3.windbg-!pte转换地址(ring0)

1.取得DirBase

kd> !process  0 0 test.exe
PROCESS 89ed6170  SessionId: 0  Cid: 0558	Peb: 7ffd9000  ParentCid: 0744
	DirBase: 0a7c0340  ObjectTable: e1e6b5a8  HandleCount:  15.
	Image: test.exe

2. 切换到指定进程

使用.process /i /p 89ed6170 注意一定要加/i
然后使用.process确认内核已切换到89ed6170 这个进程
然后!pte va即可!
给个清晰的示意图:


3.pfn对应详解



而!pfn更快:

kd> !pfn 806aeffc
PFN 006AEFFC at address 8C9B6F90//006AEFFC 为806aeffc的物理地址
flink 00000000 blink / share count 00000000 pteaddress 00000000
reference count 0000 NonCached color 0
restore pte 00000000 containing page 000000 Zeroed
kd> !pte 806aeffc
VA 806aeffc
PDE at 00000000C0602018 PTE at 00000000C0403570
contains 00000000006001E3 contains 0000000000000000
pfn 600 -GLDA–KWEV LARGE PAGE pfn 6ae
kd> db 806aeffc
806aeffc 00 00 00 00 00 00 00 00-00 00 00 00 4a 77 1d 00 …………Jw..
806af00c 2c 06 00 00 4c 70 1d 00-00 00 00 00 00 00 00 00 ,…Lp……….
806af01c 0e 78 1d 00 00 06 00 00-7c 71 1d 00 00 00 00 00 .x……|q……
806af02c 00 00 00 00 a6 78 1d 00-30 07 00 00 00 00 00 00 …..x..0…….
806af03c 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 …………….
806af04c e8 77 1d 00 d4 77 1d 00-c2 77 1d 00 ae 77 1d 00 .w…w…w…w..
806af05c a2 77 1d 00 8a 77 1d 00-72 77 1d 00 60 77 1d 00 .w…w..rw..`w..
806af06c 52 77 1d 00 f8 77 1d 00-00 00 00 00 9e 72 1d 00 Rw…w…….r..
kd> !db 006AEFFC
# 6aeffc 00 00 00 00 00 00 00 00-00 00 00 00 4a 77 1d 00 …………Jw..




  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值