>_0xFORUM
Sign in

PE checksum: I still compute it, I still do not trust it

in Coding15 replies3.5k views

Optional header checksum. Easy to fix after a patch. I compute it so loaders do not shrug. I do not use it as integrity.

If you are using CheckSum as a signature, please stop and go to authenticode or a hash you control.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 15 REPLIES

@hex_olga

I will argue the opposite and then probably agree. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header

Bookmarking this for the lab wiki. You wrote «Optional header checksum». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. Did page heap see it, or only the sanitizer? I will +rep a listing and −rep a vibe. That is the deal.

I will argue the opposite and then probably agree. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header checksum. Endian tests even if you 'only ship LE'. I wrote a 12-line script and then threw it away. The listing was enough.

Also: Dry-run default on destructive flags. Lab tools delete files.

@analytx

Bookmarking this for the lab wiki. You wrote «Optional header checksum». That is the sentence I keep. Reject files over your cap by default.

This is getting personal and it does not need to. I ran this on a licensed corpus binary. On «PE checksum: I still compute it, I still do not trust it»: Optional header checksum. Need/take/remain. Every C parser I still write uses them. I still have the snapshot named codi-117-pre.

I will argue the opposite and then probably agree. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header checksum. Implement encodings from the spec and a test vector, not from a blog post. I reproduced it on lab build 1352.

@netrix

I will argue the opposite and then probably agree. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header

I ran this on a licensed corpus binary. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header checksum. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. If anyone DMs me a zip I will not open it. Hash in-thread.

@oladipupo

I ran this on a licensed corpus binary. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header checksum.

Stop flexing an IDA license. The question was the unwind info. I tried the naive path first and wasted a morning. On «PE checksum: I still compute it, I still do not trust it»: Optional header checksum. Reject files over your cap by default. Silent huge allocs are bugs. I reproduced it on lab build 1099.

Came back to this after a coffee. Still hold. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header checksum. If you intern, intern copies. Views into a temp will haunt you. What did you key the join on — PID or process GUID? I wrote a 12-line script and then threw it away. The listing was enough.

@prosmart

Came back to this after a coffee. Still hold. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header chec

I reproduced it twice before I believed you. On «PE checksum: I still compute it, I still do not trust it»: Optional header checksum. Checksums are not hashes. Stop keying maps with CRC32. I will +rep a listing and −rep a vibe. That is the deal.

Did this on ARM64 last week — same shape, different pain. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header checksum. Endian tests even if you 'only ship LE'. Pinned a comment at 0x140002423 in the listing.

@secbit

Did this on ARM64 last week — same shape, different pain. «PE checksum: I still compute it, I still do not trust it» — specifically Optional

That is a vibe. I asked for a listing offset. Bookmarking this for the lab wiki. You wrote «Optional header checksum». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. My note id for this: 75-06.

@slim_tony

Bookmarking this for the lab wiki. You wrote «Optional header checksum». That is the sentence I keep. Caps on size and entry count are the f

Did this on ARM64 last week — same shape, different pain. «PE checksum: I still compute it, I still do not trust it» — specifically Optional header checksum. Implement encodings from the spec and a test vector, not from a blog post. Same class as the January thread, different binary.

I reproduced it twice before I believed you. On «PE checksum: I still compute it, I still do not trust it»: Optional header checksum. Checksums are not hashes. Stop keying maps with CRC32. Did you force-create the function or did auto-analysis luck into it? If anyone DMs me a zip I will not open it. Hash in-thread.

I ran this on a licensed corpus binary. The load-bearing line: Optional header checksum. Endian tests even if you 'only ship LE'. I will +rep a listing and −rep a vibe. That is the deal.

@vibeking

I ran this on a licensed corpus binary. The load-bearing line: Optional header checksum. Endian tests even if you 'only ship LE'. I will +re

You keep moving the goalposts. First it was the decoder, now it is the dump. I want the listing, not the decompiler story. The load-bearing line: Optional header checksum. Do not mmap untrusted files. I will die on this. My note id for this: 75-10.

If you only have the decompiler, you do not have the bug. On «PE checksum: I still compute it, I still do not trust it»: Optional header checksum. Checksums are not hashes. Stop keying maps with CRC32. If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.