Slow start of a systemd unit implemented in .NET
In this post I would like to describe my recent experience of troubleshooting a slow-starting systemd unit implemented in .NET. While Linux troubleshooting is still new territory for me, I am...
View ArticleTroubleshooting slow writes to a Samba share
I host my research/test Windows VMs on Linux, using Samba to share files between systems. One day, while debugging a problem in WinDbg, the debugger froze on loading symbols for combase.dll. I knew...
View ArticleImplementing a native function detour in C#
A few weeks ago I published Detours.Win32Metadata Nuget package containing a Win32 metadata for the detours library. When you combine it with CsWin32, you may easily generate PInvoke signatures for...
View ArticleUpdating PE file imports on process start
When we need to change the PE file imports, we might either modify the binary file in the file system or perform updates after it has been loaded to the memory. In this post, I will focus on the...
View ArticleGenerating C# bindings for native Windows libraries
When writing system applications in C# we often need to interact with the system APIs directly. And it has always been a challenge to write proper PInvoke signatures. However, with the introduction of...
View ArticleTroubleshooting NT_STATUS_ACCESS_DENIED from Samba on Manjaro Linux
A few months ago, I switched my main desktop to Manjaro, and I’m glad about it. Manjaro Linux is a polished and well-designed Linux distribution. As I like simplicity and a minimalistic approach, I...
View ArticleCOM+ revisited
More than ten years ago (how time flies!), when I published the basic sample of a COM+ server and client, I thought that I wouldn’t be touching this subject again. But here we are, in 2022, and I have...
View ArticleNew releases of my open-source tools
I made several updates to my open-source tools in the last four weeks, and I also released one new tool. In this post, I will describe those updates briefly, including some discoveries I made along...
View Article.NET Diagnostics Expert course
Last week we published the final module of the .NET Diagnostics Expert Course: I’m excited and happy that it’s finally available. But I’m also relieved as there were times when I thought it would...
View ArticleSnooping on .NET EventPipes
While playing with EventPipes, I wanted to better understand the Diagnostic IPC Protocol. This protocol is used to transfer diagnostic data between the .NET runtime and a diagnostic client, such as,...
View ArticleHow Visual Studio debugs containerized apps
Recently, I was looking into the internals of the Visual Studio debugger for the .NET Diagnostics Expert course. I was especially interested in how the Docker debugging works. For those of you who...
View ArticleA CPU sampling profiler in less than 200 lines
While working on a new version of wtrace, I am analyzing the PerfView source code to learn how its various features work internally. One of such features is the call stack resolution for ETW events....
View ArticleMonitoring registry activity with ETW
If you are working on Windows, you know that the registry is a crucial component of this system. It contains lots of system and application configuration data. Apps use the registry to access some of...
View ArticleFixing empty paths in FileIO events (ETW)
This month marks ten years since I started this blog . On this occasion, I would like to thank you for being my reader! Let’s celebrate with a new post on ETW Empty paths issue in the wtrace output...
View ArticleDecrypting PerfView’s OSExtensions.cs file
While analyzing the PerfView source code, I stumbled upon an interesting README file in the src/OSExtensions folder: // The OSExtensions.DLL is a DLL that contains a small number of extensions // to...
View ArticleHow Ansible impersonates users on Windows
Recently, I hit an interesting error during a deployment orchestrated by Ansible. One of the deployment steps was to execute a custom .NET application. Unfortunately, the application was failing on...
View ArticleWtrace 2.2
On the occasion of releasing wtrace 2.2, I decided to write a short post about new functionalities I added to this tool in the recent months. I hope you will find them interesting. Wtrace is a command...
View ArticlePerforming Padding Oracle Attack from PowerShell
In the previous post we created a sample ASP.NET application, which performs encryption in an old, unsecured way (without signature). Its source code is available in my blog samples repository. To run...
View ArticleCase of Unresolvable IPv4 Addresses in IIS
One of my colleagues at work was struggling with a peculiar problem on his machine. Whenever he tried to access the address of his test project: http://my.project:8080 he was getting connection refused...
View ArticleExtracting Service Principal Credentials in VSTS
When we need to deploy an application to Azure from VSTS (Visual Studio Team Services), we use the Azure tasks prepared by Microsoft. These tasks require a contributor account in Azure AD to make...
View Article