ufrisk / pcileech

Direct Memory Access (DMA) Attack Software
GNU Affero General Public License v3.0
4.87k stars 718 forks source link

SP605/FT601 + Thunderbolt + windows10 issue? #76

Closed cofarmer closed 4 years ago

cofarmer commented 5 years ago

First, i have browsed this blog: http://blog.frizk.net/2016/10/dma-attacking-over-usb-c-and.html,it was used USB3380 board, but now, i have a SP605/FT601 and a Thunderbolt device, and the target system is Windows 10 x64, when start patch signature with pcileech, a few memory readed only, no more can be readed then, and the target os died. Do you know why this happened?

ufrisk commented 5 years ago

That blog entry is a few years old now and Microsoft have been securing Thunderbolt meanwhile.

I'm not sure that's your issue though. If you're able to read memory I suspect PCILeech is trying to read some memory that belongs to a device which doesn't like it - hence the bluescreen.

Alternatively, if a signature was found and patching started Windows sometimes bluescreens, either due to an outdated patch signature or maybe due to Windows patch guard.

The signatures are currently somewhat outdated. I hope to find the time to look into this in February (sadly not before due to other upcoming engagements).

cofarmer commented 5 years ago

Oh,thanks.Happy marriage.