disassembled code of some Win exefile.

Here is the hex opcode of the instruction:
2E FF 15 24 01 6C 00

1 Answers

This is a call through a function-pointer stored in memory at that symbol address. Which is normal for a DLL call; dynamic linking updates the pointer.

But it has a CS prefix which is not normal, AFAIK. Windows (like other mainstream x86 OSes) uses a flat memory model, the the segment base address = 0 for all of CS/DS/ES/SS. So the CS prefix has no actual effect on the address being loaded from.


2E really is a CS segment-override prefix, and FF /22 is (near) call r/m32 (https://www.felixcloutier.com/x86/call), so it looks like it is a near (not far) call cs:[disp32].

This is a real segment-override prefix, not a reminder of the default sprinkled in by an overly helpful disassembler. (Like some will put mov eax, ds:label even though there's no DS segment override prefix.)

Footnote 2: In octal, the 0x15 ModRM byte is 025, and the /r field is bits [5:3], just below the 2-bit mode field at the top. So the opcode is FF /2.


Weird, how was this executable created? I didn't think compilers would do that.

Related