SlideShare a Scribd company logo
Frame 0x25
Presenter: Dmitry Vostokov
Sponsors
Debugging.TV
• Setting guest OS and virtual machine
for kernel debugging
• Configuring host WinDbg for kernel
debugging
• Examining the guest system
• Simulating a double fault
Topics
© 2013 Software Diagnostics Institute
Virtual Machine Setup
© 2013 Software Diagnostics Institute
Guest OS Setup
© 2013 Software Diagnostics Institute
Host WinDbg Setup
© 2013 Software Diagnostics Institute
Double Fault
© 2013 Software Diagnostics Institute
1: kd> k
Child-SP RetAddr Call Site
fffff980`00a9e968 fffff800`0184d8f3 nt!KeBugCheckEx
fffff980`00a9e970 fffff800`0184c138 nt!KiBugCheckDispatch+0x73
fffff980`00a9eab0 fffff800`0184b754 nt!KiDoubleFaultAbort+0xb8
fffff980`00ce4f80 fffff800`0184d900 nt!KiDebugTrapOrFault+0x14
fffff980`00ce5118 fffff800`0184b871 nt!KiExceptionDispatch
fffff980`00ce5120 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131
[…]
fffff980`00cea400 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131
fffff980`00cea598 fffff800`0184b871 nt!KiExceptionDispatch
fffff980`00cea5a0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131
fffff980`00cea738 fffff800`0184b871 nt!KiExceptionDispatch
fffff980`00cea740 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131
fffff980`00cea8d8 fffff800`0184b871 nt!KiExceptionDispatch
fffff980`00cea8e0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131
fffff980`00ceaa78 fffff800`0184bec3 nt!KiExceptionDispatch
fffff980`00ceaa80 fffff980`13ac910b nt!KiInvalidOpcodeFault+0xc3
fffff980`00ceac10 fffff980`13ac9415 spsys!SPVersion+0x237db
fffff980`00ceac50 fffff980`13ad4e6c spsys!SPVersion+0x23ae5
fffff980`00ceac90 fffff800`01859ca3 spsys!SPVersion+0x2f53c
fffff980`00ceace0 fffff800`01ae1bbb nt!ExpWorkerThread+0x12a
fffff980`00cead50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b
fffff980`00cead80 00000000`00000000 nt!KxStartSystemThread+0x16
!Ad Hardcore Software Diagnostics Training
May, 13, 2013 Philosophy of Software Diagnostics (FREE)
June 17, 2013 Pattern-Oriented Network Trace Analysis (FREE)
July, 19-22, 2013 Accelerated Windows Debugging3
July 24-29, 2013 Accelerated Windows Memory Dump Analysis
2013 The New Old Debugging
© 2013 Software Diagnostics Institute
Now Available for Booking
Debugging.TV
Now on YouTube!
http://www.youtube.com/DebuggingTV

More Related Content

PDF
Bigip exporter
PDF
[OpenStack Day in Korea 2015] Track 1-4 - VDI OpenStack? It Works!!!
PDF
44CON London 2015 - Hunting Asynchronous Vulnerabilities
PPTX
Malware Analysis For The Enterprise
PPTX
Windows kernel debugging workshop in florida
ODP
Linux kernel debugging(ODP format)
PDF
Linux kernel debugging(PDF format)
PDF
Debugging TV Frame 0x05
Bigip exporter
[OpenStack Day in Korea 2015] Track 1-4 - VDI OpenStack? It Works!!!
44CON London 2015 - Hunting Asynchronous Vulnerabilities
Malware Analysis For The Enterprise
Windows kernel debugging workshop in florida
Linux kernel debugging(ODP format)
Linux kernel debugging(PDF format)
Debugging TV Frame 0x05

Similar to Debugging TV Frame 0x25 (20)

PDF
VMworld 2013: ESXi Native Networking Driver Model - Delivering on Simplicity ...
PPTX
Static analysis as means of improving code quality
PDF
2v0 620 Exam-vSphere 6 Foundations
PDF
XPDS14 - Scaling Xen's Aggregate Storage Performance - Felipe Franciosi, Citrix
PDF
Accelerated .NET Memory Dump Analysis training public slides
PPTX
3DConsulting_Presentation
PDF
[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...
PPTX
Top Issues For Microsoft Support For Windows Server
PDF
PhD Thesis Diogo Mónica
PDF
Pharo Virtual Machine: News from the Front
PDF
My old security advisories on HMI/SCADA and industrial software released betw...
PDF
Debugging TV Frame 0x16
KEY
Varnish @ Velocity Ignite
PDF
the grinder testing certification
PDF
Rooting your internals - Exploiting Internal Network Vulns via the Browser Us...
PDF
Qemu device prototyping
PDF
Defcon CTF quals
PDF
SSL/TLS for Mortals (J-Fall)
PDF
NetBSD on Google Compute Engine (en)
PDF
laptop repairing course in delhi
VMworld 2013: ESXi Native Networking Driver Model - Delivering on Simplicity ...
Static analysis as means of improving code quality
2v0 620 Exam-vSphere 6 Foundations
XPDS14 - Scaling Xen's Aggregate Storage Performance - Felipe Franciosi, Citrix
Accelerated .NET Memory Dump Analysis training public slides
3DConsulting_Presentation
[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...
Top Issues For Microsoft Support For Windows Server
PhD Thesis Diogo Mónica
Pharo Virtual Machine: News from the Front
My old security advisories on HMI/SCADA and industrial software released betw...
Debugging TV Frame 0x16
Varnish @ Velocity Ignite
the grinder testing certification
Rooting your internals - Exploiting Internal Network Vulns via the Browser Us...
Qemu device prototyping
Defcon CTF quals
SSL/TLS for Mortals (J-Fall)
NetBSD on Google Compute Engine (en)
laptop repairing course in delhi
Ad

