>_0xFORUM
Sign in

Watchpoints on unaligned fields — x86 vs ARM64

in Debugging14 replies1.1k views

x86 hardware watchpoint on a 3-byte field worked by accident. ARM64 refused. I watched the 8-byte container.

Document the alignment. Future you will thank you.

Refs: WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 14 REPLIES

The screenshot is the useful part of the post. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentence I keep. Page heap and ASan catch different lies. I run both. Took me 10 hours the first time.

@kenwise

The screenshot is the useful part of the post. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentenc

I read the patch. You read a tweet. Those are not the same source. I would have written the opposite conclusion a year ago. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. I will +rep a listing and −rep a vibe. That is the deal.

This is the writeup I wanted when I was stuck. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. WOW64: switch the stack before you talk. !wow64exts.sw. If anyone DMs me a zip I will not open it. Hash in-thread.

@lockx

This is the writeup I wanted when I was stuck. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a 3-byte fiel

Call-convention guess is not evidence. Good. Dated shot, version in the post. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Did you snapshot before, or is this a restore-from-memory story? I wrote a 12-line script and then threw it away. The listing was enough.

@mikeflex

Good. Dated shot, version in the post. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Kernel time trav

Quietly the best note on this board this month. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentence I keep. !analyze is a hypothesis. !thread and the raw stacks are the evidence. My note id for this: 59-04.

@nexx

Quietly the best note on this board this month. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the senten

Do not call people skids because they use Ghidra. I still keep a paper notebook for this kind of note. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I will +rep a listing and −rep a vibe. That is the deal.

I disagree with the tone, not the bytes. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. Hang dump for hangs. Minidump for crashes I already understand. Took me 7 hours the first time.

@payld

I disagree with the tone, not the bytes. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field work

You are describing a live target. Stop. Patched class only. I reproduced it twice before I believed you. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentence I keep. Hang dump for hangs. Minidump for crashes I already understand. I wrote a 12-line script and then threw it away. The listing was enough.

Not fully convinced yet. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. WOW64: switch the stack before you talk. !wow64exts.sw. Did you snapshot before, or is this a restore-from-memory story? Same class as the March thread, different binary.

@rsec

Not fully convinced yet. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. WOW64: switch the stack before

Take the telegram pitch to the bin. Market listing or nothing. Quietly the best note on this board this month. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Hang dump for hangs. Minidump for crashes I already understand. Same class as the October thread, different binary.

@sessx

Quietly the best note on this board this month. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Hang du

Did this on ARM64 last week — same shape, different pain. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. Hang dump for hangs. Minidump for crashes I already understand. Took me 8 hours the first time.

@sock

Did this on ARM64 last week — same shape, different pain. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a

Quote the bytes or sit down. I disagree with the tone, not the bytes. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Hang dump for hangs. Minidump for crashes I already understand. My note id for this: 59-11.

I failed this exact class in January. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I still have the snapshot named debu-89-pre.

Also: !analyze is a hypothesis. !thread and the raw stacks are the evidence.

@tonybliss

I failed this exact class in January. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked

You are treating a checksum as a signature again. I disagree with the tone, not the bytes. On «Watchpoints on unaligned fields — x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. Dump the helper process. Always the helper process. After you did that, did the decompiler pick it up or did you dump? Pinned a comment at 0x140006e02 in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.