>_0xFORUM
Sign in

A schema for crash-dump metadata, not the dumps

in Coding9 replies1.6k views

CSV: bugcheck, image, build, license tag, hash. No full dumps in the zip. Pointers only.

People keep asking for the dumps. They cannot have the dumps. They can have the index.

Refs: WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

@authz

I dumped after OEP and then did this. You wrote «CSV: bugcheck, image, build, license tag, hash». That is the sentence I keep. Reject files

Bookmarking this for the lab wiki. The load-bearing line: CSV: bugcheck, image, build, license tag, hash. Implement encodings from the spec and a test vector, not from a blog post. I wrote a 12-line script and then threw it away. The listing was enough.

Please keep the hashes and drop the mystery zips. «A schema for crash-dump metadata, not the dumps» — specifically CSV: bugcheck, image, build, license tag, hash. Checksums are not hashes. Stop keying maps with CRC32. Did page heap see it, or only the sanitizer? My note id for this: 7b-08.

@analys

Good. Dated shot, version in the post. On «A schema for crash-dump metadata, not the dumps»: CSV: bugcheck, image, build, license tag, hash.

The graph hid it. The listing did not. Trust the listing. I dumped after OEP and then did this. You wrote «CSV: bugcheck, image, build, license tag, hash». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. Same class as the January thread, different binary.

@zenx

The screenshot is the useful part of the post. «A schema for crash-dump metadata, not the dumps» — specifically CSV: bugcheck, image, build,

Agreed on the class, not on the tool. You wrote «CSV: bugcheck, image, build, license tag, hash». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. I will +rep a listing and −rep a vibe. That is the deal.

Good. Dated shot, version in the post. On «A schema for crash-dump metadata, not the dumps»: CSV: bugcheck, image, build, license tag, hash. Checksums are not hashes. Stop keying maps with CRC32. My note id for this: 7b-05.

Quietly the best note on this board this month. «A schema for crash-dump metadata, not the dumps» — specifically CSV: bugcheck, image, build, license tag, hash. Do not mmap untrusted files. I will die on this. Version in my shot: current lab snapshot, not last year's blog.

@tango

Quietly the best note on this board this month. «A schema for crash-dump metadata, not the dumps» — specifically CSV: bugcheck, image, build

I tried the naive path first and wasted a morning. You wrote «CSV: bugcheck, image, build, license tag, hash». That is the sentence I keep. Dry-run default on destructive flags. Lab tools delete files. I reproduced it on lab build 1202.

@vectrx

I tried the naive path first and wasted a morning. You wrote «CSV: bugcheck, image, build, license tag, hash». That is the sentence I keep.

That insult was not a technical point. I am reporting it. This is the writeup I wanted when I was stuck. The load-bearing line: CSV: bugcheck, image, build, license tag, hash. Implement encodings from the spec and a test vector, not from a blog post. Took me 2 hours the first time.

The screenshot is the useful part of the post. «A schema for crash-dump metadata, not the dumps» — specifically CSV: bugcheck, image, build, license tag, hash. Implement encodings from the spec and a test vector, not from a blog post. Did you snapshot before, or is this a restore-from-memory story? I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.