CREATE and DEBUG a Windows KERNEL device driver!

Veröffentlicht am: 05 August 2024
auf dem Kanal: AshleyPurringTech
9,526
356

Peer into the Windows kernel ("ring 0") using Windows Kernel Debugger as you are introduced to Windows Device Driver Development.

💎✨ Highlights ✨💎

• Write a starter "hello world" Windows Device Driver!
• Use Windows Kernel Debugger to peer into the kernel's depths!
• Setup Windows Driver Kit, Visual Studio 2022, Debugging Tools for Windows.
• Use WinDbg for kernel debugging, "peering into ring 0."
• Intro to Page Faults (PFs).
• Directly see a cause of PAGE_FAULT_IN_NONPAGED_AREA.
• Add bugs to your driver to learn about kernel debugging, Page Faults, more!
• Observe/compare/contrast various page faults.
• Examine AMD/Intel processor page fault stacks/registers.
• Use WinDbg !pte to examine "valid/invalid" addresses.
• Much much more!!!

✨ Tutorial source code ✨
1. git clone https://github.com/AshleyT3/tutorial-...
2. All drivers within ./src/Intro-Windows-Driver-Development-and-Kernel-Debugging-Tutorial/...
kmdrvhw-1-initial-driver
kmdrvhw-2-use-after-free
kmdrvhw-3-multi-bug-driver

✅ Companion video!
Setup Windows KERNEL DEBUGGER on Azure Virtual Machines!
   • Setup Windows KERNEL DEBUGGER on Azure Vir...  

✨ Table of Contents ✨
00:00:00 Start
00:00:43 Intro
00:03:16 Bug check intro
00:04:22 Protection ring
00:05:35 WHQL Testing
00:05:47 All seeing, all powerful
00:07:59 Bug check intro pt2
00:10:11 This video's goals
00:11:21 Windows kernel debugging intro
00:15:34 Doorway to ring 0 pt1
00:16:10 Cautionary words pt1
00:18:05 Windows Driver Kit setup
00:22:45 Create a device driver
00:25:10 Driver hardware id
00:27:28 Build the driver
00:28:12 Provision target intro
00:29:46 Cautionary words pt2
00:31:28 Provision target prep
00:35:58 Provision target
00:38:19 Deploy prep
00:39:42 Deploy driver
00:40:07 Debug driver preface
00:40:26 Doorway to ring 0 pt2
00:42:26 DriverEntry intro
00:43:50 Host debugger setup
00:45:46 Cautionary words pt3
00:50:17 Start debugger
00:50:34 Break not working?
00:51:23 Symbol path setup
00:54:05 Observe frozen target
00:54:38 .reload /f
00:56:14 Debugger interactions recap
00:56:58 !process 0 0 explorer.exe
00:57:26 Interrupt command
00:58:18 'g' command
01:00:35 Deploy driver 2
01:01:20 Driver service reg key
01:02:33 DriverEntry intro pt2
01:03:27 DriverEntry breakpoint
01:03:55 sxe ld
01:05:46 Deploy to Break
01:06:41 Examine callstack
01:07:55 'lm' list modules
01:08:57 'x' examine symbols
01:09:23 'bm' to set breakpoint
01:09:42 BPs in workspace
01:10:53 Break in DriverEntry
01:11:05 Initial source window
01:12:19 F9, bp current line
01:12:32 F10 step
01:12:43 All powerful pt2
01:13:46 Examine callstack 2 (Pnp, Fx)
01:16:50 Bug check intro pt3
01:20:24 Memory management
01:22:45 use-after-free (undetected)
01:23:54 logical vs physical validity
01:28:17 pool tag intro
01:31:32 Pool tag in memory
01:33:39 use-after-free
01:37:37 non-paged pool
01:38:16 !vm 0x20
01:40:36 pool tag pt2
01:41:46 invalid non-paged memory
01:46:11 driver verifier, use-after-free revisited
01:50:11 enable 'verifier'
01:52:53 db poi(ptr)
01:53:31 verifier invalidates
01:54:09 no use-after-free with verifier
01:57:49 disable verifier
01:59:48 induce bug check 0x50
02:02:38 !analyze -v
02:07:27 'g' for blue screen
02:08:15 .reboot
02:09:03 reboot/crash cycle experiment
02:10:01 'rrip' to skip, 'ln' symbolic addr
02:12:01 driver service reg key 2
02:12:34 boot Break
02:14:33 repeating ""boot loop"" bug check
02:18:45 'rrip' skip bad code
02:19:20 all-in-one buggy driver
02:20:53 SEH try/catch block
02:23:31 __debugbreak() intrinsic
02:29:44 Access Violation Page Fault (#PF)
02:34:03 NTSTATUS 0xC0000005 Access Violation
02:35:25 Page Fault in non-paged area
02:37:31 null ptr deref, PF stack. IDT
02:38:30 Interrupt Dispatch Table (IDT)
02:39:15 processor manuals
02:40:34 PF CR2, stack, error code
02:43:35 PF stack, CR2, IDT, example
02:50:45 AV PF #2 with 0x1234
02:53:29 'dps' raw PF stack, CR2==0x1234, PF error code
02:57:50 disable critical loc BPs
03:00:53 driver deploy fail
03:01:39 invalid nonpaged PF handling
03:03:22 invalid NP PF details: dps @rsp, CR2
03:05:40 !pte
03:06:50 PAGE_FAULT_IN_NONPAGED_AREA, !analyze -v pt2
03:08:47 Outro

✏️ errata ✏️
At 2:33:59, "...when the debugger encounters..." should be "...when the processor encounters..."

✨ Related Videos ✨

🎞️ Microsoft MASM assembly, link, WinDbg:
   • Create/Assemble/Link x64 Windows ASM to EX...  

🎞️ dumpbin.exe, link, and the PE Format:
   • dumpbin.exe, link /dump, and the Portable ...  

🎞️ Setup Windows KERNEL DEBUGGER on Azure Virtual Machines!
   • Setup Windows KERNEL DEBUGGER on Azure Vir...  

✨ YouTube Super "Thanks" is active (see above) ✨

✨ Buy Me a Coffee ✨
https://buymeacoffee.com/ashleypurrin...

✨ Ko-fi ✨
https://ko-fi.com/ashleypurringtech

📧 Subscribe to the email list! 📧
https://ashleypurringtech.com/subscribe


Auf dieser Seite können Sie das Online-Video CREATE and DEBUG a Windows KERNEL device driver! mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer AshleyPurringTech 05 August 2024 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 9,526 Mal angesehen und es wurde von 356 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!