>_0xFORUM
Sign in

Don't roll your own base64, except I did, and here is why it failed

in Coding15 replies4.2k views

Whitespace in the alphabet. Padding rules. A URL-safe variant in one file. I used a crate after the third bug.

The 'why' was 'I wanted fewer deps'. The cost was three bugs. Deps won.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 15 REPLIES

This is the writeup I wanted when I was stuck. The load-bearing line: Whitespace in the alphabet. Endian tests even if you 'only ship LE'. I reproduced it on lab build 1271.

@jaydenhub

I would have written the opposite conclusion a year ago. On «Don't roll your own base64, except I did, and here is why it failed»: Whitespac

I am reporting the sample-drop hint. Hash and corpus tag only. If you only have the decompiler, you do not have the bug. «Don't roll your own base64, except I did, and here is why it failed» — specifically Whitespace in the alphabet. Endian tests even if you 'only ship LE'. Hash of the public file, or are we arguing a shape? Version in my shot: current lab snapshot, not last year's blog.

@hexlab

This is the writeup I wanted when I was stuck. The load-bearing line: Whitespace in the alphabet. Endian tests even if you 'only ship LE'. I

That insult was not a technical point. I am reporting it. This is the writeup I wanted when I was stuck. You wrote «Whitespace in the alphabet». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. Took me 8 hours the first time.

I would have written the opposite conclusion a year ago. On «Don't roll your own base64, except I did, and here is why it failed»: Whitespace in the alphabet. Caps on size and entry count are the feature. The parser is decoration. Same class as the March thread, different binary.

@kernl

If you only have the decompiler, you do not have the bug. «Don't roll your own base64, except I did, and here is why it failed» — specifical

I would have written the opposite conclusion a year ago. You wrote «Whitespace in the alphabet». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. If anyone DMs me a zip I will not open it. Hash in-thread.

Agreed on the class, not on the tool. You wrote «Whitespace in the alphabet». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. Version in my shot: current lab snapshot, not last year's blog.

@lambda

I would have written the opposite conclusion a year ago. You wrote «Whitespace in the alphabet». That is the sentence I keep. Checksums are

The graph hid it. The listing did not. Trust the listing. This is the kind of thread that should be a sticky and is not. On «Don't roll your own base64, except I did, and here is why it failed»: Whitespace in the alphabet. Implement encodings from the spec and a test vector, not from a blog post. If anyone DMs me a zip I will not open it. Hash in-thread.

@modelz

Agreed on the class, not on the tool. You wrote «Whitespace in the alphabet». That is the sentence I keep. Checksums are not hashes. Stop ke

Stop flexing an IDA license. The question was the unwind info. I still keep a paper notebook for this kind of note. You wrote «Whitespace in the alphabet». That is the sentence I keep. Dry-run default on destructive flags. Lab tools delete files. I still have the snapshot named codi-112-pre.

Please keep the hashes and drop the mystery zips. «Don't roll your own base64, except I did, and here is why it failed» — specifically Whitespace in the alphabet. Caps on size and entry count are the feature. The parser is decoration. Did you force-create the function or did auto-analysis luck into it? I will +rep a listing and −rep a vibe. That is the deal.

@omegax

Please keep the hashes and drop the mystery zips. «Don't roll your own base64, except I did, and here is why it failed» — specifically White

Calling the sticky 'priest talk' is how you earn a ban note. Did this on ARM64 last week — same shape, different pain. The load-bearing line: Whitespace in the alphabet. Caps on size and entry count are the feature. The parser is decoration. Same class as the January thread, different binary.

@pivotr

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Whitespace in the alphabet. Caps on size and entry count ar

Please keep the hashes and drop the mystery zips. On «Don't roll your own base64, except I did, and here is why it failed»: Whitespace in the alphabet. Implement encodings from the spec and a test vector, not from a blog post. I will +rep a listing and −rep a vibe. That is the deal.

@realchris

Please keep the hashes and drop the mystery zips. On «Don't roll your own base64, except I did, and here is why it failed»: Whitespace in th

That is a vibe. I asked for a listing offset. This is the writeup I wanted when I was stuck. The load-bearing line: Whitespace in the alphabet. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I will +rep a listing and −rep a vibe. That is the deal.

I reproduced it twice before I believed you. «Don't roll your own base64, except I did, and here is why it failed» — specifically Whitespace in the alphabet. Endian tests even if you 'only ship LE'. My note id for this: 70-12.

Also: Need/take/remain. Every C parser I still write uses them.

@shadow

I reproduced it twice before I believed you. «Don't roll your own base64, except I did, and here is why it failed» — specifically Whitespace

If you cannot paste bytes, you do not have a counterexample. Same wall I hit last quarter. «Don't roll your own base64, except I did, and here is why it failed» — specifically Whitespace in the alphabet. Implement encodings from the spec and a test vector, not from a blog post. Can you quote the offset instead of the graph screenshot? Version in my shot: current lab snapshot, not last year's blog.

I failed this exact class in January. You wrote «Whitespace in the alphabet». That is the sentence I keep. Need/take/remain. Every C parser I still write uses them. My note id for this: 70-14.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.