<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Matthieu Suiche&#039;s blog &#187; Matthieu Suiche</title>
	<atom:link href="http://www.msuiche.net/author/admin/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.msuiche.net</link>
	<description>Happiness only real when shared.</description>
	<lastBuildDate>Sat, 24 Apr 2010 09:10:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Trainings in Paris and Las Vegas</title>
		<link>http://www.msuiche.net/2010/04/24/trainings-in-paris-and-las-vegas/</link>
		<comments>http://www.msuiche.net/2010/04/24/trainings-in-paris-and-las-vegas/#comments</comments>
		<pubDate>Sat, 24 Apr 2010 09:10:12 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=447</guid>
		<description><![CDATA[If you want to register to a Advanced Windows Physical Memory Analysis  to mastering Windd click HERE or HERE

]]></description>
			<content:encoded><![CDATA[<p>If you want to register to a <b><i>Advanced Windows Physical Memory Analysis</i></b>  to mastering Windd click <font size=4><a href="http://moonsols.com/blog/10-trainings">HERE</a></font> or <font size=4><a href="http://moonsols.com/blog/10-trainings">HERE</a></font></p>
<p><center><a href="http://moonsols.com/blog/10-trainings"><img src="http://www.moonsols.com/images/stories/logo_2.png" width="400" height="100"/></a></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2010/04/24/trainings-in-paris-and-las-vegas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New direction</title>
		<link>http://www.msuiche.net/2010/04/05/new-direction/</link>
		<comments>http://www.msuiche.net/2010/04/05/new-direction/#comments</comments>
		<pubDate>Sun, 04 Apr 2010 23:38:14 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=445</guid>
		<description><![CDATA[As you have seen, I didn&#8217;t update this blog since a while &#8211; There is a reason. I started my own company called &#8220;MoonSols&#8221;.
I released my first product called &#8220;MoonSols Windows Memory Toolkit&#8221;. And slides of my last talks at JSSI (Paris, France) and CanSecWest (Vancouver, Canada).
By there way, there is also a twitter feed [...]]]></description>
			<content:encoded><![CDATA[<p>As you have seen, I didn&#8217;t update this blog since a while &#8211; There is a reason. I started my own company called &#8220;MoonSols&#8221;.</p>
<p>I released my first product called <a href="http://moonsols.com/blog/2-blog/9-moonsols-windows-memory-toolkit">&#8220;MoonSols Windows Memory Toolkit&#8221;</a>. And slides of my <a href="http://moonsols.com/blog/2-blog/8-mac-os-x-physical-memory-analysis">last talks</a> at JSSI (Paris, France) and CanSecWest (Vancouver, Canada).</p>
<p>By there way, there is also a twitter feed : <a href="http://www.twitter.com/MoonSols">@MoonSols</a></p>
<p><img src="http://www.moonsols.com/images/stories/logo_2.png" border="0" height="40" width="160"/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2010/04/05/new-direction/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BlackHat DC 2010 &#8211; Mac OS X Physical Memory Analysis</title>
		<link>http://www.msuiche.net/2010/02/05/blackhat-dc-2010-mac-os-x-physical-memory-analysis/</link>
		<comments>http://www.msuiche.net/2010/02/05/blackhat-dc-2010-mac-os-x-physical-memory-analysis/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 13:03:06 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=441</guid>
		<description><![CDATA[Washington D.C. &#8211; BlackHat D.C. 2010 Edition is now over. For people who attended or missed the talk, slides are now online. [slides] [more]
]]></description>
			<content:encoded><![CDATA[<p>Washington D.C. &#8211; BlackHat D.C. 2010 Edition is now over. For people who attended or missed the talk, slides are now online. <a href="http://www.msuiche.net/con/BHDC2010_MacOSX_PhysicalMemory.pdf">[slides]</a> <a href="http://blackhat.com/html/bh-dc-10/bh-dc-10-archives.html">[more]</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2010/02/05/blackhat-dc-2010-mac-os-x-physical-memory-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MSDN &#8211; Matthieu Suiche Developer Network .. and Merry xmas!</title>
		<link>http://www.msuiche.net/2009/12/24/msdn-matthieu-suiche-developer-network-and-merry-xmas/</link>
		<comments>http://www.msuiche.net/2009/12/24/msdn-matthieu-suiche-developer-network-and-merry-xmas/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 11:36:26 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=416</guid>
		<description><![CDATA[Here is my christmas gift for people who reads this blog. If you are looking for structures/types/enums definition which are not necessary in the Official MSDN just refer to the alternative MSDN at the following address: MSDN &#8211; Matthieu Suiche Developer Network.
