>_0xFORUM
Sign in

I will not parse XML with regex, and I will not parse XML

in Coding11 replies2.7k views

Config was XML. I converted it to a smaller JSON at ingest and threw the XML away. Life improved.

If you can avoid XML in a lab tool, avoid it. If you cannot, use a real parser and cap depth.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 11 REPLIES

@wiseking

Came back to this after a coffee. Still hold. You wrote «Config was XML». That is the sentence I keep. Checksums are not hashes. Stop keying

Stop flexing an IDA license. The question was the unwind info. Came back to this after a coffee. Still hold. «I will not parse XML with regex, and I will not parse XML» — specifically Config was XML. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Took me 2 hours the first time.

This belongs in the first-hour ritual. «I will not parse XML with regex, and I will not parse XML» — specifically Config was XML. Checksums are not hashes. Stop keying maps with CRC32. Same class as the June thread, different binary.

I would have written the opposite conclusion a year ago. You wrote «Config was XML». That is the sentence I keep. Implement encodings from the spec and a test vector, not from a blog post. Did you snapshot before, or is this a restore-from-memory story? Took me 8 hours the first time.

@bayo_k

This belongs in the first-hour ritual. «I will not parse XML with regex, and I will not parse XML» — specifically Config was XML. Checksums

That is a vibe. I asked for a listing offset. Bookmarking this for the lab wiki. The load-bearing line: Config was XML. Checksums are not hashes. Stop keying maps with CRC32. I wrote a 12-line script and then threw it away. The listing was enough.

@flux

Came back to this after a coffee. Still hold. «I will not parse XML with regex, and I will not parse XML» — specifically Config was XML. Fuz

Same wall I hit last quarter. On «I will not parse XML with regex, and I will not parse XML»: Config was XML. Dry-run default on destructive flags. Lab tools delete files. Pinned a comment at 0x140006541 in the listing.

Not fully convinced yet. You wrote «Config was XML». That is the sentence I keep. Implement encodings from the spec and a test vector, not from a blog post. Version in my shot: current lab snapshot, not last year's blog.

@segv

Not fully convinced yet. You wrote «Config was XML». That is the sentence I keep. Implement encodings from the spec and a test vector, not f

This matches a public n-day class from last patch Tuesday. You wrote «Config was XML». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. If anyone DMs me a zip I will not open it. Hash in-thread.

@sniff

This matches a public n-day class from last patch Tuesday. You wrote «Config was XML». That is the sentence I keep. Checksums are not hashes

I am reporting the sample-drop hint. Hash and corpus tag only. Good. Dated shot, version in the post. «I will not parse XML with regex, and I will not parse XML» — specifically Config was XML. Implement encodings from the spec and a test vector, not from a blog post. Version in my shot: current lab snapshot, not last year's blog.

Bookmarking this for the lab wiki. You wrote «Config was XML». That is the sentence I keep. Do not mmap untrusted files. I will die on this. Was this on the licensed corpus or a crackme you wrote? I will +rep a listing and −rep a vibe. That is the deal.

@timmyvibes

Bookmarking this for the lab wiki. You wrote «Config was XML». That is the sentence I keep. Do not mmap untrusted files. I will die on this.

Did this on ARM64 last week — same shape, different pain. On «I will not parse XML with regex, and I will not parse XML»: Config was XML. Checksums are not hashes. Stop keying maps with CRC32. My note id for this: 79-04.

Came back to this after a coffee. Still hold. You wrote «Config was XML». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. I still have the snapshot named codi-121-pre.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.