Wrox Programmer Forums

Need to download code?

View our list of code downloads.

Register | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read
BOOK: Professional Rootkits ISBN: 978-0-470-10154-4
This is the forum to discuss the Wrox book Professional Rootkits by Ric Vieler; ISBN: 9780470101544
Welcome to the p2p.wrox.com Forums.

You are currently viewing the BOOK: Professional Rootkits ISBN: 978-0-470-10154-4 section of the Wrox Programmer to Programmer discussions. This is a community of tens of thousands of software programmers and website developers including Wrox book authors and readers. As a guest, you can read any forum posting. By joining today you can post your own programming questions, respond to other developers’ questions, and eliminate the ads that are displayed to guests. Registration is fast, simple and absolutely free .
DRM-free e-books 300x50
Reply
 
Thread Tools Display Modes
  #1 (permalink)  
Old June 18th, 2007, 05:43 AM
Registered User
 
Join Date: Jun 2007
Location: , , .
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Default Getting past Verification

Hi,

I can't seem to get past the verification part of your book.  I've downloaded all the tools and utilities of the rootkit (chapter 1).  However, when trying to verify the Windbg part (entering !process 0 0 at the lkd> prompt), I get told this:

lkd> !process 0 0
**** NT ACTIVE PROCESS DUMP ****
NT symbols are incorrect, please fix symbols

...any ideas?  I've set the symbols path to C:\Windows\Symbols which is where the WinXP symbols installer defaulted to.

Here is what my .reload command looks like:

lkd> .reload
Connected to Windows XP 2600 x86 compatible target, ptr64 FALSE
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for ntkrnlmp.exe -
Loading Kernel Symbols
.................................................. .................................................. ....................
Loading User Symbols
.................................................. .............................
Loading unloaded module list
.........*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -

Thanks in advance.  I'm looking forward to exploring some more once I get past this initial hurdle.
Reply With Quote
  #2 (permalink)  
Old June 21st, 2007, 11:46 AM
Registered User
 
Join Date: Mar 2007
Location: , , .
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Hey Joe:

You can modify your symbol path to:

http://msdl.microsoft.com/download/symbols; C:\Windows\Symbols

This will allow the debugger to check Microsoft for the required symbols.

I hope this helps.
Ric Vieler :-)

Reply With Quote
  #3 (permalink)  
Old June 21st, 2007, 05:42 PM
Registered User
 
Join Date: Jun 2007
Location: , , .
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Default

This worked, Ric. Thanks for responding.


Reply With Quote
  #4 (permalink)  
Old January 8th, 2008, 11:44 PM
Registered User
 
Join Date: Jan 2008
Location: Las Cruces, NM, USA.
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Send a message via Yahoo to alsaleh
Default

Hi;
I am not sure where to put "lkd>!process 0 0"
There is no place to write this command. I tried the cmd.exe and WinDbg without getting any thing. Can any body help.

Thanks

Reply With Quote
  #5 (permalink)  
Old August 5th, 2008, 03:31 PM
Registered User
 
Join Date: Aug 2008
Location: ellicott city, md, USA.
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Default

All, I am in the 1st chapter of rootkits and am a bit confused about downloading the software. I was wondering if I have .net 2003, will this include all the software to compile, run and debug the examples from the book "Rootkits".
thanks


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Should I go past chapter 13? bossman21 BOOK: Beginning Visual Basic 2005 ISBN: 978-0-7645-7401-6 4 July 24th, 2006 01:42 PM
past titles oxygen_fiend All Other Wrox Books 1 September 6th, 2005 11:49 AM
Can't get past "Token StartElement" error Colonel Angus Classic ASP XML 1 August 10th, 2005 02:21 PM
Query wont work unless I copy and past into new on Mitch Access 1 March 4th, 2005 02:22 AM
Getting authentication past firewall johndove Classic ASP Basics 1 December 21st, 2003 01:41 PM



All times are GMT -4. The time now is 11:06 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
© 2013 John Wiley & Sons, Inc.