You might have seen this project earlier if you are on Twitter :-)
Structures and [...]]]></description>
			<content:encoded><![CDATA[<p>Here is my christmas gift for people who reads this blog. If you are looking for structures/types/enums definition which are not necessary in the Official MSDN just refer to the alternative MSDN at the following address: <a href="http://msdn.msuiche.net">MSDN &#8211; Matthieu Suiche Developer Network</a>.<br />
You might have seen this project earlier if you are on Twitter :-)</p>
<p>Structures and enums definition comes from public PDB files <a href="http://www.microsoft.com/whdc/devtools/debugging/symbolpkg.mspx#f">provided by Microsoft</a>.</p>
<p>This web interface provides offsets, names, and links to corresponding structures/fields of Windows Kernel. Supported versions are, at the moment, Windows 7 RTM (both x64 and x86 architectures), Windows Vista SP2 (both x64 and x86 architectures) and Windows XP SP2 (x86).</p>
<p>Here is a sample for <a href="http://msdn.msuiche.net/win7rtm_x86/KUSER_SHARED_DATA.php">KUSER_SHARED_DATA of Windows 7 RTM x86</a>, and another one for <a href="http://msdn.msuiche.net/winvistasp2_x64/POOL_HEADER.php">POOL_HEADER of Windows Vista SP2 x64</a>.</p>
<p>Unlike Nirsoft website, I also provide offsets and a wider choice of Operating Systems.</p>
<p>Merry Xmas!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2009/12/24/msdn-matthieu-suiche-developer-network-and-merry-xmas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SmInfo: Inside Store Manager of Windows 7 and Windows 2008 R2 with Windd.</title>
		<link>http://www.msuiche.net/2009/12/06/sminfo-inside-store-manager-of-windows-7-and-windows-2008-r2-with-windd/</link>
		<comments>http://www.msuiche.net/2009/12/06/sminfo-inside-store-manager-of-windows-7-and-windows-2008-r2-with-windd/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 01:01:22 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=392</guid>
		<description><![CDATA[Store Manager (Sm*) is pretty new under Windows 7/Windows 2008 R2 kernel, this is a new management system to deal with both virtual and physical stores.
ReadyBoost (cache/files/logs, &#8230;) is one exemple.
Even through ReadyBoost had been firstly introduced into Windows Vista and Windows 2008 (Refer to Mark Russinovich writeup about Windows Vista Kernel for more information [...]]]></description>
			<content:encoded><![CDATA[<p>Store Manager (<a href="http://www.msuiche.net/2009/03/31/demystifying-new-windows-7-system-information-classes/">Sm</a>*) is pretty new under Windows 7/Windows 2008 R2 kernel, this is a new management system to deal with both virtual and physical stores.<br />
ReadyBoost (cache/files/logs, &#8230;) is one exemple.<br />
Even through ReadyBoost had been firstly introduced into Windows Vista and Windows 2008 (Refer to Mark Russinovich writeup about <a href="http://technet.microsoft.com/en-us/magazine/2007.03.vistakernel.aspx?pr=blog">Windows Vista Kernel</a> for more information about ReadyBoost), Microsoft kernel developpers implemented ReadyBoost feature inside the Store Manager to make it more efficient.</p>
<p>In this blogpost, I am going to introduce a new WinDbg Extension called &#8220;<a href="http://www.msuiche.net/countcount/click.php?id=11">sminfo</a>&#8221; to retrieve information about the Store Manager from a Microsoft crash dump generated with <a href="http://windd.msuiche.net">Win[32/64]dd</a> on a Windows 7 32-bits computer. (Thanks to Mark Wodrich for the help to use DML ;-))</p>
<p>Materials used are available here:</p>
<ul>
<li>Windd utility from <a href="http://windd.msuiche.net">this link</a>. Windd works on x86 and x64 architecture from Windows XP to Windows 7 (for the crash dump feature).</li>
<li>
</li>
<li>SmInfo Debugger Extension from <a href="http://www.msuiche.net/countcount/click.php?id=11">this link</a>. The following extension works only on x86 of Windows 7 and Windows 2008 R2 with Microsoft crash dumps and (local or remote) Kernel debugging.</li>
</ul>
<p><strong>Step 1#</strong> Plug a USB Key and tell to Windows that you want to use this USB drive as a ReadyBoost extension.<br />
<strong>Step 2#</strong> Dump the physical memory into a Microsoft crashdump using the following command: &#8220;win32dd.exe /d /f readyboost.dmp&#8221;.<br />
<center><a href="http://msuiche.net/tools/sminfo/windd.png"><img src="http://msuiche.net/tools/sminfo/windd.png" alt="windd" width="70%" height="70%" /></a><br />
<strong>Figure 1</strong> &#8211; Windd [Click to enlarge]</center></p>
<p><strong>Step 3#</strong> Open WinDbg, load crashdump, configure symbols, load <i>sminfo</i> extension.<br />
<center><a href="http://msuiche.net/tools/sminfo/loading.png"><img src="http://msuiche.net/tools/sminfo/loading.png" alt="windd" width="70%" height="70%"/></a><br />
<strong>Figure 2</strong> &#8211; Windbg + SmInfo [Click to enlarge]</center></p>
<blockquote><p>0: kd> !sminfo<br />
Store Manager (ReadyBoost) Debugger Extension &#8211; v0.1<br />
Copyright (c) 2009, Matthieu Suiche http://www.msuiche.net<br />
Windows 7 x86 and Windows 2008 R2 x86 ONLY</p>
<p>   !sminfo CACHE              &#8211; Enumerate caches and display corresponding information.<br />
   !sminfo LOG [cacheindex] &#8211; Display entries from cache.</p></blockquote>
<p><strong>Step 4#</strong> Have fun with !sminfo commands!<br />
<center><a href="http://msuiche.net/tools/sminfo/smcache.png"><img src="http://msuiche.net/tools/sminfo/smcache.png" alt="windd" width="70%" height="70%"/></a><br />
<strong>Figure 3</strong> &#8211; !sminfo CACHE [Click to enlarge]</center></p>
<p><center><a href="http://msuiche.net/tools/sminfo/smlog.png"><img src="http://msuiche.net/tools/sminfo/smlog.png" alt="windd" width="70%" height="70%"/></a><br />
<strong>Figure 4</strong> &#8211; !sminfo LOG [Click to enlarge]</center></p>
<p><center><a href="http://msuiche.net/tools/sminfo/proc.png"><img src="http://msuiche.net/tools/sminfo/proc.png" alt="windd" width="70%" height="70%"/></a><br />
<strong>Figure 5</strong> &#8211; !dml_proc [Click to enlarge]</center></p>
<p>As you can see, we can retrieve various information such as the file name, its size, cached pages and application list. So basically with this debugger extension you can have access to ReadyBoost log which can be helpful to troubleshoot your system.</p>
<p><strong>Additional ressources</strong><br />
<a href="http://tinyurl.com/ydl64d8">Developping Debugger Extensions &#8211; PDC Conference</a><br />
<a href="http://mcfunley.com/242/the-debugger-extension-part-1-what-is-a-dbgeng-extension">The debugger extension &#8211; Several parts</a><br />
<a href="http://www.alex-ionescu.com/?p=51">MemInfo: Peer Inside Memory Manager Behavior on Windows Vista and Server 2008</a></p>
<p>PS. In February 2010, I will be in Washington D.C. to talk about Mac OS X Kernel internals and physical memory analysis at BlackHat. Description is available on <a href="http://blackhat.com/html/dc2010/dc2010-briefings.html#Suiche">BH website</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2009/12/06/sminfo-inside-store-manager-of-windows-7-and-windows-2008-r2-with-windd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reply to HBGary &#8212; and personal notes.</title>
		<link>http://www.msuiche.net/2009/11/16/reply-to-hbgary-and-personal-notes/</link>
		<comments>http://www.msuiche.net/2009/11/16/reply-to-hbgary-and-personal-notes/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 02:00:54 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Debugging]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[windd]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=369</guid>
		<description><![CDATA[One HBGary developper wrote a blogpost about windd entitled &#8220;Windd &#8211; Almost there, but not quite&#8230;&#8220;.
HBGary says *they* but I would like to say to readers that windd is a project that I developped and maintain alone, on my spare time.
More and more people are using windd so it looks I have to explain some [...]]]></description>
			<content:encoded><![CDATA[<p>One HBGary developper wrote a blogpost about windd entitled &#8220;<a href="https://www.hbgary.com/community/shawnblog/">Windd &#8211; Almost there, but not quite&#8230;</a>&#8220;.<br />
HBGary says *they* but I would like to say to readers that windd is a project that I developped and maintain alone, on my spare time.</p>
<p>More and more people are using windd so it looks I have to explain some things about the behavior of Windows Memory Manager and windd itself. Reading HBGary blogpost really made me feel enthusiastic because I recently complained about the lack of feedback on windd which is really frustrating when you lead a free project.</p>
<p>As you probably know early version of windd were open-source, but mainly because of the lack of feedback windd is no more open-source but still free. As far I have seen, <a href="http://www.reactos.org/pipermail/ros-dev/2009-November/012340.html">open-source doesn&#8217;t mean people understand what you wrote or read the code</a>, it is more like a philosophical aspect like &#8220;We have access to the source&#8221;. Anyway, people are still free to send me an e-mail, at matt/msuiche/net if they have questions about the internal behavior of Windd, to insult me or just to thank me.</p>
<p>Back to HBGary blogpost, we can read :</p>
<ul>
<li>Is windd acquiring all of the available physical memory on the system?</li>
<li>Would a “raw format” image dump of a 64-bit vista machine load properly into HBGary’s Responder?</li>
<li>Should windd memory images that contain greater than 4GB of ram be considered admissible in court?</li>
<li>Was windd really the first tool to support physical memory acquisition on Windows 7? (as claimed by the author)</li>
</ul>
<p>Author replied &#8220;No&#8221; to all questions above.</p>
<p>In this blogpost, I am going to provide details about the bug for both technical and no technical people by explain how windd works. The main problem with HBGary article is that they mix accessible physical memory and accessible physical memory address spaces. So I assume most people do not even know the difference between these two *things*.</p>
<p>In July 2008, Mark Russinovich wrote a very well explained article about Windows Physical Memory Manager entitled &#8220;<a href="http://blogs.technet.com/markrussinovich/archive/2008/07/21/3092070.aspx">Pushing the Limits of Windows: Physical Memory</a>&#8220;. In this article Mark also used a tool written by Alex Ionescu (co-author of Windows Internals 5th) called &#8220;meminfo&#8221; to retrieve information related to Windows PFN Database.</p>
<p>In this article Mark explains what physical memory, physical address space and PFN Database are.<br />
For lazy readers here is a short summary.</p>
<p><center><img src="http://blogs.technet.com/blogfiles/markrussinovich/WindowsLiveWriter/PushingtheLimitsofWindowsPhysicalMemory_878B/image_thumb_4.png"/></center><br />
Figure above is the <strong>physical address space</strong>.<br />
<strong>Red</strong> blocks are <strong>devices address space</strong>, <strong>blue</strong> blocks are <strong>physical memory</strong> and the &#8220;Inaccessible RAM&#8221; (only by Windows) is a reserved space in the physical memory for the Operating System to proceed to the translation from Virtual to Physical addresses.<br />
Joanna Rutkowska paper entitled &#8220;<a href="http://www.invisiblethings.org/papers/cheating-hardware-memory-acquisition-updated.ppt">Defeating Hardware Based RAM Acquisition</a>&#8221; is a good reading if you want to know more about &#8220;Red blocks&#8221;.</p>
<p><img src="http://blogs.technet.com/blogfiles/markrussinovich/WindowsLiveWriter/PushingtheLimitsofWindowsPhysicalMemory_878B/image_thumb_9.png"/><br />
Figure above comes from meminfo tool which display Memory Manager physical memory blocks. These entries describe how the physical memory is &#8220;splitted&#8221; in the physical address space which interpreted by the CPU. For the remind, DMA Access provides access to <strong>physical memory</strong> and not to the <strong>physical address space</strong>.</p>
<p>We firstly notice the highest physical page is 0&#215;120000 (1179648) which correspond to <strong>size of the physical address space</strong> and NOT to the <strong>size of physical memory</strong>.<br />
Secondly we notice physical addresses are above 4GB even if the machine has only 4GB installed. To retrieve the size of installed/detected physical memory we have to add the size of each block as follows:<br />
