惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Project Zero
Project Zero
www.infosecurity-magazine.com
www.infosecurity-magazine.com
月光博客
月光博客
Simon Willison's Weblog
Simon Willison's Weblog
S
Schneier on Security
B
Blog
NISL@THU
NISL@THU
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
AWS News Blog
AWS News Blog
W
WeLiveSecurity
PCI Perspectives
PCI Perspectives
博客园 - 三生石上(FineUI控件)
Stack Overflow Blog
Stack Overflow Blog
F
Fortinet All Blogs
Apple Machine Learning Research
Apple Machine Learning Research
P
Palo Alto Networks Blog
I
Intezer
美团技术团队
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
H
Heimdal Security Blog
T
Troy Hunt's Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Forbes - Security
Forbes - Security
T
The Exploit Database - CXSecurity.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
Check Point Blog
J
Java Code Geeks
The GitHub Blog
The GitHub Blog
U
Unit 42
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
C
Cisco Blogs
S
SegmentFault 最新的问题
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
AI
AI
WordPress大学
WordPress大学
Help Net Security
Help Net Security
Security Archives - TechRepublic
Security Archives - TechRepublic
Microsoft Azure Blog
Microsoft Azure Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
小众软件
小众软件
Cyberwarzone
Cyberwarzone
Scott Helme
Scott Helme
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
G
GRAHAM CLULEY
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
H
Hacker News: Front Page

博客园 - softfair

在Windows平台编译Substrate (How to compile and run Substrate on Windows) Truffle migrate deploy contract ESOCKETTIMEDOUT - How to fix Rust 里 String,str,Vec<u8>,Vec<char> 相互转换【Conversion between String, str, Vec<u8>, Vec<char> in Rust】 Linux下一个最简单的不依赖第三库的的C程序(2) Linux下一个最简单的不依赖第三库的的C程序(1) windbg .net 程序的死锁检测 常用方法(个人备份笔记) 自定义经纬度索引(非RTree、Morton Code[z order curve]、Geohash的方式) 通过经纬度坐标计算距离的方法(经纬度距离计算) 根据2个经纬度点,计算这2个经纬度点之间的距离(通过经度纬度得到距离) The version of SOS does not match the version of CLR you are debugging; SOS.dll版本不匹配; Dump文件不同环境mscordacwks.dll版本问题 WCF 4.0 如何编程修改wcf配置,不使用web.config静态配置 WCF4.0安装 NET.TCP启用及常见问题 Windbg 脚本命令简介 二, Windbg command what’s new in the .NET CLR 4.0/4.5 GC (.NET 4/4.5里新的垃圾收集机制) Windows中内存管理的一些知识 SSO(Single Sign-on) in Action 阿里巴巴将跌破1元股价 word 2007 中插入图片无法显示,只能显示底部一部分 Linux 动态库剖析
Windbg 脚本命令简介 一
softfair · 2013-11-30 · via 博客园 - softfair

Windbg  脚本命令简介 一 Windbg command

r:

registers的简写,可以显示或修改寄存器的值、浮点寄存器的值、定义别名变量。

可以显示当前线程下的寄存器值。

The r command displays or modifies registers, floating-point registers, flags, pseudo-registers, and fixed-name aliases.

0:000> ~2 r

//显示 2号线程的寄存器值

0:000> ~* r eax

//显示所有线程的 eax寄存器值

n (Set Number Base)

设置默认显示的数字进制(Radix)

0:000> n

base is 16

//显示默认进制

0:000> n 10

base is 10

//改成10进制

Value

Description

8

Octal

10

Decimal

16

Hexadecimal

In all MASM expressions, numeric values are interpreted as numbers in the current radix (16, 10, or 8). You can override the default radix by specifying the 0x prefix (hexadecimal), the 0n prefix (decimal), the 0t prefix (octal), or the 0y prefix (binary).

dc 00cc07c8 00cc07c8+0n4344

              Windbg默认的数值进制一般是16, 可以通过n命令查看和设置当前进制,

              , 0n(十进制), 0x(十六进制), 0t(8进制), 0y(2进制), 比如0n20表示20, 0x14表示20等

? Expression(Evaluate Expression)

计算表达式

0:000> as fn c:\dir\name.txt                                              //定义一个别名,设置别名,Alias Set

0:000> $spat("c:\dir\name.txt","*name*")                           //没有输出

0:000> ?$spat("c:\dir\name.txt","*name*")                          //计算结果,\n被转义,所以结果是0.

