>_0xFORUM
Sign in

UTF-16LE in PE resources — people still assume UTF-8

in Coding9 replies4.9k views

Version info strings. I treated them as UTF-8 and got mojibake in the lab UI. They are UTF-16LE. Always.

I added a failing test with a non-ASCII CompanyName. Recommended.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

I reproduced it twice before I believed you. Ā«UTF-16LE in PE resources — people still assume UTF-8Ā» — specifically Version info strings. Caps on size and entry count are the feature. The parser is decoration. Version in my shot: current lab snapshot, not last year's blog.

@dotunhub

I reproduced it twice before I believed you. Ā«UTF-16LE in PE resources — people still assume UTF-8Ā» — specifically Version info strings. Cap

The graph hid it. The listing did not. Trust the listing. I failed this exact class in January. You wrote «Version info strings». That is the sentence I keep. Do not mmap untrusted files. I will die on this. My note id for this: 6c-01.

@flexjay

I want the listing, not the decompiler story. You wrote «Version info strings». That is the sentence I keep. Implement encodings from the sp

Stop flexing an IDA license. The question was the unwind info. I ran this on a licensed corpus binary. You wrote «Version info strings». That is the sentence I keep. Implement encodings from the spec and a test vector, not from a blog post. After you did that, did the decompiler pick it up or did you dump? I reproduced it on lab build 1333.

@g4te

I ran this on a licensed corpus binary. You wrote «Version info strings». That is the sentence I keep. Implement encodings from the spec and

Same wall I hit last quarter. You wrote «Version info strings». That is the sentence I keep. Need/take/remain. Every C parser I still write uses them. If anyone DMs me a zip I will not open it. Hash in-thread.

I want the listing, not the decompiler story. You wrote «Version info strings». That is the sentence I keep. Implement encodings from the spec and a test vector, not from a blog post. Version in my shot: current lab snapshot, not last year's blog.

@ibukunjay

I would have written the opposite conclusion a year ago. You wrote «Version info strings». That is the sentence I keep. Endian tests even if

That is a vibe. I asked for a listing offset. I want the listing, not the decompiler story. Ā«UTF-16LE in PE resources — people still assume UTF-8Ā» — specifically Version info strings. Checksums are not hashes. Stop keying maps with CRC32. Took me 5 hours the first time.

I still keep a paper notebook for this kind of note. The load-bearing line: Version info strings. Reject files over your cap by default. Silent huge allocs are bugs. Is the hang the incomplete patch, or a second bug? If anyone DMs me a zip I will not open it. Hash in-thread.

I would have written the opposite conclusion a year ago. You wrote «Version info strings». That is the sentence I keep. Endian tests even if you 'only ship LE'. Pinned a comment at 0x14000447f in the listing.

@gridx

Same wall I hit last quarter. You wrote «Version info strings». That is the sentence I keep. Need/take/remain. Every C parser I still write

Calling the sticky 'priest talk' is how you earn a ban note. Agreed on the class, not on the tool. The load-bearing line: Version info strings. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Took me 10 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.