(0&#215;9F000 &#8211; 0&#215;1000) + (0xDFE6D000 &#8211; 0&#215;100000) + (0&#215;120000000 &#8211; 0&#215;100002000) = 0xFFE09000 (~4GB)</p>
<p>#1 Bug HBGary is talking about only concerns the RAW memory dump generation with windd (v1.3.0.x &#60;= Version &#60; v1.3.0.20091113 (fixed version)).<br />
The bug was the following: Windd was reading blue blocks and wrote them directly in a raw dump file like the DMA-way, then it means red-blocks were missing. Impact was the PFN database was invalid which means Virtual to Physical address translation was impossible. BUT windd <strong>DOES</strong>  acquiere all available physical memory. Present version of Windd produces a &#8220;CPU-like&#8221; memory dump (physical memory address space) and fills red blocks with null pages.</p>
<p>#2 Second question was about HBGary’s Responder. I don&#8217;t know this product and I never used it. But it would mean HBGary does not support DMA-style memory dump.</p>
<p>#3 For the third question, please refer to #1 and #2.</p>
<p>#4 Regarding the last question about the fact that I claimed that windd was the first tool support physical memory acquisition I do not remember saying that. I just remember I claimed several times windd was a great tool because it can produce <strong>Microsoft crash dumps</strong> which has great advantages mainly because of Windbg. Then, windd also aims at being used by troubleshooters and/or kernel developpers and not only by forensics investigators.</p>
<p>For instance in your blogpost I can read &#8220;<i>NOTE: HBGary’s Responder does not yet fully support the automatic analysis of Windows 7 which is why HBGary had elected to not publicly advertise Windows 7 acquisition support</i>&#8221; &#8212; The difference between windd and average memory acquisition tools is this point: This problem does not exist with WinDbg. Windbg supports Microsoft Crash Dump since Microsoft started to work on Windows.<br />
Analysis is very important, if someone produces a dump and is unable to analyse it this is more or less like if someone would say &#8220;I have a new car but I do not know how to drive it&#8221;. </p>
<p>Thanks again to HBGary for helping me to improve windd utility and I hope they like the new version.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2009/11/16/reply-to-hbgary-and-personal-notes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BlackHat Webcast &#8211; New Frontiers In Forensics [Slides]</title>
		<link>http://www.msuiche.net/2009/10/30/blackhat-webcast-new-frontiers-in-forensics-slides/</link>
		<comments>http://www.msuiche.net/2009/10/30/blackhat-webcast-new-frontiers-in-forensics-slides/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 08:40:53 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=354</guid>
		<description><![CDATA[First, I would like to thanks people who attended to this Webcast and to BlackHat folks for inviting me and making this webcast great!
If you missed it, slides are now available at the following link: New Frontiers In Forensics [PDF]
People can access to Win[32&#124;64]DD page here: http://windd.msuiche.net.
And media materials should be available on BH Website.
]]></description>
			<content:encoded><![CDATA[<p>First, I would like to thanks people who attended to this Webcast and to BlackHat folks for inviting me and making this webcast great!</p>
<p>If you missed it, slides are now available at the following link: <a href="http://www.msuiche.net/con/BlackHat_Webcast_New_Frontiers_in_Forensics.pdf">New Frontiers In Forensics [PDF]</a><br />
People can access to Win[32|64]DD page here: <a href="http://windd.msuiche.net">http://windd.msuiche.net</a>.<br />
And media materials should be available on <a href="http://blackhat.com/html/webcast/webcast-home.html">BH Website</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2009/10/30/blackhat-webcast-new-frontiers-in-forensics-slides/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windd 1.3 Final! (x86 and x64)</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/</link>
		<comments>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/#comments</comments>
		<pubDate>Sun, 11 Oct 2009 11:42:06 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=335</guid>
		<description><![CDATA[EDIT: 1.3.20091113 version contains a fix for incorrect size bug and raw memory dump.
EDIT: 1.3.20091024 version contains a fix for networking feature under Vista and Later.

Download windd 1.3

Win32dd and Win64dd are finally mature enough to be released which is a very good news.
First, I would like to thanks Nicolas Ruff, Andreas Schuster, Scott Noone from [...]]]></description>
			<content:encoded><![CDATA[<p><strong>EDIT: </strong><em>1.3.20091113 version contains a fix for incorrect size bug and raw memory dump.</em><br />
<strong>EDIT: </strong><em>1.3.20091024 version contains a fix for networking feature under Vista and Later.</em></p>
<p><center><br />
<h1><strong><a href="http://www.msuiche.net/countcount/click.php?id=10">Download windd 1.3</a></strong></h1>
<p></center></p>
<p>Win32dd and Win64dd are finally mature enough to be released which is a very good news.<br />
First, I would like to thanks <a href="http://news0ft.blogspot.com/">Nicolas Ruff</a>, <a href="http://computer.forensikblog.de/en/">Andreas Schuster</a>, <a href="http://www.osronline.com/">Scott Noone</a> from OSR Online, <a href="http://twitter.com/robtlee">Rob T. Lee</a>, <a href="http://g-laurent.blogspot.com">Laurent Gaffie</a>, <a href="http://www.marchetto.at/">Jimmy Marchetto</a> and Sol_Ksacap for providing either assistance, feedbacks and/or beta-testing for this version.</p>
<p><strong>Compability List:</strong><br />
<em>Raw memory dump:</em></p>
<ul>
<li>    Windows 2000 (32-Bits)</li>
<li>    Windows XP (32-Bits and 64-Bits)</li>
<li>    Windows 2003 (32-Bits and 64-Bits)</li>
<li>    Windows Vista (32-Bits and 64-Bits)</li>
<li>    Windows 2008 (32-Bits and 64-Bits)</li>
<li>    Windows 7 (32-Bits and 64-Bits)</li>
<li>    Windows 2008 R2 (32-Bits and 64-Bits)</li>
</ul>
<p><em>Microsoft crash dump:</em></p>
<ul>
<li>    Windows XP (32-Bits and 64-Bits)</li>
<li>    Windows 2003 (32-Bits and 64-Bits)</li>
<li>    Windows Vista (32-Bits and 64-Bits)</li>
<li>    Windows 2008 (32-Bits and 64-Bits)</li>
<li>    Windows 7 (32-Bits and 64-Bits)</li>
<li>    Windows 2008 R2 (32-Bits and 64-Bits)</li>
</ul>
<p><strong>Features:</strong></p>
<ul>
<li>    Raw dump generation</li>
<li>    Standalone Microsoft crash dump generation</li>
<li>    Network support (client + server)</li>
<li>    SMB path support</li>
<li>    MD5, SHA-1 and SHA-256 hash support</li>
<li>    Support 3 mapping methods for both full crash dump and raw memory dump generation</li>
<li>    Support 3 content rules</li>
<li>    Fast</li>
<li>    32-bits and 64-bits support</li>
<li>    Can hibernate the system.</li>
<li>    Can generate a Blue Screen of the Death</li>
<li>    Support of machine with more than 4GB of RAM.</li>
</ul>
<p>Microsoft Windows has an internal limitation which does not allow to generate a Microsoft Full Crash dump if the local machine has more than 2GB of physical memory. Of course, this limitation does not affect windd but it was funny and a good surprise to see Windbg correctly works with 8GB Microsoft crash dump (successfuly tested by <a href="http://twitter.com/xcessiv/status/4769084891">Jimmy</a>).<br />
<center><br />
<a href="http://pangowings.msuiche.net/imgs/win64dd_8GB.png"><br />
<img src="http://pangowings.msuiche.net/imgs/win64dd_8GB.png" alt="dd" width="334" height="372"/><br />
</a><br />
</center></p>
<p><strong>Links:</strong><br />
<a href="http://pangowings.msuiche.net/">windd main page</a><br />
<a href="http://www.msuiche.net/countcount/click.php?id=10">Download windd 1.3</a></p>
<p><strong>How to rule Windbg?</strong><br />
<a href="http://www.codeproject.com/KB/debug/cdbntsd4.aspx">Debug Tutorial Part 4: Writing WINDBG Extensions</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>R.I.P. Xpress &#8211; Welcome TLZ</title>
		<link>http://www.msuiche.net/2009/10/08/r-i-p-xpress-welcome-tlz/</link>
		<comments>http://www.msuiche.net/2009/10/08/r-i-p-xpress-welcome-tlz/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 17:25:12 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=324</guid>
		<description><![CDATA[I was reading an article about Windows 8 and 9 (which should support IA-128 architecture) when I highlighted:
Researched new algorithms and programming methods to build Hibernate/Resume Integration API that can integrate and utilize the new TLZ file compression engine for the Hibernate/Resume component of new Windows 8 Operating System.
