<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="fr">
	<id>https://futex.re/mediawiki/index.php?action=history&amp;feed=atom&amp;title=5.6._Analyse_d%27un_dump</id>
	<title>5.6. Analyse d&#039;un dump - Historique des versions</title>
	<link rel="self" type="application/atom+xml" href="https://futex.re/mediawiki/index.php?action=history&amp;feed=atom&amp;title=5.6._Analyse_d%27un_dump"/>
	<link rel="alternate" type="text/html" href="https://futex.re/mediawiki/index.php?title=5.6._Analyse_d%27un_dump&amp;action=history"/>
	<updated>2026-04-18T02:51:24Z</updated>
	<subtitle>Historique des versions pour cette page sur le wiki</subtitle>
	<generator>MediaWiki 1.39.17</generator>
	<entry>
		<id>https://futex.re/mediawiki/index.php?title=5.6._Analyse_d%27un_dump&amp;diff=2034&amp;oldid=prev</id>
		<title>Futex le 25 janvier 2013 à 09:39</title>
		<link rel="alternate" type="text/html" href="https://futex.re/mediawiki/index.php?title=5.6._Analyse_d%27un_dump&amp;diff=2034&amp;oldid=prev"/>
		<updated>2013-01-25T09:39:30Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Nouvelle page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Analyser un dump mdb -k $KERNEL $CORE&lt;br /&gt;
&lt;br /&gt;
  # mdb -k unix.0 vmcore.0&lt;br /&gt;
  Loading modules: [ unix genunix specfs dtrace ufs ssd fcp fctl emlxs px md mpt sd isp mpt_sas ip hook neti sctp arp usba nca zfs cpc random   crypto wrsmd fcip logindmux ptm sppp nfs ipc lofs ]&lt;br /&gt;
  &amp;gt; $C&lt;br /&gt;
  000002a10efd0771 vpanic(0, 3, 7af45ee0, 2a10efd1178, 47bd8a00, 7af45ee0)&lt;br /&gt;
  000002a10efd0841 zfs_panic_recover+0x38(7af45ee0, 24, 4b6, 600, 3, 0)&lt;br /&gt;
  000002a10efd08f1 dmu_buf_hold_array_by_dnode+0xa8(5, 0, 2000, 1, 7af3b93e, 1)&lt;br /&gt;
  000002a10efd09b1 dmu_read+0xcc(500000, a, 0, 2000, 800003ccdc3ce000, 7af3b800)&lt;br /&gt;
  000002a10efd0a81 zfs_fillpage+0xf0(2000, 0, 601497bb6b0, 0, 2a10efd1760, 2000)&lt;br /&gt;
  000002a10efd0b61 zfs_getpage+0x15c(60102888ac0, 601497bb6b0, 1, 0, 2a10efd1760, 2000)&lt;br /&gt;
  000002a10efd0c41 zfs_shim_getpage+0x40(60102888ac0, 0, 3003b482160, 1, ff380000, 1)&lt;br /&gt;
  000002a10efd0d21 fop_getpage+0x44(60102888ac0, 600a26396c0, 3003b482160, 1, ff380000, 1)&lt;br /&gt;
  000002a10efd0df1 segvn_fault+0xb00(2000, 601497bb6b0, 1, 2000, 0, 0)&lt;br /&gt;
  000002a10efd0fc1 as_fault+0x4c8(601497bb6b0, 30070873738, ff380000, 3007c751468, 18e8e70, 0)&lt;br /&gt;
  000002a10efd10d1 pagefault+0xac(ff380000, 0, 1, 0, 3007c7513f0, 1)&lt;br /&gt;
  000002a10efd1191 trap+0xd50(2a10efd1b90, ff3802e0, 0, 1, 115f8, 0)&lt;br /&gt;
  000002a10efd12e1 utl0+0x4c(ff3803c4, ff380000, ffbff10c, 0, 3c6, 24400)&lt;br /&gt;
  &amp;gt; ::panicinfo&lt;br /&gt;
             cpu                4&lt;br /&gt;
          thread      3003cc0b080&lt;br /&gt;
         message zfs: accessing past end of object 24/4b6 (size=1536 access=0+8192)&lt;br /&gt;
          tstate       4400001601&lt;br /&gt;
              g1         7aefced4&lt;br /&gt;
              g2             2000&lt;br /&gt;
              g3         7af45c00&lt;br /&gt;
              g4      600b4411640&lt;br /&gt;
              g5      600b4f8e1c0&lt;br /&gt;
              g6                1&lt;br /&gt;
              g7      3003cc0b080&lt;br /&gt;
              o0         7af45ee0&lt;br /&gt;
              o1      2a10efd1178&lt;br /&gt;
              o2          1892260&lt;br /&gt;
              o3      30055788270&lt;br /&gt;
              o4               16&lt;br /&gt;
              o5                0&lt;br /&gt;
              o6      2a10efd0771&lt;br /&gt;
              o7          114fc78&lt;br /&gt;
              pc          104bbec&lt;br /&gt;
             npc          104bbf0&lt;br /&gt;
               y                0&lt;br /&gt;
  &amp;gt; 3003cc0b080::thread -p&lt;br /&gt;
            ADDR             PROC              LWP             CRED&lt;br /&gt;
  000003003cc0b080      30055788270      30070873738      3003b482160&lt;br /&gt;
  &amp;gt; 30055788270::ps -ft&lt;br /&gt;
  S    PID   PPID   PGID    SID    UID      FLAGS             ADDR NAME&lt;br /&gt;
  R    991    990    533    533      0 0x4a004000 0000030055788270 tail -1 ./log/100_GENERAL_001_SOLARIS.log&lt;br /&gt;
        T     0x3003cc0b080 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
  &amp;gt; 0000030055788270::ptree&lt;br /&gt;
  0000000001892260  sched&lt;br /&gt;
     00000600a17c1088  init&lt;br /&gt;
          000006013e7fe5d0  sshd&lt;br /&gt;
               000006017c3d9918  sshd&lt;br /&gt;
                    000006014f660db8  sshd&lt;br /&gt;
                         000006013e68f2a8  op&lt;br /&gt;
                              000003009eed7b30  cks_0exe.sh&lt;br /&gt;
                                   00000600d36e9968  cut&lt;br /&gt;
                                        0000030055788270  tail&lt;br /&gt;
  &amp;gt; ::zone&lt;br /&gt;
            ADDR     ID NAME                 PATH&lt;br /&gt;
  00000000019406f8      0 global               /&lt;br /&gt;
  000006011dbb5980     28 ${VM_NAME}               /${VM_NAME}/root/&lt;br /&gt;
  00000600d51ab1c0     29 ${VM_NAME}               /${VM_NAME}/root/&lt;br /&gt;
  00000301195e3840     36 ${VM_NAME}               /${VM_NAME}/root/&lt;br /&gt;
  0000060182056fc0     37 ${VM_NAME}             /${VM_NAME}/root/&lt;br /&gt;
  0000060182055980     40 ${VM_NAME}               /${VM_NAME}/root/&lt;br /&gt;
  &amp;gt; 0000030055788270::print proc_t!grep p_zone&lt;br /&gt;
    p_zone = 0x6011dbb5980&lt;br /&gt;
  &amp;gt; ::ps -ft&lt;br /&gt;
  S    PID   PPID   PGID    SID    UID      FLAGS             ADDR NAME&lt;br /&gt;
  R      0      0      0      0      0 0x00000001 0000000001892260 sched&lt;br /&gt;
        T                t0 &amp;lt;TS_STOPPED&amp;gt;&lt;br /&gt;
  R      3      0      0      0      0 0x00020001 00000600a17bf848 fsflush&lt;br /&gt;
        T     0x3001171d3a0 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
  R      2      0      0      0      0 0x00020001 00000600a17c0468 pageout&lt;br /&gt;
        T     0x3001171d6e0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R      1      0      0      0      0 0x4a004000 00000600a17c1088 /sbin/init&lt;br /&gt;
        T     0x3001171da20 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R  29877      1  29877  29877      0 0x5a006400 00000300560242b8 /soft/UniQPT/programs/servers/xprinter ptip92&lt;br /&gt;
        T     0x30051698a00 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R   1263      1  29289  29289  44322 0x5a004400 00000300412b0700 bpbkar -L /usr/openv/netbackup/logs/user_ops/dbext    /logs/vxbsa.1330837519.191.pr&lt;br /&gt;
        T     0x301f41ced20 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
  R   1218      1  29289  29289  44322 0x5a004400 0000030179eea648 bpbkar -L /usr/openv/netbackup/logs/user_ops/dbext/logs/vxbsa.1330837519.191.pr&lt;br /&gt;
