>_0xFORUM
Sign in

WinDbg time travel: stepping across a syscall

in Debugging15 replies3.5k views

Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. People still try.

You get the user return. For kernel you need a kernel trace. Say it louder.

Refs: WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 15 REPLIES

@xcrypt

Quietly the best note on this board this month. The load-bearing line: Stepping into NtDeviceIoControlFile in TTD does not take you to the k

That is not what the listing shows. You are arguing a vibe. Good. Dated shot, version in the post. You wrote «Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel». That is the sentence I keep. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Was this on the licensed corpus or a crackme you wrote? Version in my shot: current lab snapshot, not last year's blog.

@bytefx

I tried the naive path first and wasted a morning. The load-bearing line: Stepping into NtDeviceIoControlFile in TTD does not take you to th

Do not call people skids because they use Ghidra. Please keep the hashes and drop the mystery zips. The load-bearing line: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Version in my shot: current lab snapshot, not last year's blog.

@codex

I ran this on a licensed corpus binary. On «WinDbg time travel: stepping across a syscall»: Stepping into NtDeviceIoControlFile in TTD does

You are describing a live target. Stop. Patched class only. I ran this on a licensed corpus binary. You wrote «Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel». That is the sentence I keep. TTD queries that scan the whole trace are how you learn patience. Narrow the range. My note id for this: 49-11.

I want the listing, not the decompiler story. «WinDbg time travel: stepping across a syscall» — specifically Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. SetThreadDescription is free. I will keep nagging. Took me 5 hours the first time.

Also: SetThreadDescription is free. I will keep nagging.

This is the kind of thread that should be a sticky and is not. On «WinDbg time travel: stepping across a syscall»: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x140000c09 in the listing.

I tried the naive path first and wasted a morning. The load-bearing line: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. Hang dump for hangs. Minidump for crashes I already understand. After you did that, did the decompiler pick it up or did you dump? Pinned a comment at 0x14000499e in the listing.

I failed this exact class in January. On «WinDbg time travel: stepping across a syscall»: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. Hang dump for hangs. Minidump for crashes I already understand. My note id for this: 49-06.

@exec

Good. Dated shot, version in the post. You wrote «Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel». That is the s

I ran this on a licensed corpus binary. The load-bearing line: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. Page heap and ASan catch different lies. I run both. If anyone DMs me a zip I will not open it. Hash in-thread.

@agent

I ran this on a licensed corpus binary. The load-bearing line: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. P

I read the patch. You read a tweet. Those are not the same source. I disagree with the tone, not the bytes. On «WinDbg time travel: stepping across a syscall»: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I wrote a 12-line script and then threw it away. The listing was enough.

@beacon

I failed this exact class in January. On «WinDbg time travel: stepping across a syscall»: Stepping into NtDeviceIoControlFile in TTD does no

Call-convention guess is not evidence. Same wall I hit last quarter. You wrote «Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel». That is the sentence I keep. Hang dump for hangs. Minidump for crashes I already understand. Same class as the March thread, different binary.

@davidnode

I want the listing, not the decompiler story. «WinDbg time travel: stepping across a syscall» — specifically Stepping into NtDeviceIoControl

Take the telegram pitch to the bin. Market listing or nothing. Same wall I hit last quarter. You wrote «Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel». That is the sentence I keep. If gdb finish hangs, there was a longjmp. Stop waiting. Which build of the tool? I got burned mixing notes across versions. I reproduced it on lab build 1336.

@chrisvibe

Please keep the hashes and drop the mystery zips. The load-bearing line: Stepping into NtDeviceIoControlFile in TTD does not take you to the

I ran this on a licensed corpus binary. On «WinDbg time travel: stepping across a syscall»: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. I reproduced it on lab build 1412.

Please keep the hashes and drop the mystery zips. «WinDbg time travel: stepping across a syscall» — specifically Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. If gdb finish hangs, there was a longjmp. Stop waiting. My note id for this: 49-00.

@tonybliss

Please keep the hashes and drop the mystery zips. «WinDbg time travel: stepping across a syscall» — specifically Stepping into NtDeviceIoCon

I am not moving this to DMs so you can yell. Stay on the class. I want the listing, not the decompiler story. «WinDbg time travel: stepping across a syscall» — specifically Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I reproduced it on lab build 1014.

Quietly the best note on this board this month. The load-bearing line: Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.