Evaluate expression: 0 = 00000000`00000000

0:000> ?$spat(@"c:\dir\name.txt","*name*")                        //在字符串前面加 @符号

Evaluate expression: 1 = 00000000`00000001

0:000> ?$spat("c:\dir\","*name*")

Syntax error at '("c:\dir\","*name*")'                                     //有错误,因为dir\” 这里被转义

0:000> ?$spat(@"c:\dir\","*name*")                                    //使用@,防止被转义

Evaluate expression: 0 = 00000000`00000000

0:000> ?$spat(@"c:\\name","*name")

Evaluate expression: 1 = 00000000`00000001                       //找到结果,输出1,表示true

0:000> ?$spat(@"c:\dir\","*d*")

Evaluate expression: 1 = 00000000`00000001

0:000> ?$spat(${fn},"*d*")

Syntax error at '(c:\dir\name.txt,"*d*")'                                //定义别名就是类似C++ 里的宏

0:000> ?$spat("${fn}","*d*")

Evaluate expression: 1 = 00000000`00000001

0:000> ?$spat("${fn}","*name*")

Evaluate expression: 0 = 00000000`00000000                       // fn 中的\n 被转义,所以找不到

0:000> ?$spat(@"${fn}","*name*")

Evaluate expression: 1 = 00000000`00000001

$spat 是MASM里的一个命令,检查第一个string参数是否符合第二个参数的模式(大小写敏感),

要注意 转移字符 \n\"\r, and \b

?? 是c++表达式格式的,对应MASM的 ? 功能。

Address and Address Range Syntax

下面的2个是等价的,dd是读取双字,即4个字节,2个字节(byte)为一个字(word)。

当一个存放于0x00123456 的指针指向地址0x00420000,我们想显示位于地址0x00420000的内容时,可以有如下选择:

0:000> dd 420000                        //直接打印位于该地址的值

0:000> dd poi(123456)

//取得0x00123456地址上指针的值,以poi函数(point to int)取值,即32位平台取4字节,64位平台取8字节,取的都是一个完整指针大小的长度,32位平台指针长度为4字节,64位平台指针长度是8字节。额外一点,int/Int32无论在32还是64位平台都是4字节。

读取开始地址为0x00001000  的8字节:这里假设对象长度是1字节,L指定是对象个数,它跟对象的大小有关系

Dd 0x00001000  0x00001007 //指定开始地址,结束地址

Dd 0x00001000  L8  //指定开始地址,对象个数8,假设对象是1字节长度
Dd 0x00001000  L2  //指定开始地址,对象个数2,假设对象是双字长度(4字节)

Dd 80000000 L20  // the range from 0x80000000 through 0x8000001F

Dd 80000000 L-20  //specifies the range from 0x7FFFFFE0 through 0x7FFFFFFF.

MASM parser treats all symbols as addresses, the example must have the poi operator to dereference MyVar

MASM解析器把所有的symbol符号都用地址的方式来表示,所以必须用poi函数来解析出地址里面的值。

实例:

0:000> !do 0x0000000122a8b110

Name:        InternalEntity.CityInfoEntity

MethodTable: 000007ff00283908

EEClass:     000007ff00293c18

Size:        48(0x30) bytes

File:        C:\ SearchService.InternalEntity.dll

Fields:

MT

Field  

Offset                

Type

VT    

Attr           

Value

Name

000007fee4abc7e8

4000534

10

     System.Int32

 1

instance

           30138

city

000007fee4abc7e8

4000535

14

     System.Int32

 1

instance

           10082

province

000007fee4abc7e8

4000536

18

      Sstem.Int32

 1

instance

              28

country

000007fee4abd618

4000537

20

   System.Boolean

 1

instance

               1

hasMemoryCacheConfig

000007ff00463810

4000538

 8

...ityTimeZoneEntity

 0

instance

0000000122a8b140

<CityTimeZone>k__BackingField

000007fee4abc7e8

4000539

1c

     System.Int32

 1

instance

               0

<CityhotelCount>k__BackingField

0:000> dc 0x0000000122a8b110

00000001`22a8b110  00283908 000007ff 22a8b140 00000001  .9(.....@.."....   

00000001`22a8b120  000075ba 00002762 0000001c 00000000  .u..b'..........

00000001`22a8b130  00000001 00000000 00000000 00000000  ................

00000001`22a8b140  00463810 000007ff 000075ba 00000e10  .8F......u......

00000001`22a8b150  00000e10 00000001 d266c000 08cffbb9  ..........f.....

00000001`22a8b160  9d264000 08d0a0be 20c3c000 08d119c2  .@&........ ....

00000001`22a8b170  eb834000 08d1bec6 00000000 00000000  .@..............

00000001`22a8b180  00256438 000007ff 22a8b110 00000001  8d%........"....

ß 这里一行的长度是0n16 4字节*4组=16字节 的计算方式。

这里看一下这里Offset=8的地方是CityTimeZone对象,确实是Offset在8字节处。

0:000> dc 0x0000000122a8b110+0x10   //0x000075ba=0n30138

00000001`22a8b120  000075ba 00002762 0000001c 00000000  .u..b'..........

00000001`22a8b130  00000001 00000000 00000000 00000000  ................

00000001`22a8b140  00463810 000007ff 000075ba 00000e10  .8F......u......

00000001`22a8b150  00000e10 00000001 d266c000 08cffbb9  ..........f.....

00000001`22a8b160  9d264000 08d0a0be 20c3c000 08d119c2  .@&........ ....

00000001`22a8b170  eb834000 08d1bec6 00000000 00000000  .@..............

00000001`22a8b180  00256438 000007ff 22a8b110 00000001  8d%........"....

00000001`22a8b190  00000000 00000000 00000085 000075ba  .............u..

ß 这根据上面的Offset 0x10来直接用内存看,得到的结果是一样的,0x000075ba = 0n30138,使用?0x75ba 直接计算表达式可以得到值,如下所示。

0:000> n16

base is 16

0:000> ?0x75ba //? 计算表达式的值

Evaluate expression: 30138 = 00000000`000075ba

0:000> !do 0000000122a8b140

Name:        CityTimeZoneEntity

MethodTable: 000007ff00463810

EEClass:     000007ff00475880

Size:        64(0x40) bytes

File:        C:\Hotel.Product.SearchService.InternalEntity.dll

Fields:

