WinDbg Patching Arguments at Runtime
# WinDbg Patching Arguments at Runtime When a function is about to receive a bad argument (e.g. `NULL` filename passed to `__loaddll`), you can fix the pointer value on [[Stack F…
16 published notes
# WinDbg Patching Arguments at Runtime When a function is about to receive a bad argument (e.g. `NULL` filename passed to `__loaddll`), you can fix the pointer value on [[Stack F…
In a [[Debugger attach and ASLR rebasing pitfalls|debugger]], **suspend** means pausing the target process, not killing it. The OS scheduler simply stops giving the process CPU ti…
In 32-bit x86 code compiled with a stack-based calling convention [[x86 Calling Conventions: cdecl vs stdcall]] (`cdecl` or `stdcall`), arguments are accessed as positive offsets …
# Function Prologue Decomposition Methodology When you open an x86 function, do not read line-by-line. Read the **prologue as one block** and answer these five questions before a…
# Address Types in Reverse Engineering When analyzing a binary you will see several different address spaces. The same byte can be described by each of them depending on which to…
# x86 `rand()` Calling Convention and Return Value In x86 assembly, the C standard library function `rand()` is called like any other function: ```asm call _rand ``` ## Signatu…
# WinDbg Stack Inspection Commands Use these commands to inspect values that have been pushed onto the stack, especially right before a function call. ## Core command ```windbg…
# Function Thunks and Stubs A **thunk** (also called a *stub* or *trampoline*) is a tiny function whose only purpose is to forward execution to another function. It does little o…
# WinDbg Hardware Breakpoints (`ba`) `ba` sets a **hardware breakpoint** that triggers on **memory access** rather than execution. ## `ba` vs `bp` | Command | Type | Fires when…
# Winsock fd_set Structure (0x104 Signature) On 32-bit Windows, the `fd_set` structure from Winsock (`winsock2.h`) is exactly 260 bytes, or `0x104`. That makes `0x104` a useful s…
# WinDbg Commands for Live Binary Analysis Essential commands used to inspect buffers, catch encryption, and trace function behavior in WinDbg during disassembly/reverse engineer…
# x86 Calling Conventions: cdecl vs stdcall A **calling convention** is the contract between a caller and a callee that answers two questions: 1. How are arguments passed? 2. Wh…
# Debugger attach and ASLR rebasing pitfalls When attaching a debugger to a live Windows process, the static disassembly addresses shown in tools like [[Binary Ninja]] are usuall…
# Parsing Binary Formats with Construct `construct` is a Python library that lets you describe binary file layouts as data structures instead of writing manual `struct.unpack` ca…
# Python Syntax Recall and Fluency for Security Work Many learners struggle with Python syntax not because they are "bad at memorizing," but because they are trying to memorize *…
# Python Essentials for Security Scripting A review of core Python syntax, data structures, and file I/O with an emphasis on writing clean, maintainable security scripts for pent…