Advertisement
Guest User

Untitled

a guest
Jul 3rd, 2019
145
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.50 KB | None | 0 0
  1. DRIVER_OVERRAN_STACK_BUFFER (f7)
  2. A driver has overrun a stack-based buffer. This overrun could potentially
  3. allow a malicious user to gain control of this machine.
  4. DESCRIPTION
  5. A driver overran a stack-based buffer (or local variable) in a way that would
  6. have overwritten the function's return address and jumped back to an arbitrary
  7. address when the function returned. This is the classic "buffer overrun"
  8. hacking attack and the system has been brought down to prevent a malicious user
  9. from gaining complete control of it.
  10. Do a kb to get a stack backtrace -- the last routine on the stack before the
  11. buffer overrun handlers and bugcheck call is the one that overran its local
  12. variable(s).
  13. Arguments:
  14. Arg1: ce4b37deeb0a7580, Actual security check cookie from the stack
  15. Arg2: 0000e668dabe8657, Expected security check cookie
  16. Arg3: ffff1997254179a8, Complement of the expected security check cookie
  17. Arg4: 0000000000000000, zero
  18.  
  19. Debugging Details:
  20. ------------------
  21.  
  22.  
  23. KEY_VALUES_STRING: 1
  24.  
  25.  
  26. PROCESSES_ANALYSIS: 1
  27.  
  28. SERVICE_ANALYSIS: 1
  29.  
  30. STACKHASH_ANALYSIS: 1
  31.  
  32. TIMELINE_ANALYSIS: 1
  33.  
  34.  
  35. DUMP_CLASS: 1
  36.  
  37. DUMP_QUALIFIER: 401
  38.  
  39. BUILD_VERSION_STRING: 17763.1.amd64fre.rs5_release.180914-1434
  40.  
  41. SYSTEM_MANUFACTURER: Micro-Star International Co., Ltd
  42.  
  43. SYSTEM_PRODUCT_NAME: MS-7B07
  44.  
  45. SYSTEM_SKU: To be filled by O.E.M.
  46.  
  47. SYSTEM_VERSION: 1.0
  48.  
  49. BIOS_VENDOR: American Megatrends Inc.
  50.  
  51. BIOS_VERSION: 2.B0
  52.  
  53. BIOS_DATE: 11/06/2018
  54.  
  55. BASEBOARD_MANUFACTURER: Micro-Star International Co., Ltd
  56.  
  57. BASEBOARD_PRODUCT: B350M PRO-VH PLUS (MS-7B07)
  58.  
  59. BASEBOARD_VERSION: 1.0
  60.  
  61. DUMP_TYPE: 1
  62.  
  63. BUGCHECK_P1: ce4b37deeb0a7580
  64.  
  65. BUGCHECK_P2: e668dabe8657
  66.  
  67. BUGCHECK_P3: ffff1997254179a8
  68.  
  69. BUGCHECK_P4: 0
  70.  
  71. SECURITY_COOKIE: Expected 0000e668dabe8657 found ce4b37deeb0a7580
  72.  
  73. CPU_COUNT: c
  74.  
  75. CPU_MHZ: e10
  76.  
  77. CPU_VENDOR: AuthenticAMD
  78.  
  79. CPU_FAMILY: 17
  80.  
  81. CPU_MODEL: 1
  82.  
  83. CPU_STEPPING: 1
  84.  
  85. BLACKBOXBSD: 1 (!blackboxbsd)
  86.  
  87.  
  88. DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
  89.  
  90. BUGCHECK_STR: 0xF7
  91.  
  92. PROCESS_NAME: System
  93.  
  94. CURRENT_IRQL: 2
  95.  
  96. ANALYSIS_SESSION_HOST: DESKTOP-P2JCIAF
  97.  
  98. ANALYSIS_SESSION_TIME: 07-03-2019 03:08:02.0044
  99.  
  100. ANALYSIS_VERSION: 10.0.18362.1 x86fre
  101.  
  102. LAST_CONTROL_TRANSFER: from fffff8025890e7b5 to fffff8025885aef0
  103.  
