Modifying Registers in Windbg extension

Viewed 23

Does anyone know if it is possible to either call a Windbg script from an extension or modify registers and execute APIs in the debugged process's context?

By Windbg script I mean .wds files and extensions are the compiled dll that you can execute exported functions from if required.

1 Answers

With a WDS file, you can

  • modify registers, of course:

    1:005:x86> r
    eax=00000003 [...]
    
    1:005:x86> r eax=4
    
    1:005:x86> r
    eax=00000004 [...]
    
  • allocate memory, if you need memory for an API call (note that 1000 is actually 0x1000 bytes = 4096 bytes here, because it allocates whole pages)

    1:005:x86> .dvalloc 400
    Allocated 1000 bytes starting at 00920000
    
  • .call a function

  • execute a debugger extension command (!-command). Just make sure that the extension is .loaded.

However, your WinDbg extension is loaded into the WinDbg.exe process and .call makes a function call in the debugging target. Using .call and a function from your WinDbg extension won't work.

Except if you loaded that same extension DLL into the target process. This violates the Separation of Concerns principle, IMHO. Make one WinDbg extension DLL and make one DLL which you inject into the target.

Related