Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   Use IDA in kernel mode ?? (https://forum.exetools.com/showthread.php?t=14531)

Veyskarami 09-20-2012 20:47

Use IDA in kernel mode ??
 
hello
how i can use ida on kernel mode?

mm10121991 09-20-2012 21:06

I remember with windbg debug and config it to kernel mode but i forgot how to do that exactly

Git 09-20-2012 23:12

IDA won't do kernel debugging, although Bochs that comes with it may (I don't know). Best is probably windbg. Make sure you keep a map/pdb of your driver and have a read here :
http://msdn.microsoft.com/en-us/library/windows/hardware/ff553382%28v=vs.85%29.aspx

Git

Syoma 09-21-2012 04:16

afaik, ida can debug kernel mode. Check the hexrays blog, seems I saw article about kernel debugging there.

Git 09-21-2012 05:33

You're right, it's an IDA plugin to link IDA with Windbg. Nice one.

http://www.hexblog.com/?p=92

Git

mcp 09-21-2012 16:10

The best solution is probably virtualkd + VMWare + IDA WinDBG as shown here. VirtualKD provides a faster communication channel for the WinDBG backend, so you are not limited to the speed of the serial COM port emulation.

virus 09-24-2012 17:34

VirtualKD works nice. Is there a similar solution for VirtualBox?

Syoma 09-24-2012 19:20

VKD works in VBox as well.

r00t 11-29-2012 19:05

I would personally listen to the other guys and use Windbg with VKD or without (depending on your configuration), however, in case you choose to pursue this you can find a tutorial here: http://www.hexblog.com/?p=123

stantheguy 02-20-2013 16:23

Request for IDA
 
Hi guys,

Sorry if I'm a little bit off the topic but can anyone help me out with a copy of IDA. I've searched the forum but each time, I reach a dead-end as far as the search is concerned.

cheers

Syoma 02-20-2013 16:41

You can find it on the official web-site or in Google.

stantheguy 02-21-2013 18:18

Quote:

Originally Posted by Syoma (Post 82877)
You can find it on the official web-site or in Google.

Can you please provide me the link?

Git 02-21-2013 20:02

www.google.com

Syoma 02-21-2013 20:10

http://google.com/search?q=IDA+Pro+6.1+download

jlucat 02-23-2013 12:38

with VMware , and start remote.exe.


All times are GMT +8. The time now is 11:00.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX