Joined: 09 May 2003 Posts: 25848 Location: The netherlands
Posted: Sun Sep 08, 2013 3:48 am Post subject:
With vmware you get the emulated physical memory instead of the emulated virtual memory
When an operating system allocates memory it picks some random physical memory locations and then links them into a sequence with a pagetable to form a contiguous block of virtual memory
To get a virtual address from a physical and the other way around you must find the physical address of the pagetablebase (the cr3 register of a process holds that, but you might be able to find it with a lot of tedious scanning as well)
Then go through it till you find the entry that describes the page you are interested in _________________
Do not ask me about online cheats. I don't know any and wont help finding them.
Like my help? Join me on Patreon so i can keep helping
Joined: 09 May 2003 Posts: 25848 Location: The netherlands
Posted: Sun Sep 08, 2013 6:42 am Post subject:
no, the pagetablebase is at a random location in physical memory (relative to the vmem base address)
You can manually find it after having found the address by a lot of scanning and manual inspecting the memory region, but that's useless if you wish to use it to find the address in the first place without scanning
Perhaps you can tell windows to always load the kernel at the same physical spot in memory and then use that to walk through the processlist and find the pagetablebase that way _________________
Do not ask me about online cheats. I don't know any and wont help finding them.
Like my help? Join me on Patreon so i can keep helping
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum