Hello.

JMP FF (JMP SHORT, ie one byte) EB FF bytecode

JMP FF FF FF FF (JMP NEAR ie four bytes) bytecode E9 FF FF FF FF

Such a question, JMP on 3 byte jump how will?

  • 3
    No: there is no "three byte" addressing mode on the x86 platform. - insolor
  • Well ... And how to jump then? - Laziz Ergashev
  • one
    Write the specific problem you are trying to solve. JMP SHORT allows you to jump within + - 127 bytes, JMP NEAR - + - 2 ** 31 (approximately). These bytes, which are clogged with FF, are actually offset from the end of the JMP command. - insolor
  • In the game, I change the byte code, since the byte code does not fit into one instruction, I look for the cave address and I write my bytes there, as on the Cheate Engine. But, before the cave of the address, I get a prizhok, say 7F8A00, and how is this distance weighed down? - Laziz Ergashev
  • 2
    And what's stopping you to do JMP 002C314C? - Mike

1 answer 1

It is necessary to use indirect jmp near with 4 byte addressing, filling in the missing bytes 0

 JMP 002C314C