Comments (11)
Alright noted down. The current method seems unsustainable, I believe the correct approach would be to parse that from ntoskrnl headers if the information is there. I'll try to fix this tomorrow.
from vmread.
Do you know what would be the correct return value so i could patch the function in the meantime?
from vmread.
19041, of course
from vmread.
But chances are, the offsets have also changed, you may need to fix those up as well
from vmread.
Yeah it gives me segfault when i return this value, there must be something wrong somewhere else
from vmread.
Yes, kernel structure offsets must be out of date. I will get around to fixing it when I get 2004 on my system, but I don't know when.
from vmread.
Is there any progress on this?
from vmread.
This particular issue has been resolved, however, the kernel offsets are still wrong. thus the process list will be incorrect. Someone can submit a PR with conditional offsets added for builds >= 19041 in wintools
from vmread.
Any help as to where i can find/dump these offsets?
from vmread.
Windbg provides a way to print data tables (dt!nt or something like that), the names in wintools, however, are very much shortened, so you would have to guess, or compare with the names at around the same offsets (they rarely change much, but rather by a few multiples of 8 bytes)
from vmread.
Fixed in #32
from vmread.
Related Issues (20)
- Pattern search can't handle multiple ?? regions HOT 1
- Further 1903 Compatibility Issues HOT 2
- Support for modules of System process HOT 3
- Kmod_External DeadlySignal HOT 2
- Windows 1909 update HOT 2
- Process Names bigger than 16 get cut off HOT 6
- Host and Guest crash HOT 2
- User mode -> VM -> User mode HOT 3
- Initialization Error 3 HOT 8
- dirBase changed at runtime HOT 4
- Infinite loop regression. HOT 2
- what's MODE_DMA for? HOT 1
- Not an actual issue. HOT 3
- Kernel 5.6.2+ HOT 3
- Kmod does not compile on Kernel 5.7+ HOT 1
- Project maintenance HOT 4
- delete me HOT 1
- Initialization error: -1
- Linux 5.8 changes HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from vmread.