W
wiretap
Hi =)
I have a 2GB memory dump that I forced manually. I have to find
specific information that was within an application at the time of the
dump. I have no clue where it would be, or how to access it. I have the
windows debug tool installed, and I am able to open the memory.dmp file
in it. I'm a little confused as how to navigate around to find certain
things. I tried to look in the help file, but it seems to want certain
memory locations to be specified when you search memory. I don't know
the location, but I know the application. Could anyone please point me
in the right direction? If it helps, what I am searching for is 128
bits long, so 16 bytes, or 32 hexadecimal characters. I cannot say what
I am looking for, because this is for a private project I am working on
at the moment.
To sum things up..
- dumped memory to .dmp file, opened it in windbg.exe
- looking for specific string stored in RAM
- just need help on how to do the search if I already know the
application
Thanks.
wiretap
I have a 2GB memory dump that I forced manually. I have to find
specific information that was within an application at the time of the
dump. I have no clue where it would be, or how to access it. I have the
windows debug tool installed, and I am able to open the memory.dmp file
in it. I'm a little confused as how to navigate around to find certain
things. I tried to look in the help file, but it seems to want certain
memory locations to be specified when you search memory. I don't know
the location, but I know the application. Could anyone please point me
in the right direction? If it helps, what I am searching for is 128
bits long, so 16 bytes, or 32 hexadecimal characters. I cannot say what
I am looking for, because this is for a private project I am working on
at the moment.
To sum things up..
- dumped memory to .dmp file, opened it in windbg.exe
- looking for specific string stored in RAM
- just need help on how to do the search if I already know the
application
Thanks.
wiretap