Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-02-2015, 17:36
-=bb=- -=bb=- is offline
Family
 
Join Date: Sep 2009
Location: slowly learning
Posts: 72
Rept. Given: 23
Rept. Rcvd 37 Times in 10 Posts
Thanks Given: 18
Thanks Rcvd at 23 Times in 9 Posts
-=bb=- Reputation: 37
What is everyone using for Ring 0 these days?

There are lots of lovely (x64/IDA/Olly) Ring 3 debuggers around at the moment but a bit of a dearth of Ring 0 as far as I can make out.

Syser seems dead, SoftIce is but a fond and distant memory.

I'm kind of looking at attaching IDA with GDB to a VM but have a few snags trying to do that at the moment (not sure why - going to play some more over the Easter break) but thought I would ask here. So ...

What is the community using for Ring 0/Kernel debugging at the moment?

Many thanks in advance and happy Easter break to all.

-=bb=-
Reply With Quote
  #2  
Old 04-02-2015, 17:43
mr.exodia mr.exodia is offline
Retired Moderator
 
Join Date: Nov 2011
Posts: 784
Rept. Given: 492
Rept. Rcvd 1,122 Times in 305 Posts
Thanks Given: 90
Thanks Rcvd at 711 Times in 333 Posts
mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299
windbg, it's the best for windows ring0 debugging (although it's very slow).
Reply With Quote
The Following User Says Thank You to mr.exodia For This Useful Post:
-=bb=- (04-02-2015)
  #3  
Old 04-02-2015, 18:37
-=bb=- -=bb=- is offline
Family
 
Join Date: Sep 2009
Location: slowly learning
Posts: 72
Rept. Given: 23
Rept. Rcvd 37 Times in 10 Posts
Thanks Given: 18
Thanks Rcvd at 23 Times in 9 Posts
-=bb=- Reputation: 37
Hey mr.exodia!

Thank you for your reply - I assume you mean using Windbg in a dual machine environment rather than on a single machine? IIRC you can't use Windbg on a standalone machine for Ring 0 - though I am very happy to be corrected.

EDIT : To be clear I'm on a Windows 8 64bit system. Following instructions from here (hxxps://msdn.microsoft.com/en-us/library/windows/hardware/ff553382(v=vs.85).aspx) leads me to an error stating that local kernel debugging is not supported by WOW64. Though the restrictions placed on commands you can and cannot run local debugging under Windbg (assuming I could get it to work) would render it basically useless IMHO

-=bb=-

Last edited by -=bb=-; 04-02-2015 at 19:16. Reason: Added more information
Reply With Quote
  #4  
Old 04-02-2015, 19:25
Syoma Syoma is offline
reverse engineer
 
Join Date: May 2009
Posts: 338
Rept. Given: 35
Rept. Rcvd 77 Times in 50 Posts
Thanks Given: 15
Thanks Rcvd at 78 Times in 51 Posts
Syoma Reputation: 77
Try VirtualKD.
Reply With Quote
The Following 2 Users Say Thank You to Syoma For This Useful Post:
-=bb=- (04-02-2015), Nacho_dj (04-15-2015)
  #5  
Old 04-02-2015, 20:38
-=bb=- -=bb=- is offline
Family
 
Join Date: Sep 2009
Location: slowly learning
Posts: 72
Rept. Given: 23
Rept. Rcvd 37 Times in 10 Posts
Thanks Given: 18
Thanks Rcvd at 23 Times in 9 Posts
-=bb=- Reputation: 37
Thank you Syoma - I'll look into that over the break!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 05:47.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )