|
|
E:\nt\private\ntos\rdr2\rdbss\smb.mrx\umt_stff>if x86 == x86 obj\i386\umt_stff Calling stufferdebug Here in stuffer debug Initial SMB Current size = 20 (32) 000 424d53ff 000000ff 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. First readcommand status = 0 SMB w/ NTREAD&X before stuffing Current size = 20 (32) 000 424d53ff 0000002e 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. StufferAC = XwdwWdW StufferFloop 'X' StufferFloop 'w' arg=25670 StufferFloop 'd' arg=1953719887 StufferFloop 'w' arg=30797 StufferFloop 'w' arg=28237 StufferFloop 'd' arg=1953853268 StufferFloop 'w' arg=29763 StufferCloop NewStufferControl=1 StufferAC = d StufferFloop 'd' arg=1751607624 StufferCloop NewStufferControl=1 StufferAC = B! StufferFloop 'b' Wct=12 StufferFloop '!' arg=0 SMB w/ NTREAD&X after stuffing Current size = 3b (59) 000 424d53ff 0000002e 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 de00ff0c 4f6446de 4d747366 546e4d78 4374756f 67694874 00000068 .... .FdO fstM xMnT outC tHig h.. Second readcommand status = 0 SMB w/ notNTREAD&X before stuffing Current size = 3b (59) 000 424d53ff 0000002e 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 3b002e0c 4f644600 4d747366 546e4d78 4374756f 67694874 00000068 ...; .FdO fstM xMnT outC tHig h.. StufferAC = XwdwWdW StufferFloop 'X' StufferFloop 'w' arg=25670 StufferFloop 'd' arg=1953719887 StufferFloop 'w' arg=30797 StufferFloop 'w' arg=28237 StufferFloop 'd' arg=1953853268 StufferFloop 'w' arg=29763 StufferCloop NewStufferControl=2 StufferAC = d StufferCloop NewStufferControl=1 StufferAC = B! StufferFloop 'b' Wct=10 StufferFloop '!' arg=0 SMB w/ notNTREAD&X after stuffing Current size = 52 (82) 000 424d53ff 0000002e 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 3b002e0c 4f644600 4d747366 546e4d78 4374756f 67694874 0a000068 dede00ff ...; .FdO fstM xMnT outC tHig h... .... 040 664f6446 784d7473 6f546e4d 74437475 00000000 FdOf stMx MnTo utCt .. Third readcommand status = 0 SMB w/ NTWRITE&X before stuffing Current size = 52 (82) 000 424d53ff 0000002e 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 3b002e0c 4f644600 4d747366 546e4d78 4374756f 67694874 0a000068 0052002f ...; .FdO fstM xMnT outC tHig h... /.R. 040 664f6446 784d7473 6f546e4d 74437475 00000000 FdOf stMx MnTo utCt .. StufferAC = XwddwWwwq StufferFloop 'X' StufferFloop 'w' arg=25670 StufferFloop 'd' arg=1953719887 StufferFloop 'd' arg=1953853268 StufferFloop 'w' arg=25677 StufferFloop 'w' arg=29763 StufferFloop 'w' arg=11565 StufferFloop 'w' arg=33 StufferFloop 'q' StufferCloop NewStufferControl=1 StufferAC = d StufferFloop 'd' arg=1751607624 StufferCloop NewStufferControl=1 StufferAC = BSc5! StufferFloop 'b' Wct=14 StufferFloop 'S' StufferFloop 'c' copycount = 33 StufferFloop '5' offset=149 StufferFloop '!' arg=36 SMB w/ NTWRITE&X after stuffing Current size = 95 (149) 000 424d53ff 0000002e 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 3b002e0c 4f644600 4d747366 546e4d78 4374756f 67694874 0a000068 0052002f ...; .FdO fstM xMnT outC tHig h... /.R. 040 664f6446 784d7473 6f546e4d 74437475 ff0e0000 46dede00 73664f64 756f5474 FdOf stMx MnTo utCt .... ...F dOfs tTou 060 43644d74 212d2d74 48009500 24686769 eeeeee00 33323130 37363534 33323130 tMdC t--! ...H igh$ .... 