>_0xFORUM
Sign in

CRC32 as a hash and other crimes

in Coding24 replies1k views

Someone used CRC32 to key a map of modules. Collisions in the lab corpus. I switched to blake3 truncated.

Checksums are not hashes. Hashes are not checksums. Stop mixing them in titles.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 24 REPLIES

I want the listing, not the decompiler story. The load-bearing line: Someone used CRC32 to key a map of modules. Caps on size and entry count are the feature. The parser is decoration. I wrote a 12-line script and then threw it away. The listing was enough.

@brute

I want the listing, not the decompiler story. The load-bearing line: Someone used CRC32 to key a map of modules. Caps on size and entry coun

I disagree with the tone, not the bytes. The load-bearing line: Someone used CRC32 to key a map of modules. Dry-run default on destructive flags. Lab tools delete files. I wrote a 12-line script and then threw it away. The listing was enough.

If you only have the decompiler, you do not have the bug. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map of modules. Implement encodings from the spec and a test vector, not from a blog post. Did you snapshot before, or is this a restore-from-memory story? Same class as the October thread, different binary.

@calebwise

I disagree with the tone, not the bytes. The load-bearing line: Someone used CRC32 to key a map of modules. Dry-run default on destructive f

You keep moving the goalposts. First it was the decoder, now it is the dump. This is the writeup I wanted when I was stuck. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map of modules. Checksums are not hashes. Stop keying maps with CRC32. I wrote a 12-line script and then threw it away. The listing was enough.

@coolheaded

If you only have the decompiler, you do not have the bug. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map

Came back to this after a coffee. Still hold. The load-bearing line: Someone used CRC32 to key a map of modules. Need/take/remain. Every C parser I still write uses them. Took me 9 hours the first time.

Did this on ARM64 last week — same shape, different pain. You wrote «Someone used CRC32 to key a map of modules». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. Took me 6 hours the first time.

@injectx

This belongs in the first-hour ritual. The load-bearing line: Someone used CRC32 to key a map of modules. Reject files over your cap by defa

Agreed on the class, not on the tool. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Dry-run default on destructive flags. Lab tools delete files. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1320.

This is the writeup I wanted when I was stuck. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Checksums are not hashes. Stop keying maps with CRC32. After you did that, did the decompiler pick it up or did you dump? Took me 10 hours the first time.

The screenshot is the useful part of the post. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Endian tests even if you 'only ship LE'. My note id for this: 81-05.

This belongs in the first-hour ritual. The load-bearing line: Someone used CRC32 to key a map of modules. Reject files over your cap by default. Silent huge allocs are bugs. Version in my shot: current lab snapshot, not last year's blog.

Also: Do not mmap untrusted files. I will die on this.

Agreed on the class, not on the tool. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Pinned a comment at 0x1400028ca in the listing.

@decodr

The screenshot is the useful part of the post. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Endian tes

This is getting personal and it does not need to. Good. Dated shot, version in the post. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map of modules. If you intern, intern copies. Views into a temp will haunt you. Took me 12 hours the first time.

@edgexx

Good. Dated shot, version in the post. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map of modules. If you

This matches a public n-day class from last patch Tuesday. The load-bearing line: Someone used CRC32 to key a map of modules. Dry-run default on destructive flags. Lab tools delete files. Pinned a comment at 0x140002554 in the listing.

I still keep a paper notebook for this kind of note. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Checksums are not hashes. Stop keying maps with CRC32. If anyone DMs me a zip I will not open it. Hash in-thread.

@ghost

I still keep a paper notebook for this kind of note. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Chec

I am reporting the sample-drop hint. Hash and corpus tag only. I would have written the opposite conclusion a year ago. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Need/take/remain. Every C parser I still write uses them. Took me 9 hours the first time.

@ledger

Agreed on the class, not on the tool. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Fuzz your own parse

Not fully convinced yet. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Do not mmap untrusted files. I will die on this. I reproduced it on lab build 1255.

@johnnyace

Agreed on the class, not on the tool. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Dry-run default on

Stop flexing an IDA license. The question was the unwind info. I disagree with the tone, not the bytes. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map of modules. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I reproduced it on lab build 1142.

This is the kind of thread that should be a sticky and is not. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map of modules. Need/take/remain. Every C parser I still write uses them. I reproduced it on lab build 1031.

@n0des

This is the kind of thread that should be a sticky and is not. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a

That is a vibe. I asked for a listing offset. I ran this on a licensed corpus binary. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map of modules. Checksums are not hashes. Stop keying maps with CRC32. Did you force-create the function or did auto-analysis luck into it? If anyone DMs me a zip I will not open it. Hash in-thread.

@novax

I ran this on a licensed corpus binary. «CRC32 as a hash and other crimes» — specifically Someone used CRC32 to key a map of modules. Checks

I dumped after OEP and then did this. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Checksums are not hashes. Stop keying maps with CRC32. My note id for this: 81-19.

This is the kind of thread that should be a sticky and is not. The load-bearing line: Someone used CRC32 to key a map of modules. Caps on size and entry count are the feature. The parser is decoration. I reproduced it on lab build 1357.

Also: Dry-run default on destructive flags. Lab tools delete files.

I failed this exact class in January. You wrote «Someone used CRC32 to key a map of modules». That is the sentence I keep. Do not mmap untrusted files. I will die on this. I still have the snapshot named codi-129-pre.

@redx

I failed this exact class in January. You wrote «Someone used CRC32 to key a map of modules». That is the sentence I keep. Do not mmap untru

You keep moving the goalposts. First it was the decoder, now it is the dump. If you only have the decompiler, you do not have the bug. On «CRC32 as a hash and other crimes»: Someone used CRC32 to key a map of modules. Caps on size and entry count are the feature. The parser is decoration. I wrote a 12-line script and then threw it away. The listing was enough.

The screenshot is the useful part of the post. You wrote «Someone used CRC32 to key a map of modules». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Was this on the licensed corpus or a crackme you wrote? Same class as the June thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.