Skip to content

Instantly share code, notes, and snippets.

View neitsa's full-sized avatar
🌤️

neitsa

🌤️
View GitHub Profile
@neitsa
neitsa / loader_snaps.txt
Created June 9, 2020 14:41
loader snaps
Microsoft (R) Windows Debugger Version 10.0.18362.1 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
CommandLine: G:\Appdata\CPP\Test\x64\Release\Test.exe
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*g:\Symbols*https://msdl.microsoft.com/download/symbols
Symbol search path is: srv*g:\Symbols*https://msdl.microsoft.com/download/symbols
@neitsa
neitsa / Test.js
Created October 10, 2018 14:24
Symbol Address (windbg + Javascript)
"use strict;"
//
// Test.js
//
// Usage:
//
// .load jsprovider.dll
// .scriptload Test.js
// dx Debugger.State.Scripts.Test.Contents.Test(0x1)
//
@neitsa
neitsa / hex_dump.py
Last active September 11, 2018 09:57
Hexadecimal dump of bytes (python 3)
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
"""
>>> buffer = bytes(range(0x100))
>>> result = hex_dump(buffer, 16)
>>> print(result)
Off 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F ASCII
0000 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................
0010 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................
@neitsa
neitsa / gist:8fb0f02ae084cf3012f4923763b18ebb
Created July 12, 2018 14:11
Windbg j command ; C++ expression evaluation
Microsoft (R) Windows Debugger Version 10.0.16299.15 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
CommandLine: C:\temp\testConsole\ConsoleApplication1\Release\ConsoleApplication1.exe world
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*g:\Symbols*https://msdl.microsoft.com/download/symbols
Symbol search path is: srv*g:\Symbols*https://msdl.microsoft.com/download/symbols