Debugger Suspend Does Not Kill the Process
In a [[Debugger attach and ASLR rebasing pitfalls|debugger]], **suspend** means pausing the target process, not killing it. The OS scheduler simply stops giving the process CPU ti…
4 published notes
In a [[Debugger attach and ASLR rebasing pitfalls|debugger]], **suspend** means pausing the target process, not killing it. The OS scheduler simply stops giving the process CPU ti…
In 32-bit x86 code compiled with a stack-based calling convention [[x86 Calling Conventions: cdecl vs stdcall]] (`cdecl` or `stdcall`), arguments are accessed as positive offsets …
# Function Thunks and Stubs A **thunk** (also called a *stub* or *trampoline*) is a tiny function whose only purpose is to forward execution to another function. It does little o…
# Debugger attach and ASLR rebasing pitfalls When attaching a debugger to a live Windows process, the static disassembly addresses shown in tools like [[Binary Ninja]] are usuall…