-
Notifications
You must be signed in to change notification settings - Fork 14
Description
Particularly, I see two different out-buffer size 0xc18 and 0x610 for command 41h.
In current code, the 0x610 case is not handled and returns FALSE.
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.893] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.893] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.893] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.893] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.893] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.893] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.893] [trace] command 41h called
[2024-12-04 21:56:59.893] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.893] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.893] [trace] ioctl out-buffer size: 0x610
[2024-12-04 21:56:59.806] [info] SafeDiscShim version 0.1.1
[2024-12-04 21:56:59.816] [trace] Hooked NtDeviceIoControlFile
[2024-12-04 21:56:59.816] [trace] Hooked CreateFileA
[2024-12-04 21:56:59.823] [trace] Enabled IOCTL hooks
[2024-12-04 21:56:59.824] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.824] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.825] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.825] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.831] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.831] [trace] hooked CreateProcessA called
[2024-12-04 21:56:59.833] [info] injecting into executable Z:\Temp~e5.0001
[2024-12-04 21:56:59.833] [trace] starting injection into executable
[2024-12-04 21:56:59.835] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.835] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.835] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.835] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.835] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.835] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.835] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.836] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.836] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.838] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.839] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.839] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.839] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.839] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.839] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.839] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.839] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.839] [info] SafeDisc ioctl version 4.00.040 detected.
[2024-12-04 21:56:59.839] [trace] command SetupVerification called
[2024-12-04 21:56:59.839] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.839] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.839] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.839] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.839] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.839] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.839] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.839] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.839] [trace] command GetDebugRegisterInfo called
[2024-12-04 21:56:59.841] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.841] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.841] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.841] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.841] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.841] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.841] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.841] [trace] command 3Fh called
[2024-12-04 21:56:59.841] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.842] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.842] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.842] [trace] command 3Fh called
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.842] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.842] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.842] [trace] command 3Fh called
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.842] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.842] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.842] [trace] command 3Fh called
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.842] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.842] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.842] [trace] command 3Fh called
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.842] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.842] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.842] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.842] [trace] ioctl out-buffer size: 0xc18
..................
..................
[2024-12-04 21:56:59.891] [trace] command 41h called
[2024-12-04 21:56:59.891] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.891] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.891] [trace] ioctl out-buffer size: 0x610
[2024-12-04 21:56:59.891] [trace] command 41h called
[2024-12-04 21:56:59.891] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.891] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.891] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.891] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.891] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.891] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.891] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.891] [trace] command 41h called
[2024-12-04 21:56:59.891] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.891] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.891] [trace] ioctl out-buffer size: 0x610
[2024-12-04 21:56:59.891] [trace] command 41h called
[2024-12-04 21:56:59.891] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.891] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.891] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.891] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.891] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.892] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.892] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.892] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.892] [trace] ioctl out-buffer size: 0x610
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.892] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.892] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.892] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.892] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.892] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.892] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.892] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.892] [trace] ioctl out-buffer size: 0x610
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.892] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.892] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.892] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.892] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.892] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.892] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.892] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.892] [trace] ioctl out-buffer size: 0x610
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.892] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.892] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.892] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.892] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.892] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.892] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.892] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.892] [trace] ioctl out-buffer size: 0x610
[2024-12-04 21:56:59.892] [trace] command 41h called
[2024-12-04 21:56:59.892] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.893] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.893] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.893] [trace] CreateFileA: SecDrv opened!
[2024-12-04 21:56:59.893] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.893] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.893] [trace] ioctl out-buffer size: 0xc18
[2024-12-04 21:56:59.893] [trace] command 41h called
[2024-12-04 21:56:59.893] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.893] [trace] ioctl in-buffer size: 0x514
[2024-12-04 21:56:59.893] [trace] ioctl out-buffer size: 0x610
[2024-12-04 21:56:59.893] [trace] command 41h called
[2024-12-04 21:56:59.897] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.897] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.905] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.905] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.919] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.919] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.919] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.920] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.920] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.920] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.920] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.921] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.921] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.923] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.923] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.923] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.923] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.923] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.923] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.924] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.924] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.924] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.924] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.924] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.924] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.925] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.926] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.926] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.926] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.926] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.926] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.926] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.927] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.927] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.927] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.927] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.927] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.928] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.928] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.929] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.930] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.930] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.930] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.930] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.930] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.930] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.931] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.931] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.931] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.931] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.932] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.933] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.933] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.933] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.933] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.933] [trace] hooked NtDeviceIoControlFile called
[2024-12-04 21:56:59.934] [trace] hooked CreateFileA called
[2024-12-04 21:56:59.934] [trace] hooked NtDeviceIoControlFile called