0123 4567 0123 080 37363534 33323130 37363534 33323130 37363534 00000000 4567 0123 4567 0123 4567 . Initial SMB Current size = 20 (32) 000 424d53ff 000000ff 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. First SS&X command status = 0 SMB w/ NTSESSSS&X before stuffing Current size = 20 (32) 000 424d53ff 00000073 80000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB s... .... .... .... .... .... jj.. APsize=e, UPsize=10 StufferAC = XwwwDw StufferFloop 'X' StufferFloop 'w' arg=26178 StufferFloop 'w' arg=30797 StufferFloop 'w' arg=25430 StufferFloop 'd' arg=1936942419 StufferFloop 'w' arg=14 StufferCloop NewStufferControl=1 StufferAC = wddBcczzzz StufferFloop 'w' arg=16 StufferFloop 'd' arg=1685484370 StufferFloop 'd' arg=1936744771 StufferFloop 'b' Wct=13 StufferFloop 'c' copycount = 14 StufferFloop 'c' copycount = 16 StufferFloop '4/z/>' stringing = AccountName, cp= StufferFloop '4/z/>' aligning StufferFloop '4/z/>' stringing = PrimaryDomain, cp= StufferFloop '4/z/>' stringing = NativeOS, cp= StufferFloop '4/z/>' stringing = NativeLanMan, cp= StufferCloop NewStufferControl=1 StufferAC = ! StufferFloop '!' arg=127 SMB w/ NTSESSSS&X after stuffing Current size = bc (188) 000 424d53ff 00000073 80000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB s... .... .... .... .... .... jj.. 020 de00ff0d 4d6642de 53635678 0e737365 52001000 43647673 7f737061 63734100 .... .BfM xVcS ess. ...R svdC aps. .Asc 040 61506969 6f777373 50006472 73006100 77007300 72006f00 00006400 00630041 iiPa sswo rd.P .a.s .s.w .o.r .d.. A.c. 060 006f0063 006e0075 004e0074 006d0061 00000065 00720050 006d0069 00720061 c.o. u.n. t.N. a.m. e... P.r. i.m. a.r. 080 00440079 006d006f 00690061 0000006e 0061004e 00690074 00650076 0053004f y.D. o.m. a.i. n... N.a. t.i. v.e. O.S. 0a0 004e0000 00740061 00760069 004c0065 006e0061 0061004d 0000006e ..N. a.t. i.v. e.L. a.n. M.a. n... TC&X command status = 0 SMB w/ TREECON&X before stuffing Current size = bc (188) 000 424d53ff 00000073 80000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB s... .... .... .... .... .... jj.. 020 bc00750d 4d664200 53635678 0e737365 52001000 43647673 7f737061 63734100 .u.. .BfM xVcS ess. ...R svdC aps. .Asc 040 61506969 6f777373 50006472 73006100 77007300 72006f00 00006400 00630041 iiPa sswo rd.P .a.s .s.w .o.r .d.. A.c. 060 006f0063 006e0075 004e0074 006d0061 00000065 00720050 006d0069 00720061 c.o. u.n. t.N. a.m. e... P.r. i.m. a.r. 080 00440079 006d006f 00690061 0000006e 0061004e 00690074 00650076 0053004f y.D. o.m. a.i. n... N.a. t.i. v.e. O.S. 0a0 004e0000 00740061 00760069 004c0065 006e0061 0061004d 0000006e ..N. a.t. i.v. e.L. a.n. M.a. n... StufferAC = XwwBana! StufferFloop 'X' StufferFloop 'w' arg=26438 StufferFloop 'w' arg=1 StufferFloop 'b' Wct=4 StufferFloop 'a' stringing = StufferFloop 'n' stringing = \SERver\SHare StufferFloop 'a' stringing = A: StufferFloop '!' arg=34 SMB w/ TREECON&X after stuffing Current size = e9 (233) 000 424d53ff 00000073 80000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB s... .... .... .... .... .... jj.. 020 bc00750d 4d664200 53635678 0e737365 52001000 43647673 7f737061 63734100 .u.. .BfM xVcS ess. ...R svdC aps. .Asc 040 61506969 6f777373 50006472 73006100 77007300 72006f00 00006400 00630041 iiPa sswo rd.P .a.s .s.w .o.r .d.. A.c. 060 006f0063 006e0075 004e0074 006d0061 00000065 00720050 006d0069 00720061 c.o. u.n. t.N. a.m. e... P.r. i.m. a.r. 080 00440079 006d006f 00690061 0000006e 0061004e 00690074 00650076 0053004f y.D. o.m. a.i. n... N.a. t.i. v.e. O.S. 0a0 004e0000 00740061 00760069 004c0065 006e0061 0061004d 0000006e de00ff04 ..N. a.t. i.v. e.L. a.n. M.a. n... .... 