    Using C and [...]]]></description>
			<content:encoded><![CDATA[<p>I was reading <a href="http://arstechnica.com/microsoft/news/2009/10/microsoft-mulling-128-bit-versions-of-windows-8-windows-9.ars">an article about Windows 8 and 9</a> (which should support IA-128 architecture) when I highlighted:</p>
<blockquote><p>Researched new algorithms and programming methods to build Hibernate/Resume Integration API that can integrate and utilize the new TLZ file compression engine for the Hibernate/Resume component of new Windows 8 Operating System.</p>
<p>    Using C and C++ programming languages <em>in SourceInsight</em>, developed a 100% functional C wrapper for C++ functions and the Hibernate/Resume Integration API, which will be used in Windows 8 replacing Windows Vista&#8217;s Xpress compression engine.
</p></blockquote>
<p>Apparently and according to his <a href="http://machine-learning.eggsprout.com/profile/266/">resume</a> the author, Bo Qin, is a student at University of Washington. That is cool to see that some academics are working on cool projects (while some people are wasting time to find a way to write an exploit which will be used by script-kiddies or stupid consultants and while media are claiming white-hats are challenging Microsoft).</p>
<p>Anyway, Xpress compression algorithm, introduced in Windows XP and still used in Windows 7 and actually used for <a href="http://sandman.msuiche.net">Windows Hibernation</a>, Hyper-V, Windows Mobile, SMB protocol etc., should be replaced by TLZ algorithm that should be introduced in Windows 8.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2009/10/08/r-i-p-xpress-welcome-tlz/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Call for Beta-Testers :: windd utility RC2 (32-bits &amp; 64-bits)</title>
		<link>http://www.msuiche.net/2009/09/09/call-for-beta-testers-windd-utility-rc2-32-bits-64-bits/</link>
		<comments>http://www.msuiche.net/2009/09/09/call-for-beta-testers-windd-utility-rc2-32-bits-64-bits/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 20:25:01 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=304</guid>
		<description><![CDATA[Finally, I recently managed to find some time to updated win32dd, now called windd and part of a project codenamed &#8220;Pangowings *&#8221; (inspired by pangolin mammal). windd supports both 32-bits and 64-bits version (not Itanium, but x64-based) version of Windows from Windows XP to Windows 7.
All executables (including drivers) are digitally signed. And I suggest [...]]]></description>
			<content:encoded><![CDATA[<p>Finally, I recently managed to find some time to updated win32dd, now called windd and part of a project codenamed &#8220;<em>Pangowings *</em>&#8221; (inspired by pangolin mammal). windd supports both 32-bits and 64-bits version (not Itanium, but x64-based) version of Windows from Windows XP to Windows 7.<br />
All executables (including drivers) are digitally signed. And I suggest to people to always check this.</p>
<p>Would be nice to have people with more than 4GB to test it.</p>
<p>Here is a summary of the changelog:<br />
<strong>- 2008-09-09</strong></p>
<ul>
<li><strong>1.3. Major update</strong></li>
<li>- Network support (both client and server in one executable).</li>
<li>- 64-bits support.</li>
<li>- Very fast.</li>
<li>- MD5, SHA-1 and SHA-256 hash support.</li>
<li>- Support 3 mapping methods for both full crash dump and raw memory dump generation.</li>
<li>- Can generate BSOD.</li>
<li>- Can hibernate the system.</li>
<li>- Microsoft crash dump fully compatible with Windbg</li>
</ul>
<p>So, if you want to test it.:<br />
<em>Links</em><br />
<a href="http://pangowings.msuiche.net/">windd main page</a><br />
<a href="http://www.msuiche.net/countcount/click.php?id=10">Direct link to windd RC2</a></p>
<p><em>Randoms:</em><br />
Here is also an interesting reading my friend <a href="http://danstoncloud.com/blogs/laurent/">Laurent Miltgen-Delinchamp</a> pointed out:<br />
<a href="http://support.microsoft.com/default.aspx/kb/974772/">Error when entering Hibernation on a Windows 7-based computer</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2009/09/09/call-for-beta-testers-windd-utility-rc2-32-bits-64-bits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
