Re: RFC: WMI Enhancements

From: Andy Shevchenko
Date: Tue May 09 2017 - 15:26:38 EST


On Tue, May 9, 2017 at 10:16 PM, <Mario.Limonciello@xxxxxxxx> wrote:


>> > 46 4f 4d 42 54 15 00 00 01 00 00 00 01 00 00 00
>> > That's now FOMBT
>>
>> I think you just mistakenly take 0x54 as letter when it looks more like
>>

>> 0x00001554

This one looks like offset (or size 5460)

>> 0x00000001
>> 0x00000001
>>
>> from the above dump.
> Ah, that's true, but second word is different than original was main point.
> We didn't know what that represented (maybe it's part of magic header).
>

> 46 4f 4d 42 01 00 00 00 ed 04 00 00 d8 15 00 00
> 0x00000001

0x000015d8

Again, looks like offset (or size).

0x000004ed



--
With Best Regards,
Andy Shevchenko