0c0 016746de 00002200 005c005c 00450053 00760052 00720065 0053005c 00610048 .Fg. .".. \.\. S.E. R.v. e.r. \.S. H.a. 0e0 00650072 3a410000 00000000 r.e. ..A: . Aligning start of smb cp&m,m,r=00000001 00000003 00000000 Third readcommand status = 0 SMB w/ NTOPEN&X before stuffing Current size = ec (236) 000 424d53ff 00000073 80000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB s... .... .... .... .... .... jj.. 020 bc00750d 4d664200 53635678 0e737365 52001000 43647673 7f737061 63734100 .u.. .BfM xVcS ess. ...R svdC aps. .Asc 040 61506969 6f777373 50006472 73006100 77007300 72006f00 00006400 00630041 iiPa sswo rd.P .a.s .s.w .o.r .d.. A.c. 060 006f0063 006e0075 004e0074 006d0061 00000065 00720050 006d0069 00720061 c.o. u.n. t.N. a.m. e... P.r. i.m. a.r. 080 00440079 006d006f 00690061 0000006e 0061004e 00690074 00650076 0053004f y.D. o.m. a.i. n... N.a. t.i. v.e. O.S. 0a0 004e0000 00740061 00760069 004c0065 006e0061 0061004d 0000006e ec00a204 ..N. a.t. i.v. e.L. a.n. M.a. n... .... 0c0 01674600 00002200 005c005c 00450053 00760052 00720065 0053005c 00610048 .Fg. .".. \.\. S.E. R.v. e.r. \.S. H.a. 0e0 00650072 3a410000 2c2c2c00 r.e. ..A: .,,, StufferAC = XmwdddDdddDddyB StufferFloop 'X' StufferFloop 'm' StufferFloop 'w' arg=20 StufferFloop 'd' arg=1936157766 StufferFloop 'd' arg=1684629060 StufferFloop 'd' arg=1802723661 StufferFloop 'd' arg=544698188 StufferFloop 'd' arg=1751607624 StufferFloop 'd' arg=1651668033 StufferFloop 'd' arg=1667449171 StufferFloop 'd' arg=1886611780 StufferFloop 'd' arg=1853124687 StufferFloop 'd' arg=1819700297 StufferFloop 'y' arg=221 StufferFloop 'b' Wct=24 StufferCloop NewStufferControl=0 SMB w/ NTOPEN&X midway into stuffing Current size = 11f (287) 000 424d53ff 00000073 80000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB s... .... .... .... .... .... jj.. 020 bc00750d 4d664200 53635678 0e737365 52001000 43647673 7f737061 63734100 .u.. .BfM xVcS ess. ...R svdC aps. .Asc 040 61506969 6f777373 50006472 73006100 77007300 72006f00 00006400 00630041 iiPa sswo rd.P .a.s .s.w .o.r .d.. A.c. 060 006f0063 006e0075 004e0074 006d0061 00000065 00720050 006d0069 00720061 c.o. u.n. t.N. a.m. e... P.r. i.m. a.r. 080 00440079 006d006f 00690061 0000006e 0061004e 00690074 00650076 0053004f y.D. o.m. a.i. n... N.a. t.i. v.e. O.S. 0a0 004e0000 00740061 00760069 004c0065 006e0061 0061004d 0000006e ec00a204 ..N. a.t. i.v. e.L. a.n. M.a. n... .... 0c0 01674600 00002200 005c005c 00450053 00760052 00720065 0053005c 00610048 .Fg. .".. \.\. S.E. R.v. e.r. \.S. H.a. 0e0 00650072 3a410000 2c2c2c00 de00ff18 001400de 73676c46 64696644 6b73614d r.e. ..A: .,,, .... .... Flgs Dfid Mask 100 20776f4c 68676948 62727441 63634153 70736944 6e74704f 6c766c49 00facedd Low. High Atrb SAcc Disp Optn Ilvl ... Testing for fit: 0 Fits Testing for fit: 128 Fits Testing for fit: 256 Doesn't Fit Testing for fit: 384 Doesn't Fit Testing for fit: 512 Doesn't Fit Testing for fit: 640 Doesn't Fit Testing for fit: 768 Doesn't Fit Testing for fit: 896 Doesn't Fit Testing for fit: 1024 Doesn't Fit StufferAC = v! StufferFloop 'v' stringing = FileToOpen StufferFloop 'v' aligning StufferFloop '!' arg=21 SMB w/ NTOPEN&X after stuffing Current size = 134 (308) 000 424d53ff 00000073 80000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB s... .... .... .... .... .... jj.. 020 bc00750d 4d664200 53635678 0e737365 52001000 43647673 7f737061 63734100 .u.. .BfM xVcS ess. ...R svdC aps. .Asc 040 61506969 6f777373 50006472 73006100 77007300 72006f00 00006400 00630041 iiPa sswo rd.P .a.s .s.w .o.r .d.. A.c. 060 006f0063 006e0075 004e0074 006d0061 00000065 00720050 006d0069 00720061 c.o. u.n. t.N. a.m. e... P.r. i.m. a.r. 080 00440079 006d006f 00690061 0000006e 0061004e 00690074 00650076 0053004f y.D. o.m. a.i. n... N.a. t.i. v.e. O.S. 0a0 004e0000 00740061 00760069 004c0065 006e0061 0061004d 0000006e ec00a204 ..N. a.t. i.v. e.L. a.n. M.a. n... .... 0c0 01674600 00002200 005c005c 00450053 00760052 00720065 0053005c 00610048 .Fg. .".. \.\. S.E. R.v. e.r. \.S. H.a. 0e0 00650072 3a410000 2c2c2c00 de00ff18 001400de 73676c46 64696644 6b73614d r.e. ..A: .,,, .... .... Flgs Dfid Mask 100 20776f4c 68676948 62727441 63634153 70736944 6e74704f 6c766c49 000015dd Low. High Atrb SAcc Disp Optn Ilvl .... 120 00690046 0065006c 006f0054 0070004f 006e0065 F.i. l.e. T.o. O.p. e.n. Initial SMB Current size = 20 (32) 000 424d53ff 000000ff 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. Initial NTCREATE&X status = 0 SMB w/ NTOPEN&X before stuffing Current size = 20 (32) 000 424d53ff 000000a2 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. StufferAC = XmwdddDdddDddyB StufferFloop 'X' StufferFloop 'm' StufferFloop 'w' arg=22 StufferFloop 'd' arg=1936157766 StufferFloop 'd' arg=1684629060 StufferFloop 'd' arg=1802723661 StufferFloop 'd' arg=544698188 StufferFloop 'd' arg=1751607624 StufferFloop 'd' arg=1651668033 StufferFloop 'd' arg=1667449171 StufferFloop 'd' arg=1886611780 StufferFloop 'd' arg=1853124687 StufferFloop 'd' arg=1819700297 StufferFloop 'y' arg=221 StufferFloop 'b' Wct=24 StufferCloop NewStufferControl=0 SMB w/ NTOPEN&X midway into stuffing Current size = 53 (83) 000 424d53ff 000000a2 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 de00ff18 001600de 73676c46 64696644 6b73614d 20776f4c 68676948 62727441 .... .... Flgs Dfid Mask Low. High Atrb 040 63634153 70736944 6e74704f 6c766c49 00facedd SAcc Disp Optn Ilvl ... Testing for fit: 0 Fits Testing for fit: 128 Fits Testing for fit: 256 Fits Testing for fit: 384 Fits Testing for fit: 512 Doesn't Fit Testing for fit: 640 Doesn't Fit Testing for fit: 768 Doesn't Fit Testing for fit: 896 Doesn't Fit Testing for fit: 1024 Doesn't Fit StufferAC = rv! StufferFloop 'r' regionsize = 0 StufferFloop 'v' stringing = FileToOpen2 StufferFloop 'v' aligning StufferFloop '!' arg=23 SMB w/ NTOPEN&X after stuffing Current size = 6a (106) 000 424d53ff 000000a2 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 de00ff18 001600de 73676c46 64696644 6b73614d 20776f4c 68676948 62727441 .... .... Flgs Dfid Mask Low. High Atrb 040 63634153 70736944 6e74704f 6c766c49 000017dd 00690046 0065006c 006f0054 SAcc Disp Optn Ilvl .... F.i. l.e. T.o. 060 0070004f 006e0065 00000032 O.p. e.n. 2. SMB w/ NTOPEN&X after filename replacement Current size = 6a (106) 000 424d53ff 000000a2 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 de00ff18 