Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6049263
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 23, 20262026-05-23T07:33:22+00:00 2026-05-23T07:33:22+00:00

I am new to reverse engineering, and I have been looking at a simple

  • 0

I am new to reverse engineering, and I have been looking at a simple program:

char* a = "hello world";
printf(a);

However, when I open this in ollydbg, I am not taken right to the assembly as I would have been in gdb, there are many more instructions first. I was wondering why this was happening.

Thanks!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-23T07:33:22+00:00Added an answer on May 23, 2026 at 7:33 am

    Depending how you attach to the program with olly, you’ll be take to one of two places(if no errors occurred):

    • The module entry point (aka the system glue and CRT wrapper for main/WinMain/DllMain): this occurs when you start a program with olly.
    • NtUserBreakPoint: this is when you attach to an existing process.

    To navigate to where you want you can use ctrl + e to bring up the modules window, from there, select the module you want. Then use crtl + n to bring up the symbols window for your current module (note: for non-exported symbols to be available, the pdb’s need to be available or you need to perform an object scan of your obj’s for that build).

    if your taken to the ModuleEntryPoint you can also just spelunk down the call chain (generally you want the second call/jmp), this gets you to the crt entrypoint, from there just look for a call with 3/5/4 args, this will be main/WinMain/DllMain:

    from here:

    Blackene.<ModuleEntryPoint> 004029C3                                   E8 FC030000                                             CALL Blackene.__security_init_cookie
    004029C8                                                             ^ E9 D7FCFFFF                                             JMP Blackene.__tmainCRTStartup
    

    we goto here:

    Blackene.__tmainCRTStartup 004026A4                                    6A 58                                                   PUSH 58
    004026A6                                                               68 48474000                                             PUSH Blackene.00404748
    004026AB                                                               E8 1C060000                                             CALL Blackene.__SEH_prolog4
    004026B0                                                               33DB                                                    XOR EBX,EBX
    

    then scroll down here:

    004027D3                                                               6A 0A                                                   PUSH 0A
    004027D5                                                               58                                                      POP EAX
    004027D6                                                               50                                                      PUSH EAX
    004027D7                                                               56                                                      PUSH ESI
    004027D8                                                               6A 00                                                   PUSH 0
    004027DA                                                               68 00004000                                             PUSH Blackene.00400000
    004027DF                                                               E8 2CF2FFFF                                             CALL Blackene.WinMain
    

    I’m assuming ollydbg 1.10 is being used.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Being new to test based development, this question has been bugging me. How much
New to javascript/jquery and having a hard time with using this or $(this) to
New to xml. Looking for XPath to search a xml file with python ElementTree
I ask myself where reverse engineering is used. I'm interested at learning it. But
I have a modelform that will either create a new model or edit an
New class is a subclass of the original object It needs to be php4
New to silverlight. Traditionally if I were to design a wizard-like process where a
New to both Ruby and Rails but I'm book educated by now (which apparently
New to WCF, but familiar with COM+ - can I wrap a WCF service
New to Linux programming in general. I am trying to communicate with a kernel

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.