x86 hardware watchpoint on a 3-byte field worked by accident. ARM64 refused. I watched the 8-byte container.
Document the alignment. Future you will thank you.
Refs: WinDbg
Lab / educational. Public binaries and patched classes only. Isolated VM.
x86 hardware watchpoint on a 3-byte field worked by accident. ARM64 refused. I watched the 8-byte container.
Document the alignment. Future you will thank you.
Refs: WinDbg
Lab / educational. Public binaries and patched classes only. Isolated VM.
The screenshot is the useful part of the post. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentence I keep. Page heap and ASan catch different lies. I run both. Took me 10 hours the first time.
@kenwise
The screenshot is the useful part of the post. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentenc
I read the patch. You read a tweet. Those are not the same source. I would have written the opposite conclusion a year ago. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. I will +rep a listing and ârep a vibe. That is the deal.
This is the writeup I wanted when I was stuck. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. WOW64: switch the stack before you talk. !wow64exts.sw. If anyone DMs me a zip I will not open it. Hash in-thread.
@lockx
This is the writeup I wanted when I was stuck. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a 3-byte fiel
Call-convention guess is not evidence. Good. Dated shot, version in the post. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Did you snapshot before, or is this a restore-from-memory story? I wrote a 12-line script and then threw it away. The listing was enough.
@mikeflex
Good. Dated shot, version in the post. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Kernel time trav
Quietly the best note on this board this month. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentence I keep. !analyze is a hypothesis. !thread and the raw stacks are the evidence. My note id for this: 59-04.
@nexx
Quietly the best note on this board this month. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the senten
Do not call people skids because they use Ghidra. I still keep a paper notebook for this kind of note. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I will +rep a listing and ârep a vibe. That is the deal.
I disagree with the tone, not the bytes. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. Hang dump for hangs. Minidump for crashes I already understand. Took me 7 hours the first time.
@payld
I disagree with the tone, not the bytes. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field work
You are describing a live target. Stop. Patched class only. I reproduced it twice before I believed you. You wrote «x86 hardware watchpoint on a 3-byte field worked by accident». That is the sentence I keep. Hang dump for hangs. Minidump for crashes I already understand. I wrote a 12-line script and then threw it away. The listing was enough.
Not fully convinced yet. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. WOW64: switch the stack before you talk. !wow64exts.sw. Did you snapshot before, or is this a restore-from-memory story? Same class as the March thread, different binary.
@rsec
Not fully convinced yet. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. WOW64: switch the stack before
Take the telegram pitch to the bin. Market listing or nothing. Quietly the best note on this board this month. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Hang dump for hangs. Minidump for crashes I already understand. Same class as the October thread, different binary.
@sessx
Quietly the best note on this board this month. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Hang du
Did this on ARM64 last week â same shape, different pain. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. Hang dump for hangs. Minidump for crashes I already understand. Took me 8 hours the first time.
@sock
Did this on ARM64 last week â same shape, different pain. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a
Quote the bytes or sit down. I disagree with the tone, not the bytes. The load-bearing line: x86 hardware watchpoint on a 3-byte field worked by accident. Hang dump for hangs. Minidump for crashes I already understand. My note id for this: 59-11.
I failed this exact class in January. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I still have the snapshot named debu-89-pre.
Also: !analyze is a hypothesis. !thread and the raw stacks are the evidence.
@tonybliss
I failed this exact class in January. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked
You are treating a checksum as a signature again. I disagree with the tone, not the bytes. On «Watchpoints on unaligned fields â x86 vs ARM64»: x86 hardware watchpoint on a 3-byte field worked by accident. Dump the helper process. Always the helper process. After you did that, did the decompiler pick it up or did you dump? Pinned a comment at 0x140006e02 in the listing.