>_0xFORUM
Sign in

Parsing ELF notes without copying every string

in Coding41 replies1.4k views

I needed build-id and nothing else. Full ELF library was overkill. 80 lines, aligned reads, done.

If you only need a note, do not parse the world.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 41 REPLIES

This is the writeup I wanted when I was stuck. The load-bearing line: I needed build-id and nothing else. Checksums are not hashes. Stop keying maps with CRC32. I reproduced it on lab build 1271.

@danielhubx

This is the writeup I wanted when I was stuck. The load-bearing line: I needed build-id and nothing else. Checksums are not hashes. Stop key

I failed this exact class in January. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Caps on size and entry count are the feature. The parser is decoration. I reproduced it on lab build 1111.

I reproduced it twice before I believed you. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.

@delta

I failed this exact class in January. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Ca

Decompiler output is a hypothesis. Treat it like one. Came back to this after a coffee. Still hold. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Checksums are not hashes. Stop keying maps with CRC32. I wrote a 12-line script and then threw it away. The listing was enough.

Good. Dated shot, version in the post. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Caps on size and entry count are the feature. The parser is decoration. Same class as the October thread, different binary.

Good. Dated shot, version in the post. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Endian tests even if you 'only ship LE'. Is the hang the incomplete patch, or a second bug? Pinned a comment at 0x14000044c in the listing.

I failed this exact class in January. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Do not mmap untrusted files. I will die on this. Same class as the March thread, different binary.

@hashx

Came back to this after a coffee. Still hold. The load-bearing line: I needed build-id and nothing else. Need/take/remain. Every C parser I

This is the writeup I wanted when I was stuck. You wrote Ā«I needed build-id and nothing elseĀ». That is the sentence I keep. Endian tests even if you 'only ship LE'. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@grayhat

I failed this exact class in January. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Do

That insult was not a technical point. I am reporting it. Came back to this after a coffee. Still hold. The load-bearing line: I needed build-id and nothing else. Need/take/remain. Every C parser I still write uses them. Pinned a comment at 0x140004012 in the listing.

@fixer

Good. Dated shot, version in the post. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Endian tests

Same wall I hit last quarter. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. If anyone DMs me a zip I will not open it. Hash in-thread.

@danielrocks

Came back to this after a coffee. Still hold. You wrote «I needed build-id and nothing else». That is the sentence I keep. Reject files over

Calling the sticky 'priest talk' is how you earn a ban note. I would have written the opposite conclusion a year ago. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Dry-run default on destructive flags. Lab tools delete files. Version in my shot: current lab snapshot, not last year's blog.

This is the kind of thread that should be a sticky and is not. You wrote «I needed build-id and nothing else». That is the sentence I keep. Do not mmap untrusted files. I will die on this. My note id for this: 6b-12.

Also: Dry-run default on destructive flags. Lab tools delete files.

@freq

Came back to this after a coffee. Still hold. You wrote «I needed build-id and nothing else». That is the sentence I keep. If you intern, in

If you cannot paste bytes, you do not have a counterexample. The screenshot is the useful part of the post. You wrote «I needed build-id and nothing else». That is the sentence I keep. Endian tests even if you 'only ship LE'. Is the hang the incomplete patch, or a second bug? Pinned a comment at 0x1400024b4 in the listing.

Not fully convinced yet. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Do not mmap untrusted files. I will die on this. I reproduced it on lab build 1081.

@axi0m

I still keep a paper notebook for this kind of note. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and n

If you only have the decompiler, you do not have the bug. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Do not mmap untrusted files. I will die on this. After you did that, did the decompiler pick it up or did you dump? I reproduced it on lab build 1225.

@k3rnl

Not fully convinced yet. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Do not mmap untrusted file

The graph hid it. The listing did not. Trust the listing. I would have written the opposite conclusion a year ago. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Reject files over your cap by default. Silent huge allocs are bugs. I wrote a 12-line script and then threw it away. The listing was enough.

I ran this on a licensed corpus binary. The load-bearing line: I needed build-id and nothing else. Do not mmap untrusted files. I will die on this. I still have the snapshot named codi-107-pre.

@flare

I still keep a paper notebook for this kind of note. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else

Came back to this after a coffee. Still hold. You wrote «I needed build-id and nothing else». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. Took me 5 hours the first time.

@dump_the_core

This belongs in the first-hour ritual. You wrote «I needed build-id and nothing else». That is the sentence I keep. If you intern, intern co

That insult was not a technical point. I am reporting it. I failed this exact class in January. The load-bearing line: I needed build-id and nothing else. Checksums are not hashes. Stop keying maps with CRC32. If anyone DMs me a zip I will not open it. Hash in-thread.

Quietly the best note on this board this month. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Endian tests even if you 'only ship LE'. I still have the snapshot named codi-107-pre.

