首页
社区
课程
招聘
[讨论]tp debagport 清零
发表于: 2019-8-6 22:28 4402

[讨论]tp debagport 清零

2019-8-6 22:28
4402
kd> g
Breakpoint 0 hit
fffff801`425173b6 402ad6          sub     dl,sil





====================================
kd> g
Breakpoint 0 hit
nt!DbgkOpenProcessDebugPort+0x21:
fffff801`3d61ea4d 4d8bf0          mov     r14,r8

kd> k
 # Child-SP          RetAddr           Call Site
00 ffffde01`0f85a090 fffff801`3d5d3ff2 nt!DbgkOpenProcessDebugPort+0x21
01 ffffde01`0f85a0e0 ffff9707`253ab461 nt!NtQueryInformationProcess+0x1488f2
02 ffffde01`0f85aaf0 00000000`00000002 0xffff9707`253ab461
03 ffffde01`0f85aaf8 ffffde01`0f85ab51 0x2
04 ffffde01`0f85ab00 00000000`00000000 0xffffde01`0f85ab51


////////////////////////////////////////////////////////////////

kd> g
Breakpoint 0 hit
nt!DbgkOpenProcessDebugPort+0x48:
fffff801`3d61ea74 4885db          test    rbx,rbx
kd> k
 # Child-SP          RetAddr           Call Site
00 ffffde01`0f85a090 fffff801`3d5d3ff2 nt!DbgkOpenProcessDebugPort+0x48
01 ffffde01`0f85a0e0 ffff9707`253ab461 nt!NtQueryInformationProcess+0x1488f2
02 ffffde01`0f85aaf0 00000000`00000002 0xffff9707`253ab461
03 ffffde01`0f85aaf8 ffffde01`0f85ab51 0x2
04 ffffde01`0f85ab00 00000000`00000000 0xffffde01`0f85ab51



kd> g
Breakpoint 0 hit
nt!DbgkClearProcessDebugObject+0x34:
fffff801`3d4d9630 4885db          test    rbx,rbx
kd> k
 # Child-SP          RetAddr           Call Site
00 ffffde01`0f85a9c0 fffff801`3d6207c3 nt!DbgkClearProcessDebugObject+0x34
01 ffffde01`0f85aa00 ffff9707`253ab4fa nt!NtRemoveProcessDebug+0x103
02 ffffde01`0f85aaf0 00000000`4522c3a0 0xffff9707`253ab4fa
03 ffffde01`0f85aaf8 ffffbd0c`a8455080 0x4522c3a0
04 ffffde01`0f85ab00 00000000`ffffffff 0xffffbd0c`a8455080
05 ffffde01`0f85ab08 00000000`00000000 0xffffffff
===========================================

Breakpoint 0 hit
nt!DbgkClearProcessDebugObject+0xd9d0a:
fffff801`3d5b3306 33ff            xor     edi,edi


kd> k
 # Child-SP          RetAddr           Call Site
00 ffffde01`0f85a9c0 fffff801`3d6207c3 nt!DbgkClearProcessDebugObject+0xd9d0a
01 ffffde01`0f85aa00 ffff9707`253ab4fa nt!NtRemoveProcessDebug+0x103
02 ffffde01`0f85aaf0 00000000`4522c3a0 0xffff9707`253ab4fa
03 ffffde01`0f85aaf8 ffffbd0c`a8455080 0x4522c3a0
04 ffffde01`0f85ab00 00000000`ffffffff 0xffffbd0c`a8455080
05 ffffde01`0f85ab08 00000000`00000000 0xffffffff

kd> g
Breakpoint 0 hit
nt!DbgkpMarkProcessPeb+0x6a:
fffff801`3d61f172 0f95c1          setne   cl
kd> k
 # Child-SP          RetAddr           Call Site
00 ffffde01`0f85a950 fffff801`3d5b3315 nt!DbgkpMarkProcessPeb+0x6a
01 ffffde01`0f85a9c0 fffff801`3d6207c3 nt!DbgkClearProcessDebugObject+0xd9d19
02 ffffde01`0f85aa00 ffff9707`253ab4fa nt!NtRemoveProcessDebug+0x103
03 ffffde01`0f85aaf0 00000000`4522c3a0 0xffff9707`253ab4fa
04 ffffde01`0f85aaf8 ffffbd0c`a8455080 0x4522c3a0
05 ffffde01`0f85ab00 00000000`ffffffff 0xffffbd0c`a8455080
06 ffffde01`0f85ab08 00000000`00000000 0xffffffff

kd> g
PTModIoRequest:D[0]=0,D[1]=00
PTModIoRequest:D[0]=0,D[1]=ce
Breakpoint 0 hit
nt!DbgkCreateThread+0x8a:
fffff801`3d463832 0f856d681600    jne     nt!DbgkCreateThread+0x1668fd (fffff801`3d5ca0a5)
kd> k
 # Child-SP          RetAddr           Call Site
00 ffffde01`0fdd36f0 fffff801`3d463676 nt!DbgkCreateThread+0x8a
01 ffffde01`0fdd38d0 fffff801`3cfcaecc nt!PspUserThreadStartup+0xb6
02 ffffde01`0fdd39c0 fffff801`3cfcae40 nt!KiStartUserThread+0x1c
03 ffffde01`0fdd3b00 00007ff9`615ea250 nt!KiStartUserThreadReturn
04 00000000`69c4fcf8 00000000`00000000 ntdll!RtlUserThreadStart

> g
Breakpoint 0 hit
nt!KiDispatchException+0x279:
fffff801`3ce32bf9 0f85fea41b00    jne     nt!KiDispatchException+0x1ba77d (fffff801`3cfed0fd)



Breakpoint 0 hit
nt!DbgkForwardException+0x99:
fffff801`3d4cec45 4532f6          xor     r14b,r14b
Breakpoint 0 hit
nt!KiDispatchException+0x279:
fffff801`3ce32bf9 0f85fea41b00    jne     nt!KiDispatchException+0x1ba77d (fffff801`3cfed0fd)
nt!DbgkForwardException+0x99:
fffff801`3d4cec45 4532f6          xor     r14b,r14b
Breakpoint 0 hit
nt!KiDispatchException+0x279:
fffff801`3ce32bf9 0f85fea41b00    jne     nt!KiDispatchException+0x1ba77d (fffff801`3cfed0fd)

reak instruction exception - code 80000003 (first chance)
ntdll!DbgBreakPoint:
0033:00007ff9`61623080 cc              int     3
记录了下看不懂呀
那个是写入的?
那个是访问的?
讨论下TP 清零

[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

收藏
免费 1
支持
分享
最新回复 (4)
雪    币: 914
活跃值: (2473)
能力值: ( LV5,RANK:68 )
在线值:
发帖
回帖
粉丝
2
debag 太真实
2019-8-7 08:53
0
雪    币: 12848
活跃值: (9147)
能力值: ( LV9,RANK:280 )
在线值:
发帖
回帖
粉丝
3
君英国语本当上手
2019-8-7 10:24
0
雪    币: 435
活跃值: (176)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
NtRemoveProcessDebug 这个函数 弄死他就完事
2019-8-12 10:42
1
雪    币: 248
活跃值: (3789)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
万剑归宗 debag 太真实
dibag 更真实
2019-8-12 10:45
0
游客
登录 | 注册 方可回帖
返回
//