>_0xFORUM
Sign in

When serde is the bug, not the data

in Coding7 replies2.8k views

A deny_unknown_fields struct and a vendor added a field. We failed closed in a good way, then I had to ship a permit.

Fail closed in parsers. Fail open in product managers.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 7 REPLIES

Good. Dated shot, version in the post. On «When serde is the bug, not the data»: A deny_unknown_fields struct and a vendor added a field. Do not mmap untrusted files. I will die on this. Pinned a comment at 0x140006707 in the listing.

I will argue the opposite and then probably agree. You wrote «A deny_unknown_fields struct and a vendor added a field». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Hash of the public file, or are we arguing a shape? Same class as the October thread, different binary.

@ethanzone

Good. Dated shot, version in the post. On «When serde is the bug, not the data»: A deny_unknown_fields struct and a vendor added a field. Do

I reproduced it twice before I believed you. You wrote «A deny_unknown_fields struct and a vendor added a field». That is the sentence I keep. Endian tests even if you 'only ship LE'. I still have the snapshot named codi-109-pre.

@index

This is the kind of thread that should be a sticky and is not. «When serde is the bug, not the data» — specifically A deny_unknown_fields st

This is getting personal and it does not need to. Came back to this after a coffee. Still hold. You wrote «A deny_unknown_fields struct and a vendor added a field». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. My note id for this: 6d-06.

@foren

I reproduced it twice before I believed you. You wrote «A deny_unknown_fields struct and a vendor added a field». That is the sentence I kee

You keep moving the goalposts. First it was the decoder, now it is the dump. I dumped after OEP and then did this. On «When serde is the bug, not the data»: A deny_unknown_fields struct and a vendor added a field. Do not mmap untrusted files. I will die on this. I still have the snapshot named codi-109-pre.

@h4sh

I will argue the opposite and then probably agree. You wrote «A deny_unknown_fields struct and a vendor added a field». That is the sentence

I dumped after OEP and then did this. «When serde is the bug, not the data» — specifically A deny_unknown_fields struct and a vendor added a field. Dry-run default on destructive flags. Lab tools delete files. I wrote a 12-line script and then threw it away. The listing was enough.

This is the kind of thread that should be a sticky and is not. «When serde is the bug, not the data» — specifically A deny_unknown_fields struct and a vendor added a field. Dry-run default on destructive flags. Lab tools delete files. Version in my shot: current lab snapshot, not last year's blog.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.