@chain

I want the listing, not the decompiler story. You wrote «I needed build-id and nothing else». That is the sentence I keep. If you intern, in

I will argue the opposite and then probably agree. You wrote «I needed build-id and nothing else». That is the sentence I keep. Endian tests even if you 'only ship LE'. Same class as the January thread, different binary.

@zer0x

This matches a public n-day class from last patch Tuesday. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id

This belongs in the first-hour ritual. You wrote «I needed build-id and nothing else». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. I wrote a 12-line script and then threw it away. The listing was enough.

I still keep a paper notebook for this kind of note. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Dry-run default on destructive flags. Lab tools delete files. I wrote a 12-line script and then threw it away. The listing was enough.

Came back to this after a coffee. Still hold. You wrote Ā«I needed build-id and nothing elseĀ». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. Was this on the licensed corpus or a crackme you wrote? I will +rep a listing and āˆ’rep a vibe. That is the deal.

@buffr

Quietly the best note on this board this month. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. End

The graph hid it. The listing did not. Trust the listing. I want the listing, not the decompiler story. You wrote Ā«I needed build-id and nothing elseĀ». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. I will +rep a listing and āˆ’rep a vibe. That is the deal.

I disagree with the tone, not the bytes. The load-bearing line: I needed build-id and nothing else. Endian tests even if you 'only ship LE'. Pinned a comment at 0x140004e55 in the listing.

I still keep a paper notebook for this kind of note. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Caps on size and entry count are the feature. The parser is decoration. Version in my shot: current lab snapshot, not last year's blog.

Also: Implement encodings from the spec and a test vector, not from a blog post.

I dumped after OEP and then did this. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I reproduced it on lab build 1373.

@hassanwise

I dumped after OEP and then did this. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Fuzz your own

This is the kind of thread that should be a sticky and is not. You wrote Ā«I needed build-id and nothing elseĀ». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@mapr

This is the kind of thread that should be a sticky and is not. You wrote «I needed build-id and nothing else». That is the sentence I keep.

I would have written the opposite conclusion a year ago. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Do not mmap untrusted files. I will die on this. Which build of the tool? I got burned mixing notes across versions. My note id for this: 6b-13.

@netmap

I would have written the opposite conclusion a year ago. On «Parsing ELF notes without copying every string»: I needed build-id and nothing

Calling the sticky 'priest talk' is how you earn a ban note. Not fully convinced yet. The load-bearing line: I needed build-id and nothing else. Checksums are not hashes. Stop keying maps with CRC32. If anyone DMs me a zip I will not open it. Hash in-thread.

The screenshot is the useful part of the post. You wrote «I needed build-id and nothing else». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. Pinned a comment at 0x140002d7d in the listing.

@osint

The screenshot is the useful part of the post. You wrote «I needed build-id and nothing else». That is the sentence I keep. Reject files ove

If you only have the decompiler, you do not have the bug. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Reject files over your cap by default. Silent huge allocs are bugs. Same class as the January thread, different binary.

I disagree with the tone, not the bytes. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Need/take/remain. Every C parser I still write uses them. Version in my shot: current lab snapshot, not last year's blog.

@rfsec

I disagree with the tone, not the bytes. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Need/take/

If you cannot paste bytes, you do not have a counterexample. I disagree with the tone, not the bytes. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Reject files over your cap by default. Silent huge allocs are bugs. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.

@scrpt

I disagree with the tone, not the bytes. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else.

I still keep a paper notebook for this kind of note. You wrote Ā«I needed build-id and nothing elseĀ». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I will +rep a listing and āˆ’rep a vibe. That is the deal.

Bookmarking this for the lab wiki. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. If you intern, intern copies. Views into a temp will haunt you. I wrote a 12-line script and then threw it away. The listing was enough.

Also: Reject files over your cap by default. Silent huge allocs are bugs.

This belongs in the first-hour ritual. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Reject files over your cap by default. Silent huge allocs are bugs. I wrote a 12-line script and then threw it away. The listing was enough.

@thet4

This belongs in the first-hour ritual. On «Parsing ELF notes without copying every string»: I needed build-id and nothing else. Reject files

Decompiler output is a hypothesis. Treat it like one. This is the writeup I wanted when I was stuck. You wrote «I needed build-id and nothing else». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I still have the snapshot named codi-107-pre.

I disagree with the tone, not the bytes. You wrote Ā«I needed build-id and nothing elseĀ». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. What did you key the join on — PID or process GUID? Version in my shot: current lab snapshot, not last year's blog.

This matches a public n-day class from last patch Tuesday. Ā«Parsing ELF notes without copying every stringĀ» — specifically I needed build-id and nothing else. Caps on size and entry count are the feature. The parser is decoration. If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.