Microsoft符号服务器已联机,但不知何故,我无法下载任何符号。
我试着把它缩小到跟随POC。它应该只下载aadtb.dll的符号,但它返回一个HTTP_STATUS_NOT_FOUND。
symchk /v /r c:windowssystem32aadtb.dll /s SRV*c:symbols*https://msdl.microsoft.com/download/symbols
或者,我尝试使用以下不同的Powershell方法下载pdb,但这也返回了404消息
$url = "https://msdl.microsoft.com/download/symbols/aadtb.pdb/BC45F7DA843249FFA96D9396BEE5F35D1/aadtb.pdb"
$output = "c:test.pdb"
(New-Object System.Net.WebClient).DownloadFile($url, $output)
Invoke-WebRequest -Uri $url -OutFile $output
Start-BitsTransfer -Source $url -Destination $output
我仍然怀疑自己有问题,但请注意,我确实在两台不同的机器上尝试过,并通过了3个不同的VPN隧道,结果都是一样的上周五,25/10在一台完全不同的机器上工作
在完全疯狂之前,有人能验证他们是否还能下载符号,最好是我提到的符号吗?
编辑
kernel32.dll和ntdll给出了相同的结果为简洁起见剪切了
symchk /v c:windowssystem32kernel32.dll /s SRV*c:symbols*https://msdl.microsoft.com/download/symbols
symchk /v c:windowssystem32ntdll.dll /s SRV*c:symbols*https://msdl.microsoft.com/download/symbols
SYMSRV: HTTPGET: /download/symbols/kernel32.pdb/5A77DE8CE8D58731F0EA38F1C92F48D81/kernel32.pdb
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/ntdll.pdb/0C2E19EA1901E9B82E4567D2D21E56D21/ntdll.pdb
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
编辑2
c:Program Files (x86)Windows Kits10Debuggersx64>ver
Microsoft Windows [Version 10.0.18362.418]
symchk的输出
SRV*c:symbols*http://msdl.microsoft.com/download/symbols
[SYMCHK] Searching for symbols to c:windowssystem32aadtb.dll in path SRV*c:symbols*http://msdl.microsoft.com/download/symbols
DBGHELP: Symbol Search Path: SRV*c:symbols*http://msdl.microsoft.com/download/symbols
[SYMCHK] Using search path "SRV*c:symbols*http://msdl.microsoft.com/download/symbols"
DBGHELP: No header for c:windowssystem32aadtb.dll. Searching for image on disk
DBGHELP: c:windowssystem32aadtb.dll - OK
SYMSRV: BYINDEX: 0x1
c:symbols*http://msdl.microsoft.com/download/symbols
aadtb.pdb
BC45F7DA843249FFA96D9396BEE5F35D1
SYMSRV: UNC: c:symbolsaadtb.pdbBC45F7DA843249FFA96D9396BEE5F35D1aadtb.pdb - path not found
SYMSRV: UNC: c:symbolsaadtb.pdbBC45F7DA843249FFA96D9396BEE5F35D1aadtb.pd_ - path not found
SYMSRV: UNC: c:symbolsaadtb.pdbBC45F7DA843249FFA96D9396BEE5F35D1file.ptr - path not found
SYMSRV: HTTPGET: /download/symbols/index2.txt
SYMSRV: HttpQueryInfo: 80190190 - HTTP_STATUS_BAD_REQUEST
SYMSRV: HTTPGET: /download/symbols/aadtb.pdb/BC45F7DA843249FFA96D9396BEE5F35D1/aadtb.pdb
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/aadtb.pdb/BC45F7DA843249FFA96D9396BEE5F35D1/aadtb.pd_
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/aadtb.pdb/BC45F7DA843249FFA96D9396BEE5F35D1/file.ptr
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: RESULT: 0x80190194
DBGHELP: aadtb - no symbols loaded
[SYMCHK] MODULE64 Info ----------------------
[SYMCHK] Struct size: 1680 bytes
[SYMCHK] Base: 0x0000000180000000
[SYMCHK] Image size: 1986560 bytes
[SYMCHK] Date: 0x5c901636
[SYMCHK] Checksum: 0x001eadb3
[SYMCHK] NumSyms: 0
[SYMCHK] SymType: SymNone
[SYMCHK] ModName: aadtb
[SYMCHK] ImageName: c:windowssystem32aadtb.dll
[SYMCHK] LoadedImage: c:windowssystem32aadtb.dll
[SYMCHK] PDB: ""
[SYMCHK] CV: RSDS
[SYMCHK] CV DWORD: 0x53445352
[SYMCHK] CV Data: aadtb.pdb
[SYMCHK] PDB Sig: 0
[SYMCHK] PDB7 Sig: {BC45F7DA-8432-49FF-A96D-9396BEE5F35D}
[SYMCHK] Age: 1
[SYMCHK] PDB Matched: TRUE
[SYMCHK] DBG Matched: TRUE
[SYMCHK] Line nubmers: FALSE
[SYMCHK] Global syms: FALSE
[SYMCHK] Type Info: FALSE
[SYMCHK] ------------------------------------
SymbolCheckVersion 0x00000002
Result 0x00010001
DbgFilename aadtb.dbg
DbgTimeDateStamp 0x00000000
DbgSizeOfImage 0x00000000
DbgChecksum 0x00000000
PdbFilename aadtb.pdb
PdbSignature {BC45F7DA-8432-49FF-A96D-9396BEE5F35D}
PdbDbiAge 0x00000001
[SYMCHK] [ 0x00000000 - 0x00010001 ] Checked "c:windowssystem32aadtb.dll"
SYMCHK: aadtb.dll FAILED - aadtb.pdb mismatched or not found
SYMCHK: FAILED files = 1
SYMCHK: PASSED + IGNORED files = 0
Powershell下载方法的输出
Exception calling "DownloadFile" with "2" argument(s): "The remote server returned an error: (404) Not Found."
At line:4 char:1
+ (New-Object System.Net.WebClient).DownloadFile($url, $output)
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [], MethodInvocationException
+ FullyQualifiedErrorId : WebException
Invoke-WebRequest : The remote server returned an error: (404) Not Found.
At line:5 char:1
+ Invoke-WebRequest -Uri $url -OutFile $output
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebException
+ FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand
Start-BitsTransfer : HTTP status 404: The requested URL does not exist on the server.
At line:6 char:1
+ Start-BitsTransfer -Source $url -Destination $output
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (:) [Start-BitsTransfer], Exception
+ FullyQualifiedErrorId : StartBitsTransferCOMException,Microsoft.BackgroundIntelligentTransfer.Management.NewBitsTransferCommand
它看起来像是微软的SNAFU。所以,是的,就像@RbMm指出的那样,给WinDbgFb@microsoft.com让他们知道。也许也可以发推给Andy Luhrs。请记住,这是一个小团队,他们可能要到周一才能做任何事情(在美国(
服务器上根本不存在该文件。
这能帮你吗?