        T     0x300a137d1a0 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
  R   1186      1  29289  29289  44322 0x5a004400 0000030089472158 bpbkar -L /usr/openv/netbackup/logs/user_ops/dbext/logs/vxbsa.1330837519.191.pr&lt;br /&gt;
        T     0x3003e3655a0 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
  R   1172      1  29289  29289  44322 0x5a004400 00000300d0970338 bpbkar -L /usr/openv/netbackup/logs/user_ops/dbext/logs/vxbsa.1330837519.191.pr&lt;br /&gt;
        T     0x3009d23b8c0 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
  R   1093      1  29289  29289  44322 0x5a004400 000006010fb57270 bpbkar -L /usr/openv/netbackup/logs/user_ops/dbext/logs/vxbsa.1330837519.191.pr&lt;br /&gt;
        T     0x3021752cb40 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    859      1  29289  29289  44322 0x5a004400 0000030166904d20 bpbkar -L /usr/openv/netbackup/logs/user_ops/dbext/logs/vxbsa.1330837519.191.pr&lt;br /&gt;
        T     0x30028262540 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    188      1  26455  26455  44322 0x4a004400 00000301639719d8 /usr/sap/PO1/SYS/exe/run/brconnect -S 26455&lt;br /&gt;
        T     0x3010127a5c0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  Z    300    188    300    300  44322 0x4a004002 000003005616da90 oraclePO1 (DESCRIPTION=(LOCAL=YES)(ADDRESS=(PROTOCOL=beq)))&lt;br /&gt;
  R  26353      1  26353  26353      0 0x4a004400 000006016cdec130 bphdb -sb -rdbms sap -S pyasej -to 3600 -c pyasg7_isapbw_po1 -s FULL -clnt pyas&lt;br /&gt;
        T     0x30069a92020 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R  26354  26353  26353  26353      0 0x4a004000 00000300d09ae4b8 /bin/sh /users/nbk00/exploit/script/nbk_0ls.sh &amp;gt;/dev/null 2&amp;gt;/dev/null&lt;br /&gt;
        T     0x300fcea60e0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R  26361  26354  26353  26353      0 0x4a004000 0000030166513960 /bin/sh /users/nbk00/exploit/script/nbk_0os.sh&lt;br /&gt;
        T     0x30011f8a500 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R  26381  26361  26353  26353  44322 0x4a014000 00000300fc5c3990 -csh -c  setenv SAP_SERVER pyasej; setenv SAP_CLASS pyasg7_isapbw_po1; brbackup&lt;br /&gt;
        T     0x300a25b8440 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R  26455  26381  26455  26455  44322 0x4a004000 000003016690cd10 brbackup -c force -u / -p initPO1.sapdata.offline.bw.sap -m all&lt;br /&gt;
        T     0x300a05fa460 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    190  26455  26455  26455  44322 0x4a004000 000006014f6619d8 sh -c ( /usr/sap/PO1/SYS/exe/run/backint -u PO1 -f backup -i /oracle/PO1/sapbac&lt;br /&gt;
        T     0x300c7167540 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    191    190  26455  26455  44322 0x4a004000 00000600a2dc0c60 /usr/sap/PO1/SYS/exe/run/backint -u PO1 -f backup -i /oracle/PO1/sapbackup/.bei&lt;br /&gt;
        T     0x301fdfef7a0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    203    191  26455  26455  44322 0x42000000 00000300d09a24d0 /usr/sap/PO1/SYS/exe/run/backint -u PO1 -f backup -i /oracle/PO1/sapbackup/.bei&lt;br /&gt;
        T     0x3009f65c840 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    202    191  26455  26455  44322 0x42000000 00000600d2769950 /usr/sap/PO1/SYS/exe/run/backint -u PO1 -f backup -i /oracle/PO1/sapbackup/.bei&lt;br /&gt;