  104. STACK_TEXT:
  105. ffffc409`eb0a7538 fffff802`5890e7b5 : 00000000`000000f7 ce4b37de`eb0a7580 0000e668`dabe8657 ffff1997`254179a8 : nt!KeBugCheckEx
  106. ffffc409`eb0a7540 fffff802`5870f9c7 : fffff802`58ae32f0 ffffc37b`99f3a000 00000000`00000002 fffff802`00000001 : nt!_report_gsfailure+0x25
  107. ffffc409`eb0a7580 fffff802`5870de91 : fffff802`58ae2ee0 00000000`00000000 00000000`00000009 00000000`00000080 : nt!MiMakeZeroedPageTablesEx+0x253
  108. ffffc409`eb0a77e0 fffff802`5870de59 : fffff802`58ae2158 00000000`00000001 00000000`00000009 fffff802`00000002 : nt!MiMakeZeroedPageTables+0x9
  109. ffffc409`eb0a7820 fffff802`586d2b88 : ffffc37b`99f3a080 fffff802`00000000 ffff2261`31b4f117 00000000`00000000 : nt!MiSplitBitmapPages+0x6d
  110. ffffc409`eb0a7850 fffff802`5878c555 : 00000000`00000000 00000000`00000080 00000000`00000000 00000000`00000000 : nt!MiExpandPtes+0x150
  111. ffffc409`eb0a7910 fffff802`5878affe : 00000027`0db68a01 fffff802`00000003 ffffc409`eb0a7a40 ffff2261`31b4ffd7 : nt!MiReservePtes+0x435
  112. ffffc409`eb0a79e0 fffff802`587a322a : 00000000`59df0000 ffff2261`31b4ffa7 fffff802`586e7500 ffffa308`d23c5300 : nt!MmMapLockedPagesSpecifyCache+0xce
  113. ffffc409`eb0a7a40 fffff802`586e760a : ffffa308`d23c5300 00000000`00000000 00000000`00080000 ffffa308`00000005 : nt!CcCompleteAsyncRead+0xf2
  114. ffffc409`eb0a7b30 fffff802`5871bbfa : ffffa308`d0b11040 fffff802`586e75c0 ffffa308`d13d11f0 ffffa308`b3ceecb0 : nt!CcCompleteAsyncReadWorker+0x4a
  115. ffffc409`eb0a7b70 fffff802`586e4b35 : ffffa308`d0b11040 ffffa308`b3c6b040 ffffa308`d0b11040 00000000`00000000 : nt!ExpWorkerThread+0x16a
  116. ffffc409`eb0a7c10 fffff802`5886235c : ffffb381`ce19e180 ffffa308`d0b11040 fffff802`586e4ae0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
  117. ffffc409`eb0a7c60 00000000`00000000 : ffffc409`eb0a8000 ffffc409`eb0a2000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x1c
  118.  
  119.  
  120. THREAD_SHA1_HASH_MOD_FUNC: 7fee156177d79f735223a9a9f95185f063a61ba8
  121.  
  122. THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 5fc1cf84ecd72ab0238d797518a9227b5886d195
  123.  
  124. THREAD_SHA1_HASH_MOD: fe34192f63d13620a8987d294372ee74d699cfee
  125.  
  126. FOLLOWUP_IP:
  127. nt!_report_gsfailure+25
  128. fffff802`5890e7b5 cc int 3
  129.  
  130. FAULT_INSTR_CODE: cccccccc
  131.  
  132. SYMBOL_STACK_INDEX: 1
  133.  
  134. SYMBOL_NAME: nt!_report_gsfailure+25
  135.  
  136. FOLLOWUP_NAME: MachineOwner
  137.  
  138. MODULE_NAME: nt
  139.  
  140. IMAGE_NAME: ntkrnlmp.exe
  141.  
  142. DEBUG_FLR_IMAGE_TIMESTAMP: 33a6c3fc
  143.  
  144. STACK_COMMAND: .thread ; .cxr ; kb
  145.  
  146. BUCKET_ID_FUNC_OFFSET: 25
  147.  
  148. FAILURE_BUCKET_ID: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
  149.  
  150. BUCKET_ID: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
  151.  
  152. PRIMARY_PROBLEM_CLASS: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
  153.  
  154. TARGET_TIME: 2019-06-18T03:07:47.000Z
  155.  
  156. OSBUILD: 17763
  157.  
  158. OSSERVICEPACK: 0
  159.  
  160. SERVICEPACK_NUMBER: 0
  161.  
  162. OS_REVISION: 0
  163.  
  164. SUITE_MASK: 784
  165.  
  166. PRODUCT_TYPE: 1
  167.  
  168. OSPLATFORM_TYPE: x64
  169.  
  170. OSNAME: Windows 10
  171.  
  172. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
  173.  
  174. OS_LOCALE:
  175.  
  176. USER_LCID: 0
  177.  
  178. OSBUILD_TIMESTAMP: 1997-06-17 14:06:04
  179.  
  180. BUILDDATESTAMP_STR: 180914-1434
  181.  
  182. BUILDLAB_STR: rs5_release
  183.  
  184. BUILDOSVER_STR: 10.0.17763.1.amd64fre.rs5_release.180914-1434
  185.  
  186. ANALYSIS_SESSION_ELAPSED_TIME: 1459
  187.  
  188. ANALYSIS_SOURCE: KM
  189.  
  190. FAILURE_ID_HASH_STRING: km:0xf7_missing_gsframe_nt!_report_gsfailure
  191.  
  192. FAILURE_ID_HASH: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
  193.  
  194. Followup: MachineOwner
  195. ---------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement