29912分页


拆分地址:

003FDFB0
0000 0000 0011 1111 1101 1111 1011 0000

00  0*8
00 0000 001 -> 1*8
1 1111 1101	-> 1FD*8
1111 1011 0000 -> FB0


PROCESS 883ef7c8  SessionId: 1  Cid: 09b0    Peb: 7ffdf000  ParentCid: 0588
    DirBase: bf2484a0  ObjectTable: 989df200  HandleCount:  61.
    Image: notepad.exe
	
kd> !dq bf2484a0 
#bf2484a0 00000000`b1b2e801 00000000`b1fef801
#bf2484b0 00000000`aed40801 00000000`b1ac1801
#bf2484c0 00000000`0a49a801 00000000`0a48b801
#bf2484d0 00000000`0a15c801 00000000`0a79d801
#bf2484e0 00000000`87648480 00000000`a3e39801
#bf2484f0 00000000`a445a801 00000000`a3aeb801
#bf248500 00000000`09e4b801 00000000`09b1c801
#bf248510 00000000`0a16d801 00000000`09f4e801
kd> !dq 00000000`b1b2e000+8
#b1b2e008 00000000`b1cd3867 00000000`ad80a867
#b1b2e018 00000000`adb26867 00000000`00000000
#b1b2e028 00000000`00000000 00000000`00000000
#b1b2e038 00000000`00000000 00000000`00000000
#b1b2e048 00000000`ae0a7867 00000000`ad523867
#b1b2e058 00000000`ad774867 00000000`b1ff8867
#b1b2e068 00000000`ad781867 00000000`00000000
#b1b2e078 00000000`00000000 00000000`00000000
kd> !dq 00000000`b1cd3000+1fd*8
#b1cd3fe8 80000000`ad7a1867 80000000`ad933867
#b1cd3ff8 80000000`ad88f867 8bfffffd`a4e8f475
#b1cd4008 8b0889f8`4d8b1045 90909090`76ebfc45
#b1cd4018 ec83ec8b`55ff8b90 00fc6583`08458b18
#b1cd4028 83f98b57`f08b5653 04eec1ec`7d890fe0
#b1cd4038 00010cbe`e8f44589 00017a77`850fc085
#b1cd4048 a1645674`d285178b 0f80808b`00000018
#b1cd4058 de8bc203`008b0000 85008bc3`0302e3c1
kd> !db 80000000`ad7a1000+fb0
#80000000ad7a1fb0 33 00 32 00 31 00 71 00-00 00 65 00 00 00 63 01 3.2.1.q...e...c.
#80000000ad7a1fc0 07 00 00 07 d7 7f 00 00-48 49 40 00 78 ff 3f 00 ........HI@.x.?.
#80000000ad7a1fd0 50 34 2b 76 00 00 00 00-d4 47 40 00 05 00 00 00 P4+v.....G@.....
#80000000ad7a1fe0 18 19 40 00 00 00 00 00-01 00 00 00 00 00 00 00 ..@.............
#80000000ad7a1ff0 00 00 00 00 04 00 63 01-2d d7 9d d1 de 7f 00 08 ......c.-.......
#80000000ad7a2000 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
#80000000ad7a2010 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
#80000000ad7a2020 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................

PDE&PTE:

最高位63位:硬件DEP位,1不可执行,0可执行

相关推荐
一只特立独行的程序猿7 分钟前
关于GCC内联汇编(也可以叫内嵌汇编)的简单学习
汇编·学习·gcc
天幕繁星14 小时前
docker desktop es windows解决vm.max_map_count [65530] is too low 问题
windows·elasticsearch·docker·docker desktop
百锦再15 小时前
详解基于C#开发Windows API的SendMessage方法的鼠标键盘消息发送
windows·c#·计算机外设
IT-民工2111017 小时前
Ansible剧本检测Windows防火墙状态
linux·运维·windows·自动化·ansible
菜鸟江多多20 小时前
【windows 下使用 tree】
windows
星晨羽20 小时前
esayExcel根据模板导出包含图片
java·开发语言·windows
开发者每周简报1 天前
当微软windows的记事本被AI加持
人工智能·windows·microsoft
命里有定数1 天前
windows工具 -- 使用rustdesk和云服务器自建远程桌面服务, 手机, PC, Mac, Linux远程桌面 (简洁明了)
linux·运维·服务器·windows·ubuntu·远程工作
染指11101 天前
45.第二阶段x86游戏实战2-hook监控实时抓取游戏lua
汇编·c++·windows·反游戏外挂·游戏逆向
ARM&开发(Haidong)1 天前
ARM 汇编指令
汇编