        T     0x3001295e3e0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    201    191  26455  26455  44322 0x42000000 000003013d6fe230 /usr/sap/PO1/SYS/exe/run/backint -u PO1 -f backup -i /oracle/PO1/sapbackup/.bei&lt;br /&gt;
        T     0x3006a298de0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    200    191  26455  26455  44322 0x42000000 000003016690c0f0 /usr/sap/PO1/SYS/exe/run/backint -u PO1 -f backup -i /oracle/PO1/sapbackup/.bei&lt;br /&gt;
        T     0x300a1ade700 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    199    191  26455  26455  44322 0x42000000 000006010f8cc200 /usr/sap/PO1/SYS/exe/run/backint -u PO1 -f backup -i /oracle/PO1/sapbackup/.bei&lt;br /&gt;
        T     0x30158d96220 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R    198    191  26455  26455  44322 0x42000000 00000300878c6ca8 /usr/sap/PO1/SYS/exe/run/backint -u PO1 -f backup -i /oracle/PO1/sapbackup/.bei&lt;br /&gt;
        T     0x3003750bc80 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R   5441      1   5441   5441   9009 0x4a004400 0000030166921908 oracleDSM00 (DESCRIPTION=(LOCAL=no)(ADDRESS=(PROTOCOL=BEQ)))&lt;br /&gt;
        T     0x3015e54d6c0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R   5439      1   5439   5439   9009 0x4a004400 00000300d09fe518 oracleDSM00 (DESCRIPTION=(LOCAL=no)(ADDRESS=(PROTOCOL=BEQ)))&lt;br /&gt;
        T     0x300837bc760 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R   5437      1   5437   5437   9009 0x4a004400 00000300d099d8b8 oracleDSM00 (DESCRIPTION=(LOCAL=no)(ADDRESS=(PROTOCOL=BEQ)))&lt;br /&gt;
        T     0x301fb7f5040 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R   5435      1   5435   5435   9009 0x4a004400 00000600d2b7c118 oracleDSM00 (DESCRIPTION=(LOCAL=no)(ADDRESS=(PROTOCOL=B&lt;br /&gt;
        T     0x300bf51eb20 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  R   5433      1   5433   5433   9009 0x4a004400 00000300fa9be250 oracleDSM00 (DESCRIPTION=(LOCAL=no)(ADDRESS=(PROTOCOL=B&lt;br /&gt;
        T     0x300114614c0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  &amp;gt; 30055788270::ps&lt;br /&gt;
  S    PID   PPID   PGID    SID    UID      FLAGS             ADDR NAME&lt;br /&gt;
  R    991    990    533    533      0 0x4a004000 0000030055788270 tail&lt;br /&gt;
  &amp;gt; $&lt;br /&gt;
  &amp;gt; 30055788270::ps -aef&lt;br /&gt;
  mdb: illegal option -- a&lt;br /&gt;
  Usage: ps [-fltzTP]&lt;br /&gt;
  &amp;gt; 30055788270::ps -fltz&lt;br /&gt;
  S    PID   PPID   PGID    SID  ZONE    UID      FLAGS             ADDR NAME&lt;br /&gt;
  R    991    990    533    533    28      0 0x4a004000 0000030055788270 tail -1 ./log/100_GENERAL_001_SOLARIS.log&lt;br /&gt;
        T     0x3003cc0b080 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
        L     0x30070873738 ID: 1&lt;br /&gt;
  &amp;gt; ::ps&lt;br /&gt;
  &amp;gt; ::zone&lt;br /&gt;
            ADDR     ID NAME                 PATH &lt;br /&gt;
  00000000019406f8      0 global               /&lt;br /&gt;
  000006011dbb5980     28 ${VM_NAME}               /${VM_NAME}/root/&lt;br /&gt;
  00000600d51ab1c0     29 ${VM_NAME}               /${VM_NAME}/root/&lt;br /&gt;
  00000301195e3840     36 ${VM_NAME}               /${VM_NAME}/root/&lt;br /&gt;
  0000060182056fc0     37 ${VM_NAME}             /${VM_NAME}/root/&lt;br /&gt;
  0000060182055980     40 ${VM_NAME}               /${VM_NAME}/root/ &lt;br /&gt;
  &amp;gt; 0000030055788270::print proc_t!grep p_zone&lt;br /&gt;
    p_zone = 0x6011dbb5980&lt;br /&gt;