More from Dmitry Vostokov (20)

PDF
Accelerated Windows Debugging 3 training public slides
PDF
Debugging TV Frame 0x1C
PDF
Debugging TV Frame 0x1A
PDF
Debugging TV Frame 0x34
PDF
Debugging TV Frame 0x33
PDF
Debugging TV Frame 0x31
PDF
Debugging TV Frame 0x24
PDF
Debugging TV Frame 0x21
PDF
Debugging TV Frame 0x20
PDF
Debugging TV Frame 0x19
PDF
Debugging TV Frame 0x18
PDF
Debugging TV Frame 0x17
PDF
Debugging TV Frame 0x15
PDF
Debugging TV Frame 0x14
PDF
Debugging TV Frame 0x13
PDF
Debugging TV Frame 0x12
PDF
Debugging TV Frame 0x11
PDF
Debugging TV Frame 0x10
PDF
Debugging TV Frame 0x0F
PDF
Debugging TV Frame 0x0D
Accelerated Windows Debugging 3 training public slides
Debugging TV Frame 0x1C
Debugging TV Frame 0x1A
Debugging TV Frame 0x34
Debugging TV Frame 0x33
Debugging TV Frame 0x31
Debugging TV Frame 0x24
Debugging TV Frame 0x21
Debugging TV Frame 0x20
Debugging TV Frame 0x19
Debugging TV Frame 0x18
Debugging TV Frame 0x17
Debugging TV Frame 0x15
Debugging TV Frame 0x14
Debugging TV Frame 0x13
Debugging TV Frame 0x12
Debugging TV Frame 0x11
Debugging TV Frame 0x10
Debugging TV Frame 0x0F
Debugging TV Frame 0x0D
Ad

Recently uploaded (20)

PDF
System and Network Administration Chapter 2
PDF
Designing Intelligence for the Shop Floor.pdf
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
System and Network Administraation Chapter 3
PPTX
Reimagine Home Health with the Power of Agentic AI​
PPTX
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
PDF
Cost to Outsource Software Development in 2025
PPTX
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Softaken Excel to vCard Converter Software.pdf
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PPTX
history of c programming in notes for students .pptx
PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PPTX
Introduction to Artificial Intelligence
PDF
Digital Strategies for Manufacturing Companies
System and Network Administration Chapter 2
Designing Intelligence for the Shop Floor.pdf
Wondershare Filmora 15 Crack With Activation Key [2025
System and Network Administraation Chapter 3
Reimagine Home Health with the Power of Agentic AI​
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
Cost to Outsource Software Development in 2025
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Odoo Companies in India – Driving Business Transformation.pdf
Softaken Excel to vCard Converter Software.pdf
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
How to Choose the Right IT Partner for Your Business in Malaysia
history of c programming in notes for students .pptx
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Understanding Forklifts - TECH EHS Solution
Upgrade and Innovation Strategies for SAP ERP Customers
Introduction to Artificial Intelligence
Digital Strategies for Manufacturing Companies

Debugging TV Frame 0x25

  • 1. Frame 0x25 Presenter: Dmitry Vostokov Sponsors Debugging.TV
  • 2. • Setting guest OS and virtual machine for kernel debugging • Configuring host WinDbg for kernel debugging • Examining the guest system • Simulating a double fault Topics © 2013 Software Diagnostics Institute
  • 3. Virtual Machine Setup © 2013 Software Diagnostics Institute
  • 4. Guest OS Setup © 2013 Software Diagnostics Institute
  • 5. Host WinDbg Setup © 2013 Software Diagnostics Institute
  • 6. Double Fault © 2013 Software Diagnostics Institute 1: kd> k Child-SP RetAddr Call Site fffff980`00a9e968 fffff800`0184d8f3 nt!KeBugCheckEx fffff980`00a9e970 fffff800`0184c138 nt!KiBugCheckDispatch+0x73 fffff980`00a9eab0 fffff800`0184b754 nt!KiDoubleFaultAbort+0xb8 fffff980`00ce4f80 fffff800`0184d900 nt!KiDebugTrapOrFault+0x14 fffff980`00ce5118 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ce5120 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 […] fffff980`00cea400 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cea598 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cea5a0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cea738 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cea740 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cea8d8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cea8e0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ceaa78 fffff800`0184bec3 nt!KiExceptionDispatch fffff980`00ceaa80 fffff980`13ac910b nt!KiInvalidOpcodeFault+0xc3 fffff980`00ceac10 fffff980`13ac9415 spsys!SPVersion+0x237db fffff980`00ceac50 fffff980`13ad4e6c spsys!SPVersion+0x23ae5 fffff980`00ceac90 fffff800`01859ca3 spsys!SPVersion+0x2f53c fffff980`00ceace0 fffff800`01ae1bbb nt!ExpWorkerThread+0x12a fffff980`00cead50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cead80 00000000`00000000 nt!KxStartSystemThread+0x16
  • 7. !Ad Hardcore Software Diagnostics Training May, 13, 2013 Philosophy of Software Diagnostics (FREE) June 17, 2013 Pattern-Oriented Network Trace Analysis (FREE) July, 19-22, 2013 Accelerated Windows Debugging3 July 24-29, 2013 Accelerated Windows Memory Dump Analysis 2013 The New Old Debugging © 2013 Software Diagnostics Institute Now Available for Booking