<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Data Hiding in Crash Dumps</title>
	<link>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/</link>
	<description>Structural and Behavioral Patterns for Software Diagnostics, Forensics and Prognostics</description>
	<pubDate>Tue, 05 May 2026 18:09:05 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Crash Dump Analysis &#187; Blog Archive &#187; Crash Dump Analysis Patterns (Part 104)</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-173272</link>
		<dc:creator>Crash Dump Analysis &#187; Blog Archive &#187; Crash Dump Analysis Patterns (Part 104)</dc:creator>
		<pubDate>Wed, 04 Aug 2010 23:07:14 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-173272</guid>
		<description>[...] of .dump command (including privacy-aware) instead of /ma or deprecated /f option. On the contrary, manually erased data in crash dumps looks more like an example of another pattern called Lateral [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] of .dump command (including privacy-aware) instead of /ma or deprecated /f option. On the contrary, manually erased data in crash dumps looks more like an example of another pattern called Lateral [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Crash Dump Analysis &#187; Blog Archive &#187; Hardening Dump Security: Beware of PEB data</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-41932</link>
		<dc:creator>Crash Dump Analysis &#187; Blog Archive &#187; Hardening Dump Security: Beware of PEB data</dc:creator>
		<pubDate>Tue, 09 Sep 2008 11:29:39 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-41932</guid>
		<description>[...] - Include PEB but erase specific sections and regions pointed to like environment blocks. See the previous Data Hiding in Crash Dumps post. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] - Include PEB but erase specific sections and regions pointed to like environment blocks. See the previous Data Hiding in Crash Dumps post. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmitry Vostokov</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-30184</link>
		<dc:creator>Dmitry Vostokov</dc:creator>
		<pubDate>Thu, 12 Jun 2008 16:57:56 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-30184</guid>
		<description>Kdexts!vad is for kernel and complete memory dumps. The following prompt suggests that you have a process dump:

0:000&gt;</description>
		<content:encoded><![CDATA[<p>Kdexts!vad is for kernel and complete memory dumps. The following prompt suggests that you have a process dump:</p>
<p>0:000></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Crash Dump Analysis &#187; Blog Archive &#187; Crash Dump Analysis Patterns (Part 59b)</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-30182</link>
		<dc:creator>Crash Dump Analysis &#187; Blog Archive &#187; Crash Dump Analysis Patterns (Part 59b)</dc:creator>
		<pubDate>Thu, 12 Jun 2008 16:51:36 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-30182</guid>
		<description>[...] Crash Dump Analysis Exploring Crash Dumps and Debugging Techniques on Windows Platforms      &#171; Data Hiding in Crash Dumps [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Crash Dump Analysis Exploring Crash Dumps and Debugging Techniques on Windows Platforms      &laquo; Data Hiding in Crash Dumps [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ray Kinsella</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-30161</link>
		<dc:creator>Ray Kinsella</dc:creator>
		<pubDate>Thu, 12 Jun 2008 11:33:27 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2008/06/10/data-hiding-in-crash-dumps/#comment-30161</guid>
		<description>Ah .load Kdexts.dll solved that one, now I am getting :-

0:000&#62; !vad
unable to get nt!MmHighestUserAddress
VAD     level      start      end    commit
00000000: Unable to get contents of VAD1</description>
		<content:encoded><![CDATA[<p>Ah .load Kdexts.dll solved that one, now I am getting :-</p>
<p>0:000&gt; !vad<br />
unable to get nt!MmHighestUserAddress<br />
VAD     level      start      end    commit<br />
00000000: Unable to get contents of VAD1</p>
]]></content:encoded>
	</item>
</channel>
</rss>
