-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
师傅你好,有些问题想请教一下 #1
Comments
ics服务和你不在一个session ,要使用windbg的远程调试,参考微软的文档设置注册表,手动启动ics服务然后接上windbg |
你确定你能attach到ics服务上吗,我记得是附加不上去的,因为session隔离,只能用微软的方法调试svchost。 |
好的,麻烦师傅了,非常感谢 |
你可以在ipnathlp!DhcpProcessMessage断点,在起一台虚拟机去发起DHCP请求看看会不会触发。 |
你还是试一下微软提供的方法吧,我的想法是你这应该没有正常的断下 或者你单步调试,看看为什么没有进入到ipnathlp!DhcpProcessMessage,另外crash表现是不能响应DHCP了好像,记忆有点模糊了 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
在学习师傅的是博客复现漏洞的时候遇到了一些问题,方便请教一下为什么我复现ICS那个漏洞的时候断点断不下来,是我环境配置出问题了吗,不应该是虚拟机直接windows 第二个网卡开启共享,然后设置开启服务吗,然后linux直接用师傅说的poc注释调option53的地方,然后改hlen去触发溢出吗,我似乎无法复现,想请教一下师傅是如何配置环境的
The text was updated successfully, but these errors were encountered: