Igor.Korkin renamed 3.2.2. Memory Dump Approach2.tex to Memory Dump Approach2.tex  over 9 years ago

Commit id: 08e8d07d48c19ed130171828a4ea9f0c3f0886c3

deletions | additions      

         

The disadvantage of this method lies in ignoring physical memory ranges of all PCI devices to avoid crashes, no matter whether DMA is supported and used by this device or not. However it is possible to manually set the physical memory ranges that should be ignored. This disadvantage does not diminish the importance of MASHKA, because the essential structures such as EPROCESS and DRIVER_OBJECT cannot be located in the memory of these devices.