- quarantine is boring
- reading a book "ARM 64-Bit Assembly Language" without practice is useless
Main magic happens in ntoskrnl_hack::find_lock_list function
my $state = 0; my($str, %dict, $size); while( $str = <> ) { chomp $str; last if ( $str eq '' ); if ( ! $state ) { $state = 1 if ( $str =~ /^-----/ ); next; } $str = substr($str, 72, 10); $str =~ s/^\s+//g; $str =~ s/\s+$//g; $size = hex($str); next if ( !$size ); $dict{$size} += 1; } # dump results my $iter; foreach $iter ( sort { $dict{$b} <=> $dict{$a} } keys %dict ) { printf("%X %d\n", $iter, $dict{$iter}); }results are encouraging:
Our min. configuration/price € 24.000 per year and it will include:
- UP to 20 fixed user licenses (or 4 floating licenses) Single Language-Klocwork insight
-1 fixed build license (server)
-unlimited LOC (lines of code)
-Maintenance & support for 12 month
All prices depends on the following choices :
- Insight or Insight Pro license
- fixed or floating license
- single language or all languages (C,C++,Java)
Dangerous magic number 4 used: UCHAR Tag[4]Дико опасная ошибка, да. Я заметил что оно вообще всегда делает стойку на константы 4 и 32
On 64-bit platform, structure size can be reduced from 48 to 40 bytes by rearranging the fields according to their sizes in decreasing order.Ну круто, чо. А как делать rearranging the fields то ? Хоть бы варианты какие предлагала
sizeof(PBYTE) * _countof(m_index_table) считается It is odd that a sizeof() operator is multiplied by sizeof()
if ( memcmp(hash, old_hash, HASH_SIZE) ) считается как The 'memcmp' function returns 0 if corresponding buffers are equal. Consider examining the condition for mistakesну и чо - проверил я хэши и если не совпали - мне нужно предпринять какие-то действия например
• Bullseye Coverage (http://www.bullseye.com/). This coverage tool, from Bullseye Testing Technology, provides function as well as condition/decision coverage, to give you a range of coverage precision. It offers features such as covering system-level and kernel mode code, merging results from distributed testing, and integration with Microsoft Visual Studio. It also gives you the ability to exclude certain portions of your code from analysis.Bullseye is a mature product that has support for a wide range of platforms and compilers.
• Rational PureCoverage (http://www.rational.com/). This code coverage analysis tool is sold as
part of the PurifyPlus package from IBM. It can report coverage at executable, library, file, function, block, and line levels.PureCoverage can accumulate coverage over multiple runs and merge data from different programs that share the same source code. It offers both graphical and textual output to let you explore its results.
• Intel Code-CoverageTool (http://www.intel.com/). This tool is included with Intel compilers and runs on instrumentation files produced by those compilers. It provides function and basic block coverage and can restrict analysis to only those modules of interest. It also supports differential coverage, that is, comparing the output of one run against another run.The Code-Coverage Tool runs on Intel processors under Windows or Linux.
• Gcov (http://gcc.gnu.org/onlinedocs/gcc/Gcov.html). This test coverage program is part of
the open-source GNU GCC compiler collection. It operates on code generated by
-fprofile-arcs and -ftest-coverage options.Gcov provides function, line, and branch code coverage. It outputs its report in a textual format; however, the accompanying lcov script
can be used to output results as an HTML report