>_0xFORUM
Sign in

Conditional breakpoints that make the target unusable

in Debugging11 replies2.9k views

A condition that walks a list on every hit. Target became a slideshow. I logged instead.

When is a conditional breakpoint honest, and when is it a denial of service on yourself?

bp foo "j (poi(rcx+8)==0x1) 'gc'; 'k; gc'"

Refs: WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 11 REPLIES

@xorx

I ran this on a licensed corpus binary. The load-bearing line: A condition that walks a list on every hit. Dump the helper process. Always t

Agreed on the class, not on the tool. The load-bearing line: A condition that walks a list on every hit. If gdb finish hangs, there was a longjmp. Stop waiting. I still have the snapshot named debu-70-pre.

I disagree with the tone, not the bytes. Ā«Conditional breakpoints that make the target unusableĀ» — specifically A condition that walks a list on every hit. WOW64: switch the stack before you talk. !wow64exts.sw. Hash of the public file, or are we arguing a shape? Same class as the June thread, different binary.

@array

This matches a public n-day class from last patch Tuesday. On «Conditional breakpoints that make the target unusable»: A condition that walk

That is not what the listing shows. You are arguing a vibe. Not fully convinced yet. Ā«Conditional breakpoints that make the target unusableĀ» — specifically A condition that walks a list on every hit. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I wrote a 12-line script and then threw it away. The listing was enough.

This matches a public n-day class from last patch Tuesday. On «Conditional breakpoints that make the target unusable»: A condition that walks a list on every hit. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Pinned a comment at 0x140006a44 in the listing.

I reproduced it twice before I believed you. Ā«Conditional breakpoints that make the target unusableĀ» — specifically A condition that walks a list on every hit. Hang dump for hangs. Minidump for crashes I already understand. Pinned a comment at 0x140000962 in the listing.

@rseclab

I reproduced it twice before I believed you. Ā«Conditional breakpoints that make the target unusableĀ» — specifically A condition that walks a

Bookmarking this for the lab wiki. The load-bearing line: A condition that walks a list on every hit. SetThreadDescription is free. I will keep nagging. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@seyiwave

Bookmarking this for the lab wiki. The load-bearing line: A condition that walks a list on every hit. SetThreadDescription is free. I will k

Quote the bytes or sit down. Quietly the best note on this board this month. Ā«Conditional breakpoints that make the target unusableĀ» — specifically A condition that walks a list on every hit. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I reproduced it on lab build 1367.

Same wall I hit last quarter. The load-bearing line: A condition that walks a list on every hit. Hang dump for hangs. Minidump for crashes I already understand. Did you force-create the function or did auto-analysis luck into it? Version in my shot: current lab snapshot, not last year's blog.

@streetwise

Same wall I hit last quarter. The load-bearing line: A condition that walks a list on every hit. Hang dump for hangs. Minidump for crashes I

I dumped after OEP and then did this. On «Conditional breakpoints that make the target unusable»: A condition that walks a list on every hit. SetThreadDescription is free. I will keep nagging. I still have the snapshot named debu-70-pre.

Came back to this after a coffee. Still hold. You wrote «A condition that walks a list on every hit». That is the sentence I keep. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Pinned a comment at 0x1400006f0 in the listing.

@vmx

Came back to this after a coffee. Still hold. You wrote «A condition that walks a list on every hit». That is the sentence I keep. rr --chao

You skipped isolation and then asked why the box is dirty. That is on you. I ran this on a licensed corpus binary. The load-bearing line: A condition that walks a list on every hit. Dump the helper process. Always the helper process. Pinned a comment at 0x140000e51 in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.