Closed pdamian closed 2 years ago
strlen
) that we skip, can change values on the stack. Therefore, in the leave state, everything on the stack but outside of [fp
, sp
] is fine to mismatch.r4
-r8
, r9
?, r10
-r11
).Therefore, the test case hijack_indirect_callsite
should not be buggy.
Investigate the
hijack_indirect_callsite
test case. Why is the leave state of the GDB trace different than the leave state of the symbolic execution?