Nested VM, no debug transport. I triggered a hang dump from the hypervisor side and pulled the vmem.
It worked. It was ugly. I would still rather have kdnet.
Refs: WinDbg
Lab / educational. Public binaries and patched classes only. Isolated VM.
Nested VM, no debug transport. I triggered a hang dump from the hypervisor side and pulled the vmem.
It worked. It was ugly. I would still rather have kdnet.
Refs: WinDbg
Lab / educational. Public binaries and patched classes only. Isolated VM.
I dumped after OEP and then did this. On «Kernel dump from a VM that has no serial and no kdnet»: Nested VM, no debug transport. Hang dump for hangs. Minidump for crashes I already understand. Same class as the January thread, different binary.
@n0xturn
I dumped after OEP and then did this. On «Kernel dump from a VM that has no serial and no kdnet»: Nested VM, no debug transport. Hang dump f
Do not call people skids because they use Ghidra. This belongs in the first-hour ritual. On «Kernel dump from a VM that has no serial and no kdnet»: Nested VM, no debug transport. TTD queries that scan the whole trace are how you learn patience. Narrow the range. If anyone DMs me a zip I will not open it. Hash in-thread.
I disagree with the tone, not the bytes. You wrote «Nested VM, no debug transport». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. Can you quote the offset instead of the graph screenshot? Took me 6 hours the first time.
@auth
I disagree with the tone, not the bytes. You wrote «Nested VM, no debug transport». That is the sentence I keep. WOW64: switch the stack bef
You are describing a live target. Stop. Patched class only. Not fully convinced yet. «Kernel dump from a VM that has no serial and no kdnet» — specifically Nested VM, no debug transport. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Same class as the June thread, different binary.
@bitlab
Not fully convinced yet. «Kernel dump from a VM that has no serial and no kdnet» — specifically Nested VM, no debug transport. Kernel time t
I failed this exact class in January. «Kernel dump from a VM that has no serial and no kdnet» — specifically Nested VM, no debug transport. TTD queries that scan the whole trace are how you learn patience. Narrow the range. I still have the snapshot named debu-71-pre.
Good. Dated shot, version in the post. You wrote «Nested VM, no debug transport». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. My note id for this: 47-00.
@shola_k
Good. Dated shot, version in the post. You wrote «Nested VM, no debug transport». That is the sentence I keep. WOW64: switch the stack befor
That is not what the listing shows. You are arguing a vibe. I failed this exact class in January. You wrote «Nested VM, no debug transport». That is the sentence I keep. Page heap and ASan catch different lies. I run both. I reproduced it on lab build 1106.
I will argue the opposite and then probably agree. The load-bearing line: Nested VM, no debug transport. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x140002c96 in the listing.
@sysx
I will argue the opposite and then probably agree. The load-bearing line: Nested VM, no debug transport. Kernel time travel is not user TTD.
I read the patch. You read a tweet. Those are not the same source. This belongs in the first-hour ritual. The load-bearing line: Nested VM, no debug transport. Hang dump for hangs. Minidump for crashes I already understand. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.
@uptownkid
This belongs in the first-hour ritual. The load-bearing line: Nested VM, no debug transport. Hang dump for hangs. Minidump for crashes I alr
I failed this exact class in January. You wrote «Nested VM, no debug transport». That is the sentence I keep. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x1400002f6 in the listing.
@vultr
I failed this exact class in January. You wrote «Nested VM, no debug transport». That is the sentence I keep. Kernel time travel is not user
Call-convention guess is not evidence. Came back to this after a coffee. Still hold. The load-bearing line: Nested VM, no debug transport. If gdb finish hangs, there was a longjmp. Stop waiting. I wrote a 12-line script and then threw it away. The listing was enough.