001600de 73676c46 64696644 6b73614d 20776f4c 68676948 62727441 .... .... Flgs Dfid Mask Low. High Atrb 040 63634153 70736944 6e74704f 6c766c49 000017dd 00460046 00460046 006f0054 SAcc Disp Optn Ilvl .... F.F. F.F. T.o. 060 0070004f 006e0065 00000033 O.p. e.n. 3. Aligning start of smb cp&m,m,r=00000002 00000003 00000000 Another NTCREATE&X status = 0 SMB w/ NTOPEN&X before stuffing Current size = 6c (108) 000 424d53ff 000000a2 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 6c00a218 00160000 73676c46 64696644 6b73614d 20776f4c 68676948 62727441 ...l .... Flgs Dfid Mask Low. High Atrb 040 63634153 70736944 6e74704f 6c766c49 000017dd 00460046 00460046 006f0054 SAcc Disp Optn Ilvl .... F.F. F.F. T.o. 060 0070004f 006e0065 2c2c0033 O.p. e.n. 3.,, StufferAC = XmwdddDdddDddyB StufferFloop 'X' StufferFloop 'm' StufferFloop 'w' arg=22 StufferFloop 'd' arg=1936157766 StufferFloop 'd' arg=1684629060 StufferFloop 'd' arg=1802723661 StufferFloop 'd' arg=544698188 StufferFloop 'd' arg=1751607624 StufferFloop 'd' arg=1651668033 StufferFloop 'd' arg=1667449171 StufferFloop 'd' arg=1886611780 StufferFloop 'd' arg=1853124687 StufferFloop 'd' arg=1819700297 StufferFloop 'y' arg=221 StufferFloop 'b' Wct=24 StufferCloop NewStufferControl=0 SMB w/ NTOPEN&X midway into stuffing Current size = 9f (159) 000 424d53ff 000000a2 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 6c00a218 00160000 73676c46 64696644 6b73614d 20776f4c 68676948 62727441 ...l .... Flgs Dfid Mask Low. High Atrb 040 63634153 70736944 6e74704f 6c766c49 000017dd 00460046 00460046 006f0054 SAcc Disp Optn Ilvl .... F.F. F.F. T.o. 060 0070004f 006e0065 2c2c0033 de00ff18 001600de 73676c46 64696644 6b73614d O.p. e.n. 3.,, .... .... Flgs Dfid Mask 080 20776f4c 68676948 62727441 63634153 70736944 6e74704f 6c766c49 00facedd Low. High Atrb SAcc Disp Optn Ilvl ... StufferAC = s? StufferFloop 's' arg= StufferFloop '?' out if 0==00000000 SMB w/ NTOPEN&X after alignment Current size = a0 (160) 000 424d53ff 000000a2 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 6c00a218 00160000 73676c46 64696644 6b73614d 20776f4c 68676948 62727441 ...l .... Flgs Dfid Mask Low. High Atrb 040 63634153 70736944 6e74704f 6c766c49 000017dd 00460046 00460046 006f0054 SAcc Disp Optn Ilvl .... F.F. F.F. T.o. 060 0070004f 006e0065 2c2c0033 de00ff18 001600de 73676c46 64696644 6b73614d O.p. e.n. 3.,, .... .... Flgs Dfid Mask 080 20776f4c 68676948 62727441 63634153 70736944 6e74704f 6c766c49 eefacedd Low. High Atrb SAcc Disp Optn Ilvl .... MRxSmbStuffSetByteCount ByteCount=23 SMB w/ NTOPEN&X after filename replacement Current size = a0 (160) 000 424d53ff 000000a2 00000000 00000000 00000000 00000000 fefebaba dead6a6a .SMB .... .... .... .... .... .... jj.. 020 6c00a218 00160000 73676c46 64696644 6b73614d 20776f4c 68676948 62727441 ...l .... Flgs Dfid Mask Low. High Atrb 040 63634153 70736944 6e74704f 6c766c49 000017dd 00460046 00460046 006f0054 SAcc Disp Optn Ilvl .... F.F. F.F. T.o. 060 0070004f 006e0065 2c2c0033 de00ff18 001600de 73676c46 64696644 6b73614d O.p. e.n. 3.,, .... .... Flgs Dfid Mask 080 20776f4c 68676948 62727441 63634153 70736944 6e74704f 6c766c49 ee0017dd Low. High Atrb SAcc Disp Optn Ilvl .... -----------Data size = 16 (22) 0a0 00690046 0065006c 006f0054 0070004f 006e0065 00000032 F.i. l.e. T.o. O.p. e.n. 2.
|