|
Forums Terrorist posted:winders 2000 had a cooler name thus it is the better choice and a better logo
|
# ? Dec 10, 2014 02:37 |
|
|
# ? Apr 26, 2024 18:09 |
|
im the New Technology Technology
|
# ? Dec 10, 2014 04:33 |
|
even windows 7 looks presentable when you set it to use the Classic theme locked in a VM ghetto where it loving belongs
|
# ? Dec 10, 2014 06:24 |
|
so I've had a curious windows internals issue recently. I have some target software whose very obfuscated usermode component loads a packed driver that proceeds to unpack itself, destroy its PE header, etc. It does something to detect windbg being attached and proceeds to destroy various kernel stuff before causing an irql_not_less_or_equal bugcheck. So ideally I would set windbg to breakpoint on module load so I could patch out whatever's detecting windbg before any of the module's code executes. I have no idea how windbg detects the load module event, but it never triggers for the loading of this driver. The bugcheck occurs, analysis shows no clues. Probably have these options: tick all the boxes in rohitab API monitor and dig through a huge log to figure out what they're doing in userland to load the kernel module find the specific kernel function that creates the initial kernel thread or whatever for modules and breakpoint there, then set breakpoints on the module's entry points as it'll be known then both options sorta suck, lotta stuff to look through just to get debugging working.
|
# ? Dec 13, 2014 13:58 |
|
Notorious b.s.d. posted:windows has had text anti-aliasing since at least windows 3.0, probably earlier i meant subpixel rendering or whatever. i just know that i tried win 2000 on an old laptop and it looked like dogshit
|
# ? Dec 13, 2014 14:25 |
|
Notorious b.s.d. posted:windows has had text anti-aliasing since at least windows 3.0, probably earlier lol nope, the first windows that could antialias text was 95, and even then only if you bought the
|
# ? Dec 13, 2014 14:31 |
|
Soricidus posted:lol nope, the first windows that could antialias text was 95, and even then only if you bought the
|
# ? Dec 13, 2014 16:18 |
|
Soricidus posted:lol nope, the first windows that could antialias text was 95, and even then only if you bought the not that it really mattered since blurry 15" CRT monitors did that for you.
|
# ? Dec 13, 2014 21:05 |
|
15 inches?? luxury
|
# ? Dec 13, 2014 21:23 |
|
Daman posted:so I've had a curious windows internals issue recently. try breaking on nt!NtLoadDriver
|
# ? Dec 14, 2014 00:41 |
|
|
# ? Apr 26, 2024 18:09 |
|
omeg posted:try breaking on nt!NtLoadDriver this worked! specifically within this on win7 x64 is nt!IopLoadDriver+0xa04 which calls the entry point for new drivers. interestingly enough, this driver isn't listed in the module list at that point. its unpacking routine handles adding it to that.
|
# ? Dec 14, 2014 21:42 |