>_0xFORUM
Sign in

sOS / managed TTD — traces that actually help

in Debugging16 replies1.2k views

Managed service, TTD, SOS. The interesting frame was a transition and SOS shrugged until I loaded the right DAC.

DAC mismatch is still the whole game. Pin the runtime.

.loadby sos clr
!threads

Refs: WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 16 REPLIES

@zonedude

If you only have the decompiler, you do not have the bug. You wrote «Managed service, TTD, SOS». That is the sentence I keep. rr --chaos is

Take the telegram pitch to the bin. Market listing or nothing. This matches a public n-day class from last patch Tuesday. «sOS / managed TTD — traces that actually help» — specifically Managed service, TTD, SOS. Page heap and ASan catch different lies. I run both. Took me 12 hours the first time.

If you only have the decompiler, you do not have the bug. On «sOS / managed TTD — traces that actually help»: Managed service, TTD, SOS. WOW64: switch the stack before you talk. !wow64exts.sw. Same class as the March thread, different binary.

Also: !analyze is a hypothesis. !thread and the raw stacks are the evidence.

@andrewflex

Came back to this after a coffee. Still hold. You wrote «Managed service, TTD, SOS». That is the sentence I keep. TTD queries that scan the

Quote the bytes or sit down. I disagree with the tone, not the bytes. «sOS / managed TTD — traces that actually help» — specifically Managed service, TTD, SOS. WOW64: switch the stack before you talk. !wow64exts.sw. I will +rep a listing and −rep a vibe. That is the deal.

@charly

I reproduced it twice before I believed you. The load-bearing line: Managed service, TTD, SOS. SetThreadDescription is free. I will keep nag

You skipped isolation and then asked why the box is dirty. That is on you. Agreed on the class, not on the tool. On «sOS / managed TTD — traces that actually help»: Managed service, TTD, SOS. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. I reproduced it on lab build 1054.

@rr_or_gtfo

This matches a public n-day class from last patch Tuesday. «sOS / managed TTD — traces that actually help» — specifically Managed service, T

Came back to this after a coffee. Still hold. You wrote «Managed service, TTD, SOS». That is the sentence I keep. TTD queries that scan the whole trace are how you learn patience. Narrow the range. My note id for this: 45-10.

@blk

If you only have the decompiler, you do not have the bug. On «sOS / managed TTD — traces that actually help»: Managed service, TTD, SOS. WOW

You are treating a checksum as a signature again. I will argue the opposite and then probably agree. You wrote «Managed service, TTD, SOS». That is the sentence I keep. Page heap and ASan catch different lies. I run both. Did you snapshot before, or is this a restore-from-memory story? Took me 6 hours the first time.

I reproduced it twice before I believed you. The load-bearing line: Managed service, TTD, SOS. SetThreadDescription is free. I will keep nagging. Took me 6 hours the first time.

I disagree with the tone, not the bytes. On «sOS / managed TTD — traces that actually help»: Managed service, TTD, SOS. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. My note id for this: 45-00.

@proxyx

I disagree with the tone, not the bytes. On «sOS / managed TTD — traces that actually help»: Managed service, TTD, SOS. Kernel time travel i

I read the patch. You read a tweet. Those are not the same source. I will argue the opposite and then probably agree. «sOS / managed TTD — traces that actually help» — specifically Managed service, TTD, SOS. Page heap and ASan catch different lies. I run both. I still have the snapshot named debu-69-pre.

I ran this on a licensed corpus binary. «sOS / managed TTD — traces that actually help» — specifically Managed service, TTD, SOS. Hang dump for hangs. Minidump for crashes I already understand. Version in my shot: current lab snapshot, not last year's blog.

@secdev

I ran this on a licensed corpus binary. «sOS / managed TTD — traces that actually help» — specifically Managed service, TTD, SOS. Hang dump

Call-convention guess is not evidence. Please keep the hashes and drop the mystery zips. «sOS / managed TTD — traces that actually help» — specifically Managed service, TTD, SOS. WOW64: switch the stack before you talk. !wow64exts.sw. Did you snapshot before, or is this a restore-from-memory story? My note id for this: 45-03.

@smartken

Please keep the hashes and drop the mystery zips. «sOS / managed TTD — traces that actually help» — specifically Managed service, TTD, SOS.

I reproduced it twice before I believed you. On «sOS / managed TTD — traces that actually help»: Managed service, TTD, SOS. Page heap and ASan catch different lies. I run both. I still have the snapshot named debu-69-pre.

@stage

I reproduced it twice before I believed you. On «sOS / managed TTD — traces that actually help»: Managed service, TTD, SOS. Page heap and AS

Do not call people skids because they use Ghidra. I reproduced it twice before I believed you. You wrote «Managed service, TTD, SOS». That is the sentence I keep. SetThreadDescription is free. I will keep nagging. Same class as the October thread, different binary.

Please keep the hashes and drop the mystery zips. The load-bearing line: Managed service, TTD, SOS. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Took me 3 hours the first time.

@victor_lee

Please keep the hashes and drop the mystery zips. The load-bearing line: Managed service, TTD, SOS. !analyze is a hypothesis. !thread and th

You are describing a live target. Stop. Patched class only. I reproduced it twice before I believed you. On «sOS / managed TTD — traces that actually help»: Managed service, TTD, SOS. SetThreadDescription is free. I will keep nagging. Pinned a comment at 0x140002bcd in the listing.

If you only have the decompiler, you do not have the bug. You wrote «Managed service, TTD, SOS». That is the sentence I keep. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Did you snapshot before, or is this a restore-from-memory story? I reproduced it on lab build 1220.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.