  &amp;gt; 30055788270::ps -fltzT&lt;br /&gt;
  S    PID   PPID   PGID    SID  TASK  ZONE    UID      FLAGS             ADDR NAME&lt;br /&gt;
  R    991    990    533    533 359639    28      0 0x4a004000 0000030055788270 tail -1 ./log/100_GENERAL_001_SOLARIS.log&lt;br /&gt;
        T     0x3003cc0b080 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
        L     0x30070873738 ID: 1&lt;br /&gt;
  &amp;gt; 30055788270::ps -fltzTP&lt;br /&gt;
  S    PID   PPID   PGID    SID  TASK  PROJ  ZONE    UID      FLAGS             ADDR NAME&lt;br /&gt;
  R    991    990    533    533 359639     3    28      0 0x4a004000 0000030055788270 tail -1 ./log/100_GENERAL_001_SOLARI&lt;br /&gt;
        T     0x3003cc0b080 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
        L     0x30070873738 ID: 1&lt;br /&gt;
&lt;br /&gt;
Autre exemple:&lt;br /&gt;
&lt;br /&gt;
  ll&lt;br /&gt;
  &amp;gt; ::panicinfo&lt;br /&gt;
  cpu 7&lt;br /&gt;
  thread fffffebbd3ce2c60&lt;br /&gt;
  message BAD TRAP: type=e (#pf Page fault) rp=fffffe8011496c40 addr=c96610d2 occurred in module &amp;quot;unix&amp;quot; due to an illegal access to a user address&lt;br /&gt;
  rdi c96610d2&lt;br /&gt;
  rsi fffffeb60b4418d0&lt;br /&gt;
  rdx fffffebbd3ce2c60&lt;br /&gt;
  rcx fffffeb60b4418d0&lt;br /&gt;
  r8 0&lt;br /&gt;
  r9 0&lt;br /&gt;
  rax 71&lt;br /&gt;
  rbx c96610d2&lt;br /&gt;
  rbp fffffe8011496d50&lt;br /&gt;
  r10 34&lt;br /&gt;
  r10 34&lt;br /&gt;
  r11 fffffffffbd18460&lt;br /&gt;
  r12 ffffffffa0e3f600&lt;br /&gt;
  r13 ffffff286cd33bb8&lt;br /&gt;
  r14 d&lt;br /&gt;
  r15 fffffe8011496e50&lt;br /&gt;
  fsbase ffffffff80000000&lt;br /&gt;
  gsbase ffffffffa4c2a000&lt;br /&gt;
  ds 43&lt;br /&gt;
  es 43&lt;br /&gt;
  fs 0&lt;br /&gt;
  gs 1c3&lt;br /&gt;
  trapno e&lt;br /&gt;
  err 0&lt;br /&gt;
  rip fffffffffb836310&lt;br /&gt;
  cs 28&lt;br /&gt;
  rflags 10206&lt;br /&gt;
  rsp fffffe8011496d38&lt;br /&gt;
  ss 30&lt;br /&gt;
  gdt_hi 0&lt;br /&gt;
  gdt_lo defacedd&lt;br /&gt;
  idt_hi 0&lt;br /&gt;
  idt_lo d0000fff&lt;br /&gt;
  ldt 0&lt;br /&gt;
  task 60&lt;br /&gt;
  cr0 80050033&lt;br /&gt;
  cr2 c96610d2&lt;br /&gt;
  cr3 182c345000&lt;br /&gt;
  &amp;gt; fffffebbd3ce2c60::thread -p&lt;br /&gt;
  ADDR PROC LWP CRED&lt;br /&gt;
  fffffebbd3ce2c60 fffffeb2a09488d8 ffffff60d65de0b0 fffffeb62b0d0830&lt;br /&gt;
  &amp;gt; fffffeb2a09488d8::ps -ft&lt;br /&gt;
  S PID PPID PGID SID UID FLAGS ADDR NAME&lt;br /&gt;
  R 23089 23087 141 141 0 0x4a004000 fffffeb2a09488d8 format /dev/rdsk/c0t60050768018E826F5000000000000C58d0s2&lt;br /&gt;
  T 0xfffffebbd3ce2c60 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
  T 0xfffffeb266c698c0 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  T 0xfffffeb2a4e4b760 &amp;lt;TS_SLEEP&amp;gt;&lt;br /&gt;
  T 0xfffffed3808538c0 &amp;lt;TS_ONPROC&amp;gt;&lt;br /&gt;
  &amp;gt; fffffeb2a09488d8::ptree&lt;br /&gt;
  fffffffffbc27720 sched&lt;br /&gt;
  ffffffffa3745348 init&lt;br /&gt;
  fffffeb271dcd6f0 Lance_get_all.sh&lt;br /&gt;
  fffffeb29d9058f8 get_disques.sh&lt;br /&gt;
  fffffeb25ee0e1f0 dc&lt;br /&gt;
  fffffeb2a09488d8 format &lt;br /&gt;
  &amp;gt; fffffeb271dcd6f0::ps -ft&lt;br /&gt;
  S PID PPID PGID SID UID FLAGS ADDR NAME&lt;br /&gt;
  R 19197 1 141 141 0 0x4a004000 fffffeb271dcd6f0 ${ICI SERA LE NOM DU PROCESS}&lt;br /&gt;
  T 0xfffffeb2d5d8c780 &amp;lt;TS_SLEEP&amp;gt;&lt;/div&gt;</summary>
		<author><name>Futex</name></author>
	</entry>
</feed>