CREATE and DEBUG a Windows KERNEL device driver!

Pubblicato il: 05 agosto 2024
sul canale di: AshleyPurringTech
9,526
356

Peer into the Windows kernel ("ring 0") using Windows Kernel Debugger as you are introduced to Windows Device Driver Development.

💎✨ Highlights ✨💎

• Write a starter "hello world" Windows Device Driver!
• Use Windows Kernel Debugger to peer into the kernel's depths!
• Setup Windows Driver Kit, Visual Studio 2022, Debugging Tools for Windows.
• Use WinDbg for kernel debugging, "peering into ring 0."
• Intro to Page Faults (PFs).
• Directly see a cause of PAGE_FAULT_IN_NONPAGED_AREA.
• Add bugs to your driver to learn about kernel debugging, Page Faults, more!
• Observe/compare/contrast various page faults.
• Examine AMD/Intel processor page fault stacks/registers.
• Use WinDbg !pte to examine "valid/invalid" addresses.
• Much much more!!!

✨ Tutorial source code ✨
1. git clone https://github.com/AshleyT3/tutorial-...
2. All drivers within ./src/Intro-Windows-Driver-Development-and-Kernel-Debugging-Tutorial/...
kmdrvhw-1-initial-driver
kmdrvhw-2-use-after-free
kmdrvhw-3-multi-bug-driver

✅ Companion video!
Setup Windows KERNEL DEBUGGER on Azure Virtual Machines!
   • Setup Windows KERNEL DEBUGGER on Azure Vir...  

✨ Table of Contents ✨
00:00:00 Start
00:00:43 Intro
00:03:16 Bug check intro
00:04:22 Protection ring
00:05:35 WHQL Testing
00:05:47 All seeing, all powerful
00:07:59 Bug check intro pt2
00:10:11 This video's goals
00:11:21 Windows kernel debugging intro
00:15:34 Doorway to ring 0 pt1
00:16:10 Cautionary words pt1
00:18:05 Windows Driver Kit setup
00:22:45 Create a device driver
00:25:10 Driver hardware id
00:27:28 Build the driver
00:28:12 Provision target intro
00:29:46 Cautionary words pt2
00:31:28 Provision target prep
00:35:58 Provision target
00:38:19 Deploy prep
00:39:42 Deploy driver
00:40:07 Debug driver preface
00:40:26 Doorway to ring 0 pt2
00:42:26 DriverEntry intro
00:43:50 Host debugger setup
00:45:46 Cautionary words pt3
00:50:17 Start debugger
00:50:34 Break not working?
00:51:23 Symbol path setup
00:54:05 Observe frozen target
00:54:38 .reload /f
00:56:14 Debugger interactions recap
00:56:58 !process 0 0 explorer.exe
00:57:26 Interrupt command
00:58:18 'g' command
01:00:35 Deploy driver 2
01:01:20 Driver service reg key
01:02:33 DriverEntry intro pt2
01:03:27 DriverEntry breakpoint
01:03:55 sxe ld
01:05:46 Deploy to Break
01:06:41 Examine callstack
01:07:55 'lm' list modules
01:08:57 'x' examine symbols
01:09:23 'bm' to set breakpoint
01:09:42 BPs in workspace
01:10:53 Break in DriverEntry
01:11:05 Initial source window
01:12:19 F9, bp current line
01:12:32 F10 step
01:12:43 All powerful pt2
01:13:46 Examine callstack 2 (Pnp, Fx)
01:16:50 Bug check intro pt3
01:20:24 Memory management
01:22:45 use-after-free (undetected)
01:23:54 logical vs physical validity
01:28:17 pool tag intro
01:31:32 Pool tag in memory
01:33:39 use-after-free
01:37:37 non-paged pool
01:38:16 !vm 0x20
01:40:36 pool tag pt2
01:41:46 invalid non-paged memory
01:46:11 driver verifier, use-after-free revisited
01:50:11 enable 'verifier'
01:52:53 db poi(ptr)
01:53:31 verifier invalidates
01:54:09 no use-after-free with verifier
01:57:49 disable verifier
01:59:48 induce bug check 0x50
02:02:38 !analyze -v
02:07:27 'g' for blue screen
02:08:15 .reboot
02:09:03 reboot/crash cycle experiment
02:10:01 'rrip' to skip, 'ln' symbolic addr
02:12:01 driver service reg key 2
02:12:34 boot Break
02:14:33 repeating ""boot loop"" bug check
02:18:45 'rrip' skip bad code
02:19:20 all-in-one buggy driver
02:20:53 SEH try/catch block
02:23:31 __debugbreak() intrinsic
02:29:44 Access Violation Page Fault (#PF)
02:34:03 NTSTATUS 0xC0000005 Access Violation
02:35:25 Page Fault in non-paged area
02:37:31 null ptr deref, PF stack. IDT
02:38:30 Interrupt Dispatch Table (IDT)
02:39:15 processor manuals
02:40:34 PF CR2, stack, error code
02:43:35 PF stack, CR2, IDT, example
02:50:45 AV PF #2 with 0x1234
02:53:29 'dps' raw PF stack, CR2==0x1234, PF error code
02:57:50 disable critical loc BPs
03:00:53 driver deploy fail
03:01:39 invalid nonpaged PF handling
03:03:22 invalid NP PF details: dps @rsp, CR2
03:05:40 !pte
03:06:50 PAGE_FAULT_IN_NONPAGED_AREA, !analyze -v pt2
03:08:47 Outro

✏️ errata ✏️
At 2:33:59, "...when the debugger encounters..." should be "...when the processor encounters..."

✨ Related Videos ✨

🎞️ Microsoft MASM assembly, link, WinDbg:
   • Create/Assemble/Link x64 Windows ASM to EX...  

🎞️ dumpbin.exe, link, and the PE Format:
   • dumpbin.exe, link /dump, and the Portable ...  

🎞️ Setup Windows KERNEL DEBUGGER on Azure Virtual Machines!
   • Setup Windows KERNEL DEBUGGER on Azure Vir...  

✨ YouTube Super "Thanks" is active (see above) ✨

✨ Buy Me a Coffee ✨
https://buymeacoffee.com/ashleypurrin...

✨ Ko-fi ✨
https://ko-fi.com/ashleypurringtech

📧 Subscribe to the email list! 📧
https://ashleypurringtech.com/subscribe


In questa pagina del sito puoi guardare il video online CREATE and DEBUG a Windows KERNEL device driver! della durata di ore minuti seconda in buona qualità , che l'utente ha caricato AshleyPurringTech 05 agosto 2024, condividi il link con amici e conoscenti, su youtube questo video è già stato visto 9,526 volte e gli è piaciuto 356 spettatori. Buona visione!