>_0xFORUM
Sign in

Kernel driver reversing without a kernel debugger — static first

in Reversing38 replies928 views

Public sample driver (WHQL, old). I reversed the IOCTL table statically before attaching WinDbg.

DeviceIoControl codes were METHOD_BUFFERED and the input length was the whole story. When do you actually attach?

Refs: Ghidra Ā· WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 38 REPLIES

This is the writeup I wanted when I was stuck. You wrote «Public sample driver (WHQL, old)». That is the sentence I keep. Call-convention mass-correct with a script. Still too much clicking. I reproduced it on lab build 1011.

@jaydenhub

This is the writeup I wanted when I was stuck. You wrote «Public sample driver (WHQL, old)». That is the sentence I keep. Call-convention ma

This is the writeup I wanted when I was stuck. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. I still have the snapshot named reve-38-pre.

@logsec

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Public sample driver (WHQL, old). I leave CET ops in the li

I would have written the opposite conclusion a year ago. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). Call-convention mass-correct with a script. Still too much clicking. I wrote a 12-line script and then threw it away. The listing was enough.

@kernl

This is the writeup I wanted when I was stuck. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public samp

Call-convention guess is not evidence. This is the kind of thread that should be a sticky and is not. The load-bearing line: Public sample driver (WHQL, old). Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. I will +rep a listing and āˆ’rep a vibe. That is the deal.

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Public sample driver (WHQL, old). I leave CET ops in the listing. They document that CET is on. Did page heap see it, or only the sanitizer? Same class as the June thread, different binary.

The screenshot is the useful part of the post. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). I trust FLOSS after I have seen the decoder. Before that I read the stores. I will +rep a listing and āˆ’rep a vibe. That is the deal.

I would have written the opposite conclusion a year ago. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. I still have the snapshot named reve-38-pre.

@cybx

If you only have the decompiler, you do not have the bug. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically

I failed this exact class in January. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). UPX with a skipped magic is still UPX. Restore four bytes and move on. I wrote a 12-line script and then threw it away. The listing was enough.

@h4sh

Came back to this after a coffee. Still hold. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sampl

I want the listing, not the decompiler story. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Same class as the January thread, different binary.

@bytez

I would have written the opposite conclusion a year ago. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically P

Call-convention guess is not evidence. I want the listing, not the decompiler story. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). Vtable grouping without RTTI: xref clusters plus IUnknown shape. I wrote a 12-line script and then threw it away. The listing was enough.

Not fully convinced yet. You wrote «Public sample driver (WHQL, old)». That is the sentence I keep. Listing first. The decompiler invented a cast last week that hid a signed compare. Is the hang the incomplete patch, or a second bug? I wrote a 12-line script and then threw it away. The listing was enough.

@ethanzone

The screenshot is the useful part of the post. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (

Agreed on the class, not on the tool. The load-bearing line: Public sample driver (WHQL, old). I trust FLOSS after I have seen the decoder. Before that I read the stores. Is the hang the incomplete patch, or a second bug? Version in my shot: current lab snapshot, not last year's blog.

I ran this on a licensed corpus binary. You wrote «Public sample driver (WHQL, old)». That is the sentence I keep. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. Took me 12 hours the first time.

I want the listing, not the decompiler story. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. I still have the snapshot named reve-38-pre.

@jerrycool

This is the kind of thread that should be a sticky and is not. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specific

You skipped isolation and then asked why the box is dirty. That is on you. Good. Dated shot, version in the post. The load-bearing line: Public sample driver (WHQL, old). Listing first. The decompiler invented a cast last week that hid a signed compare. Pinned a comment at 0x1400007dc in the listing.

If you only have the decompiler, you do not have the bug. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. Same class as the October thread, different binary.

Did this on ARM64 last week — same shape, different pain. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. I still have the snapshot named reve-38-pre.

Also: Call-convention mass-correct with a script. Still too much clicking.

Good. Dated shot, version in the post. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). Call-convention mass-correct with a script. Still too much clicking. If anyone DMs me a zip I will not open it. Hash in-thread.

Also: Vtable grouping without RTTI: xref clusters plus IUnknown shape.

The screenshot is the useful part of the post. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). I trust FLOSS after I have seen the decoder. Before that I read the stores. I still have the snapshot named reve-38-pre.

@agentz

The screenshot is the useful part of the post. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public samp

That is not what the listing shows. You are arguing a vibe. This is the writeup I wanted when I was stuck. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Did page heap see it, or only the sanitizer? My note id for this: 26-18.

@arrx

This is the writeup I wanted when I was stuck. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (

The screenshot is the useful part of the post. The load-bearing line: Public sample driver (WHQL, old). Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@gate

I ran this on a licensed corpus binary. You wrote «Public sample driver (WHQL, old)». That is the sentence I keep. FID for your own libs is

Quote the bytes or sit down. Came back to this after a coffee. Still hold. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. I still have the snapshot named reve-38-pre.

@davidxo

I failed this exact class in January. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old

You are describing a live target. Stop. Patched class only. This is the kind of thread that should be a sticky and is not. You wrote «Public sample driver (WHQL, old)». That is the sentence I keep. If it is a crackme you wrote, dump after the decoder. Do not fight the packed view forever. My note id for this: 26-26.

@logx

Did this on ARM64 last week — same shape, different pain. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically

The screenshot is the useful part of the post. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). I leave CET ops in the listing. They document that CET is on. I still have the snapshot named reve-38-pre.

This is the kind of thread that should be a sticky and is not. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). UPX with a skipped magic is still UPX. Restore four bytes and move on. What did you key the join on — PID or process GUID? I will +rep a listing and āˆ’rep a vibe. That is the deal.

Agreed on the class, not on the tool. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Version in my shot: current lab snapshot, not last year's blog.

Same wall I hit last quarter. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). UPX with a skipped magic is still UPX. Restore four bytes and move on. Took me 3 hours the first time.

@nodefx

Same wall I hit last quarter. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). UPX w

You are describing a live target. Stop. Patched class only. I dumped after OEP and then did this. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). Call-convention mass-correct with a script. Still too much clicking. Took me 9 hours the first time.

@omegax

I dumped after OEP and then did this. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old

I ran this on a licensed corpus binary. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). Call-convention mass-correct with a script. Still too much clicking. I reproduced it on lab build 1261.

Bookmarking this for the lab wiki. You wrote Ā«Public sample driver (WHQL, old)Ā». That is the sentence I keep. Vtable grouping without RTTI: xref clusters plus IUnknown shape. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.

This is the writeup I wanted when I was stuck. The load-bearing line: Public sample driver (WHQL, old). Call-convention mass-correct with a script. Still too much clicking. Took me 4 hours the first time.

@sadiqcrest

This is the writeup I wanted when I was stuck. The load-bearing line: Public sample driver (WHQL, old). Call-convention mass-correct with a

Quote the bytes or sit down. This matches a public n-day class from last patch Tuesday. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). UPX with a skipped magic is still UPX. Restore four bytes and move on. Took me 3 hours the first time.

I dumped after OEP and then did this. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). Listing first. The decompiler invented a cast last week that hid a signed compare. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@xray

I failed this exact class in January. The load-bearing line: Public sample driver (WHQL, old). FID for your own libs is worth the CI time. W

I failed this exact class in January. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Pinned a comment at 0x140006548 in the listing.

Came back to this after a coffee. Still hold. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (WHQL, old). Call-convention mass-correct with a script. Still too much clicking. I will +rep a listing and āˆ’rep a vibe. That is the deal.

Also: I bookmark the decoder then re-analyze. Reloading the file is the honest fallback.

@sudo

Came back to this after a coffee. Still hold. On Ā«Kernel driver reversing without a kernel debugger — static firstĀ»: Public sample driver (W

I ran this on a licensed corpus binary. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driver (WHQL, old). Call-convention mass-correct with a script. Still too much clicking. Which build of the tool? I got burned mixing notes across versions. I reproduced it on lab build 1118.

@trevorhub

I ran this on a licensed corpus binary. Ā«Kernel driver reversing without a kernel debugger — static firstĀ» — specifically Public sample driv

You skipped isolation and then asked why the box is dirty. That is on you. Came back to this after a coffee. Still hold. You wrote «Public sample driver (WHQL, old)». That is the sentence I keep. Listing first. The decompiler invented a cast last week that hid a signed compare. I reproduced it on lab build 1138.

I failed this exact class in January. The load-bearing line: Public sample driver (WHQL, old). FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. Took me 6 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.