[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Q: What mechanism SoftICE BPR uses?



Hello,

for finding classics BRPs I know 2 ways:
 
1.
Search in program for 0CCh (you must know where you have 0ccg in 
program, because you will find this places too)

2.
Use CRC and if is BRP set, is CRC bad.


for debug breakpoints:
Soft-Ice use debug registers for them.

You can read debug registers (mov eax, dr0 etc.) but it is working 
only in RING0.
Other way is Context. There are some good informations. It working 
for winNT and 2k, too.

Bye Exit