Case, You get a Dump from a live proudction Server, (which has some performance problem for some real cusomters. ), at first you want to dump out all the requests that the server is handling.
Her is a how to tutorial.
| #List all Requests 0:030> !DumpHeap -type System.Web.HttpRequest -short |
here , we get the Request address. let’s pick any of them. like 0e7810bc
| !do 0e7810bc # Dump the object WebRequest 0:030> !do 0e77ebb0 |
in this request 0e77ebb0 , the _Url in red above is not null. the Address of the Url is
0e7810bc , this space is stored as the base object address 0e77ebb0 +48 Offset.
when you run dd 0e77ebb0 +48 l 1
| 0:030> dd 0e77ebb0 +48 l 1 |
then Inspect the Url object which is located in 0e7810bc
| !do 0e7810bc 0:030> !do 0e7810bc |
then dumpobject 0e781110 , which you can get this value from base address+C
| 0:030> !do 0e781110 |
here we get url. whole process is get the addressof Request, then get the address of URL by inspecting the memory offset 48. Get the URl Address B. then inspect B+offset c, get the string value.
When can put all into a foreach command.
| 0:030> .foreach (req {!DumpHeap -type System.Web.HttpRequest -short}) { .foreach /pS 1 (a {dd ${req}+48 l 1}) {.echo ${a}; !do poi(${a}+c)} } |
here we get all the ongoing request urls.
if you get errors like
00000000
Invalid parameter poi(00000000+c)
00000000
Invalid parameter poi(00000000+c)
00000000
Invalid parameter poi(00000000+c)
00000000
Invalid parameter poi(00000000+c)
that means the application itself never query the url of the request. by default the _Url is keeped as binary format in the IISworkrequest.
