>_0xFORUM
Sign in

Error enums vs strings in lab tools — I switched back to strings

in Coding13 replies2.9k views

I had a 40-variant error enum. Nobody matched on it. Display impl was the product. I went back to a string + a code.

Enums are for APIs. Lab tools are not APIs until they are.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 13 REPLIES

If you only have the decompiler, you do not have the bug. Ā«Error enums vs strings in lab tools — I switched back to stringsĀ» — specifically I had a 40-variant error enum. Checksums are not hashes. Stop keying maps with CRC32. I reproduced it on lab build 1379.

@lukmanfresh

If you only have the decompiler, you do not have the bug. Ā«Error enums vs strings in lab tools — I switched back to stringsĀ» — specifically

Decompiler output is a hypothesis. Treat it like one. Agreed on the class, not on the tool. On Ā«Error enums vs strings in lab tools — I switched back to stringsĀ»: I had a 40-variant error enum. Implement encodings from the spec and a test vector, not from a blog post. Same class as the January thread, different binary.

I want the listing, not the decompiler story. The load-bearing line: I had a 40-variant error enum. Dry-run default on destructive flags. Lab tools delete files. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@nova

I want the listing, not the decompiler story. The load-bearing line: I had a 40-variant error enum. Dry-run default on destructive flags. La

This is getting personal and it does not need to. Agreed on the class, not on the tool. You wrote «I had a 40-variant error enum». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. Which build of the tool? I got burned mixing notes across versions. If anyone DMs me a zip I will not open it. Hash in-thread.

@opzsec

Agreed on the class, not on the tool. You wrote «I had a 40-variant error enum». That is the sentence I keep. Caps on size and entry count a

I disagree with the tone, not the bytes. You wrote «I had a 40-variant error enum». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. Same class as the June thread, different binary.

@ports

I disagree with the tone, not the bytes. You wrote «I had a 40-variant error enum». That is the sentence I keep. Caps on size and entry coun

That insult was not a technical point. I am reporting it. Agreed on the class, not on the tool. On Ā«Error enums vs strings in lab tools — I switched back to stringsĀ»: I had a 40-variant error enum. Checksums are not hashes. Stop keying maps with CRC32. Took me 7 hours the first time.

I disagree with the tone, not the bytes. The load-bearing line: I had a 40-variant error enum. Checksums are not hashes. Stop keying maps with CRC32. My note id for this: 74-06.

@samueljay

I disagree with the tone, not the bytes. The load-bearing line: I had a 40-variant error enum. Checksums are not hashes. Stop keying maps wi

I am reporting the sample-drop hint. Hash and corpus tag only. This is the writeup I wanted when I was stuck. The load-bearing line: I had a 40-variant error enum. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Took me 9 hours the first time.

Please keep the hashes and drop the mystery zips. You wrote Ā«I had a 40-variant error enumĀ». That is the sentence I keep. Dry-run default on destructive flags. Lab tools delete files. What did you key the join on — PID or process GUID? I wrote a 12-line script and then threw it away. The listing was enough.

@sp4rk

Please keep the hashes and drop the mystery zips. You wrote «I had a 40-variant error enum». That is the sentence I keep. Dry-run default on

The graph hid it. The listing did not. Trust the listing. I still keep a paper notebook for this kind of note. The load-bearing line: I had a 40-variant error enum. Do not mmap untrusted files. I will die on this. Same class as the March thread, different binary.

@sysx

I still keep a paper notebook for this kind of note. The load-bearing line: I had a 40-variant error enum. Do not mmap untrusted files. I wi

If you only have the decompiler, you do not have the bug. On Ā«Error enums vs strings in lab tools — I switched back to stringsĀ»: I had a 40-variant error enum. If you intern, intern copies. Views into a temp will haunt you. Version in my shot: current lab snapshot, not last year's blog.

@uptownkid

If you only have the decompiler, you do not have the bug. On Ā«Error enums vs strings in lab tools — I switched back to stringsĀ»: I had a 40-

Stop flexing an IDA license. The question was the unwind info. This matches a public n-day class from last patch Tuesday. The load-bearing line: I had a 40-variant error enum. Checksums are not hashes. Stop keying maps with CRC32. My note id for this: 74-11.

I dumped after OEP and then did this. The load-bearing line: I had a 40-variant error enum. Implement encodings from the spec and a test vector, not from a blog post. I still have the snapshot named codi-116-pre.

Also: Endian tests even if you 'only ship LE'.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.