<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Debugging LSASS ... oh what fun, it is to ride..</title><link>http://blogs.msdn.com/spatdsg/archive/2005/12/27/507265.aspx</link><description>I spend a lot of my time debugging LSASS or Winlogon due to what I specialize in ( Active Directory \ Security \ PKI \ GPO’s ) As of XP and greater I have historically done a kernel debug to get at LSASS. If you try to debug it from usermode on the machine</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Debugging LSASS ... oh what fun, it is to ride..</title><link>http://blogs.msdn.com/spatdsg/archive/2005/12/27/507265.aspx#507630</link><pubDate>Wed, 28 Dec 2005 03:37:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:507630</guid><dc:creator>Pavel Lebedinsky</dc:creator><description>Since normally there's only one instance of lsass running, it's easier to attach by name rather than by pid:&lt;br&gt;&lt;br&gt;windbg -premote ... -pn lsass.exe&lt;br&gt;&lt;br&gt;You can also add -pd option to make sure you don't accidentally kill the process on detach.</description></item><item><title>re: Debugging LSASS ... oh what fun, it is to ride..</title><link>http://blogs.msdn.com/spatdsg/archive/2005/12/27/507265.aspx#652550</link><pubDate>Fri, 30 Jun 2006 21:11:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:652550</guid><dc:creator>Mike</dc:creator><description>I am quite fancy the last debugging method(via dbgsrv.exe), however, I always got an error&lt;br&gt;&amp;quot;Could not attach to process 280, Win32 error 5 Access is denied&amp;quot; (280 = PID of lsass). Any idea?&lt;br&gt;&lt;br&gt;Thanks,&lt;br&gt;</description></item><item><title>re: Debugging LSASS ... oh what fun, it is to ride..</title><link>http://blogs.msdn.com/spatdsg/archive/2005/12/27/507265.aspx#655910</link><pubDate>Tue, 04 Jul 2006 12:55:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:655910</guid><dc:creator>Mike</dc:creator><description>Sorry, my fault.&lt;br&gt;&lt;br&gt;I run dbgsrv.exe through TS (terminal service), that's why I got the error.&lt;br&gt;</description></item><item><title>re: Debugging LSASS ... oh what fun, it is to ride..</title><link>http://blogs.msdn.com/spatdsg/archive/2005/12/27/507265.aspx#771901</link><pubDate>Tue, 26 Sep 2006 11:50:42 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:771901</guid><dc:creator>James</dc:creator><description>Very Good! : )&lt;br&gt;&lt;br&gt;</description></item><item><title>College Fun Facts &amp;raquo; Spat&amp;#8217;s WebLog (Steve Patrick) : Debugging LSASS &amp;#8230; oh what fun it is &amp;#8230;</title><link>http://blogs.msdn.com/spatdsg/archive/2005/12/27/507265.aspx#8346435</link><pubDate>Mon, 31 Mar 2008 23:39:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8346435</guid><dc:creator>College Fun Facts » Spat’s WebLog (Steve Patrick) : Debugging LSASS … oh what fun it is …</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://collegefunfactsblog.info/spats-weblog-steve-patrick-debugging-lsass-oh-what-fun-it-is/"&gt;http://collegefunfactsblog.info/spats-weblog-steve-patrick-debugging-lsass-oh-what-fun-it-is/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>??????IAT hook??????windows?????????????????? | ??????&amp;#8217;s Blog</title><link>http://blogs.msdn.com/spatdsg/archive/2005/12/27/507265.aspx#8548514</link><pubDate>Sat, 24 May 2008 21:40:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8548514</guid><dc:creator>??????IAT hook??????windows?????????????????? | ??????&amp;#8217;s Blog</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://huaidan.org/archives/2012.html"&gt;http://huaidan.org/archives/2012.html&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>利用IAT hook实现windows通用密码后门</title><link>http://blogs.msdn.com/spatdsg/archive/2005/12/27/507265.aspx#8553822</link><pubDate>Tue, 27 May 2008 05:01:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8553822</guid><dc:creator>小辉</dc:creator><description>&lt;p&gt;来源：看雪学院&lt;/p&gt;
&lt;p&gt;作者：clyfish windows有通用密码吗？&lt;/p&gt;
&lt;p&gt;去问比尔大叔吧。 先不管是不是真的有，我们可以自己实现一个这样的后门。 先简单介绍一下windows登陆过程中...&lt;/p&gt;
</description></item></channel></rss>