2014年10月21日 星期二

Windows server 2008 R2 SP1 kernel socket leak

最近發現在 server 2008 上面跑的 service 出現 connection error,
經過測試, 確定網路是通的
後來自己寫了小程式去做 socket connect 測試, 發現只要同時開多個 socket, 一定會出現 exception

an operation on a socket could not be performed because the system lacked sufficient buffer space

上網查了資料, 這個錯誤常常是因為 windows 有 socket port range 限制, 但是 application 頻繁的打開跟關閉 socket 所已 port number 達到 windows 規定上限

http://blog.zhaojie.me/2010/08/lack-of-dynamic-ports-when-frequently-open-and-close-socket.html

http://blog.miniasp.com/post/2010/11/17/How-to-deal-with-TIME_WAIT-problem-under-Windows.aspx

這種情況通常等個一會讓 windows 把關掉的 socket port number 再重用, 就可以避開
但是我遇到的情況是不管等多久這個 exception 都會出現

繼續查資料發現 windows 還有一個 known issue, kernel socket leak

http://support.microsoft.com/kb/2577795

當這個 issue 發生時, 因為是 kernel 沒有把 socket 正確關閉, 所以除了重開機不然沒救
這個 KB 描述的現象跟我遇到的非常相似, 而且我使用的 server 剛好就是該 KB 有提到的
server 2008 R2 SP1.

可惜的是沒有一個方法可以確定是不是真的發生了 kernel socket leak, 只能先裝上 hotfix
再看看之後會不會發生

2014年10月13日 星期一

在 blog 中程式碼上色的解決方案: Google Javascript code prettifier

想在 blog 中貼上程式碼上色, Google 出了一個很簡單使用的解決方案

Javascript code prettifier

只要在 blog 的 template 加上一個連結
<script src="https://google-code-prettify.googlecode.com/svn/loader/run_prettify.js"></script>

再把程式碼區塊用特定的 html 元素包起來, 就可以幫程式碼上色了

reference:
https://google-code-prettify.googlecode.com/svn/trunk/README.html

用 parameterized queries 防止 SQL Injection

當用程式做資料庫操作時, 不建議把 SQL command 直接寫在 code 裡面, 因為這樣常會有背 SQL injection 的風險, 比較好的方式是使用 parameterized queries.

例如:

string stmt = "INSERT INTO dbo.Test(id, name) VALUES(@ID, @Name)";

SqlCommand cmd = new SqlCommand(smt, _connection);
cmd.Parameters.Add("@ID", SqlDbType.Int);
cmd.Parameters.Add("@Name", SqlDbType.VarChar, 100);

for (int i = 0; i < 10000; i++)
{
    cmd.Parameters["@ID"].Value = i;
    cmd.Parameters["@Name"].Value = i.ToString();

    cmd.ExecuteNonQuery();
}

reference:
http://stackoverflow.com/questions/60174/how-can-i-prevent-sql-injection-in-php
http://stackoverflow.com/questions/8218867/c-sharp-sql-insert-command

2014年7月7日 星期一

Anti debugger tricks

Windows 有 IsDebuggerPresent API 可以讓程式知道自己是不是正在被 debug.
其實這個 API 就是去 PEB 裡面讀取 BeingDebugged 欄位.

程式也可以自己取得 PEB 位址, 然後讀取 BeingDebugged 欄位, 而不呼叫 API.
免得很容易就被人 bypass.

除了 BeingDebugged 欄位外, PEB 還有 NtGlobalFlag 欄位可以檢查是否被 debug.

GetStartupInfo API 也可以用來 anti debug, 因為被 Ollydbg lunch 的程式
StartupInfo 裡面的 dwFlags 會跟被 explorer lunch 起來的不一樣.

Reference:
http://www.codeproject.com/Articles/29469/Introduction-Into-Windows-Anti-Debugging

2014年6月25日 星期三

Debug 程式好用的指令 EB FE

0xEBFE 是一個短跳指令, 作用是跳到這個指令原本的位址
可以看做是單一指令的 infinite loop

有時候想 attach debugger 到某個程式時可以先把 EP 改成 EBFE
等程式在這邊 loop 時再 attach 上去就好了

2014年6月16日 星期一

Debug custom exception filter set by SetUnhandledExceptionFilter

SetUnhandledExceptionFilter 可以讓程式設定自定義的頂層 exception filter
用來處理程式中未被處理的 exception

之前想要 debug 這種 custom exception filter, 但用 debugger 開啟程式後卻怎麼也跑不到
查了後才發現這是 MS 的設計

MSDN 上的描述:

A pointer to a top-level exception filter function that will be called whenever the UnhandledExceptionFilter function gets control, and the process is not being debugged. A value of NULL for this parameter specifies default handling within UnhandledExceptionFilter. 

不過為什麼要有這麼奇怪的設計? 真的讓人猜不透
如果只有執行檔沒有 source code 時要怎麼 debug?

幸好網路上早有了怎麼 bypass 的方法,
UnhandledExceptionFilter 是呼叫 NtQueryInformationProcess 檢查程式是否正在被 debug 的
所以只要改掉 NtQueryInformationProcess 回傳的值就好了

Reference:
http://evilcodecave.wordpress.com/2008/07/24/setunhandledexception-filter-anti-debug-trick/

2014年6月3日 星期二

Program crash without WER dialog

在 XP 上很容易發生 process silent death,
因為在 XP 上做 error reporting 的機制是由 crashed process 負責,
所以只要將 stack 搞爛, 就可以讓 WER dialog 不顯示
甚至註冊的 unhandled exception handler 也不會被執行

但是在 Vista 之後, 實作 error reporting 的機制移到另外的 process 中, 所以在 XP 上
讓 process silent death 的方式在 Vista 之後就不行了
不過如果搞爛 stack, 雖然有 WER dialog,
但是 unhandled exception handler 不會被執行
猜測是因為 unhandled exception handler 的執行也需要 stack,
但是既然 stack 爛掉了, 自然也就無法執行

Reference:
http://stackoverflow.com/questions/14195327/how-to-crash-a-process-on-windows-7-without-getting-the-wer-dialog