Log in

View Full Version : Frank Grossman's last words about SoftIce


separator
May 14th, 2008, 21:07
Frank Grossman is one of founders of Numega. I almost cry when I read it at: hxxp://blogs.msdn.com/matt_pietrek/archive/2006/04/11/573621.aspx

Very nice last words:

And only about 6 months from his 20th birthday.

But we should remember the good times.

He was born with a fairly short and energetic labor. Born back in the simple days of a 386s chip with 512K memory. He was a very skinny baby, fitting on a 360K floppy, and a little shy always hiding away in the upper part of memory where no one could find him. Although shy he started to getting around quickly. Moving from DOS to Win 3.0 then a big date in ‘Chicago’. His popularity grew to the point that even songs where written about him, ‘The Soft-ICE blues’. And finally showing up in a ‘New Technology’ where no one thought he could live. He was fickle at times, dating a lot of different symbol engines along the way and picking up friends wearing strange ‘Underware’. He became a little confused as he left the nest; trying to be hip, doing the 64bit thing and was even seen cross dressing in a GUI.


But as his parents;
SI = ‘JM’
DI = ‘FG’

We will always be proud of him and what he accomplished for the world, in a time when the OS changed every 2 years and drivers were a combination of science and art.

We would like to thank all those who helped him along during his life!

In his memory we ask that you always keep CTRL-D unassigned on your keyboard.


Frank & Jim

naides
May 14th, 2008, 21:22
Amen

JMI
May 14th, 2008, 21:58
"Least we forget," this "Obit" was published on MSDN by Matt Pietrek on:

Tuesday, April 11, 2006 3:48 PM

Apparently Separator was more than a little late to the funeral!

Regards,

Kayaker
May 14th, 2008, 22:30
I remember seeing that, still funny. There is one slight forgivable mistake however.

Quote:

But as his parents;
SI = ‘JM’
DI = ‘FG’


The Int3 - FGJM interface was used as a backdoor in the DOS versions. SI = 'FG', DI = 'JM', AH = service number.

It's still (was still?) incorporated in the DS32 code as an external interface with cpthook.sys, though it's execution appears to be short circuited:

Code:

:000137FF extern_FGJM: ; CODE XREF: :00014E99
:000137FF ; DATA XREF: InterfaceWithCptHook+14E
:000137FF cld
:00013800 call sub_17EEE
:00013805 cmp cs:fVER_TOUCH, 1
:0001380D jnz short loc_13810
:0001380F retn
:00013810 ; ---------------------------------------------------------------------------
:00013810
:00013810 loc_13810: ; CODE XREF: :0001380D
:00013810 call sub_15989
:00013815 pop ss:ntoskrnl_KiTrap03
:0001381C cmp si, 4647h ; FG
:00013821 jnz short loc_1384D
:00013823 cmp di, 4A4Dh ; JM
:00013828 jnz short loc_1384D
:0001382A call CheckServiceNumber
:0001382F jnb short loc_13847
:00013831 mov dBreakReason, 10004h ; BREAK_SYMBOL_LOADER
:0001383B mov byte_ED605, 0
:00013842 call sub_1421A
:00013847
:00013847 loc_13847: ; CODE XREF: :0001382F
:00013847 call sub_1592C
:0001384C iret


It seems F.G. forgot their secret identities and which one was SI and which was DI. It should actually be

Quote:

But as his parents;
SI = ‘FG’ (Frank Grossman)
DI = ‘JM’ (Jim Moskun)

JMI
May 14th, 2008, 23:22
Kayaker always has the "inside" information.

Regards,

separator
May 15th, 2008, 07:36
Yes, I am little bit late But yesterday I searched for some info about SoftIce and Windows Vista. Only interesting thing which I found was this last words. SoftIce is dead and there is nothing to replace it. I want to debug all processes in same time at Windows Vista, because my process inject to all processes where is possible loads. I think this scenario is not possible debugg with OllyDbg or other Ring3 debugger. Yesterday I tried Syser Debugger but it doesn't load in Windows Vista under VM Ware I hope they will update it soon because it looks like promising project. I will try WinDbg but I don't like it I think if they release SoftIce sources then some people with reborn it and update it for Windows Vista. Last years were not easy for SoftIce, maybe it need new parents It is shame to leave HIM dead alone!!!

Aimless
May 16th, 2008, 01:28
Wonder what +ORC and he are discussing in the big cracking house up there....

HAve Phun

kugi
May 16th, 2008, 01:42
Where does Kayaker get all this information?

Regards, kugi

dELTA
May 16th, 2008, 03:06
Quote:
[Originally Posted by kugi;74650]Where does Kayaker get all this information?
Simply by doing what this board is about, i.e. reversing the crap out of stuff.

JMI
May 16th, 2008, 06:49
Just use the Advanced Search and enter softice and Kayaker and you will see his reversing/analysis of softice over the years.

Regards,

Kayaker
May 16th, 2008, 17:18
aka "get a life!"

JMI
May 16th, 2008, 18:03
And, if you can't, reverse one.

Regards,

Woodmann
May 16th, 2008, 23:03
Ummmmmmmmmmmm.........

Thats pretty harsh. Do I need to suspend you bastards for being pricks?
(notice no smilies)

Woodmann

Kayaker
May 16th, 2008, 23:50
BWAHAHAHAA

I get suspended for a self-deprecating joke about my wasted youth spent reversing Softice?

I meant nothing else..

JMI
May 17th, 2008, 02:01
And I get suspended for recognizing Kayaker's joke and "reversing" it.

Regards,

Woodmann
May 17th, 2008, 18:32
Well then...........

I guess I should have SEARCHED before I typed .

Wood

Kayaker
May 18th, 2008, 01:06
No worries, one of the built-in hazards of the internet is misinterpreting what someone says (especially obtuse jokes which I'm partial to).

Don't worry, I don' be dissin' my homey's choice of playtime activity. You down wit dat, b?

JMI
May 18th, 2008, 01:13
Heck...we don't even care whether they do it with their left hand or their right hand....

.....

.....

I was talking about "mousing."

What were YOU thinking I was talking about???

Regards,