Hi there,
According to this wiki page:
kernel virtual addresses start at 0xC0000000 and go to 0xFFFFFFFF
In your slides I saw you try to find sys_call_table within 0xc0000000~0xd0000000. I wonder why we should stop at 0xd0000000 instead of 0xFFFFFFFF?
Thanks