             MT

  Field

Offset

          Type

VT

    Attr

           Value

Name

000007fee4abc7e8

4000490

     8

   System.Int32

 1

instance

           30138

<City>k__BackingField

000007fee4abc7e8

4000491

     c

   System.Int32

 1

instance

            3600

<DstOffset>k__BackingField

000007fee4abd618

4000492

    14

 System.Boolean

 1

instance

               1

<IsSupportDst>k__BackingField

000007fee4ad96d8

4000493

    18

System.DateTime

 1

instance

0000000122a8b158

<CurDstStartDate>k__BackingField

000007fee4ad96d8

4000494

    20

System.DateTime

 1

instance

0000000122a8b160

<CurDstEndDate>k__BackingField

000007fee4ad96d8

4000495

    28

System.DateTime

 1

instance

0000000122a8b168

<NextDstStartDate>k__BackingField

000007fee4ad96d8

4000496

    30

System.DateTime

 1

instance

0000000122a8b170

<NextDstEndDate>k__BackingField

000007fee4abc7e8

4000497

    10

   System.Int32

 1

instance

            3600

<UTCOffset>k__BackingField

0:000> dd 0000000122a8b140

00000001`22a8b140  00463810 000007ff 000075ba 00000e10

00000001`22a8b150  00000e10 00000001 d266c000 08cffbb9

00000001`22a8b160  9d264000 08d0a0be 20c3c000 08d119c2

<-- 查看offset=8的地方,发现值确实是30138,查看offset=12,16进制 0xc的地方值确实为3600

0:000> ?0x75ba

Evaluate expression: 30138 = 00000000`000075ba

0:000> ?0xe10

Evaluate expression: 3600 = 00000000`00000e10

0:000> dd poi(0x0000000122a8b110+8)

00000001`22a8b140  00463810 000007ff 000075ba 00000e10

00000001`22a8b150  00000e10 00000001 d266c000 08cffbb9

00000001`22a8b160  9d264000 08d0a0be 20c3c000 08d119c2

00000001`22a8b170  eb834000 08d1bec6 00000000 00000000

00000001`22a8b180  00256438 000007ff 22a8b110 00000001

00000001`22a8b190  00000000 00000000 00000085 000075ba

00000001`22a8b1a0  00000000 00000000 4aea67f9 08d0b971

00000001`22a8b1b0  00000000 00000000 e4ab6900 000007fe

0:000> !do  poi(0x000000122a8b110+8)

Name:        Hotel.Product.SearchService.InternalEntity.CityTimeZoneEntity

MethodTable: 000007ff00463810

EEClass:     000007ff00475880

Size:        64(0x40) bytes

<--直接将CityInfoEntity 对象Offset=8位置处的地址通过poi函数得到该地址上的值0000000122a8b140 ,运行!do <object address> 看到的是CityTimeZoneEntity这个对象的内容。如果不加poi函数,dd 看到的还是CityInfoEntity对象的内容,

运行 !do 0x000000122a8b110+8 看到的将不是一个有效的对象。

下面来看看如果不小心输入了下面的命令会是什么结果:

0:000> dd poi(0x0000000122a8b110)+8

000007ff`00283910  00050011 00000004 e4ab5a58 000007fe

000007ff`00283920  0025ed18 000007ff 00283978 000007ff

000007ff`00283930  00293c18 000007ff 00000000 00000000

000007ff`00283940  00000000 00000000 00283958 000007ff

<--里右括号括号的位置与上面的命令位置不一样。

看到前面正确命令的基地址是00000001`22a8b140,而这里变成了000007ff`00283910 ,差距很大。

原因是什么呢? Poi命令把0x0000000122a8b110地址上的值作为另外一个地址,0x0000000122a8b110 后续的几个字节的那一段东西其实是内容,而不是地址。它表示的是CityInfoEntity这个对象的有实际意义的内容,而不是地址。Poi命令简单粗暴的将内容作为地址来对待。

0:000> dd 0x0000000122a8b110

00000001`22a8b110  00283908 000007ff 22a8b140 00000001

00000001`22a8b120  000075ba 00002762 0000001c 00000000

<--通过dd 查看到以16进制表示的一串数字,这些数字是代表了CityInfoEntity的内容,00283908 000007ff 是内容,而poi把它作为地址来使用了。

0:000> dd 000007ff00283908

000007ff`00283908  00080000 00000030 00050011 00000004

000007ff`00283918  e4ab5a58 000007fe 0025ed18 000007ff

000007ff`00283928  00283978 000007ff 00293c18 000007ff

<--通过查看00283908 000007ff 这个地址的内容,我们找到offset=8的地方的内容,可以发现下划线的东西是一样的。