I am starting to wonder... can anybody at all do a syscall::NtCreateFile:entry probe in dtrace that print the filename attempted opened without getting "dtrace: processing aborted: Illegal byte sequence" within the first minute. If you can- i would love to see how
-
Show this thread
-
Replying to @jonasLyk
Just a random guess: can it be that it does not handle FILE_OPEN_BY_FILE_ID correctly and tries to interpret its binary input as a string?
1 reply 0 retweets 0 likes -
Replying to @diversenok_zero
Ive also thought about that- but it fails with somethng beginning with {146F1A80-4791-11D0-A5D6-28DB04C10000}
1 reply 0 retweets 0 likes
Replying to @jonasLyk @diversenok_zero
must be thispic.twitter.com/u8ticbuC8U
1:55 PM - 25 Jan 2021
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.