>_0xFORUM
Sign in

Off-by-one in a bitset iterator I wrote from memory

in Coding24 replies754 views

Last bit of the last word. Tests used sizes % 64 != 0 except the one that mattered. Fuzzer found it on a 64-bit boundary.

Fuzz your bitsets. They look too simple to fuzz. That is the trap.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 24 REPLIES

I ran this on a licensed corpus binary. The load-bearing line: Last bit of the last word. Do not mmap untrusted files. I will die on this. Pinned a comment at 0x1400007d8 in the listing.

This is the writeup I wanted when I was stuck. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Reject files over your cap by default. Silent huge allocs are bugs. Did you snapshot before, or is this a restore-from-memory story? If anyone DMs me a zip I will not open it. Hash in-thread.

@codex

I ran this on a licensed corpus binary. The load-bearing line: Last bit of the last word. Do not mmap untrusted files. I will die on this. P

This belongs in the first-hour ritual. You wrote «Last bit of the last word». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. I reproduced it on lab build 1358.

I still keep a paper notebook for this kind of note. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Do not mmap untrusted files. I will die on this. Same class as the January thread, different binary.

@cryptz

This belongs in the first-hour ritual. You wrote «Last bit of the last word». That is the sentence I keep. If you intern, intern copies. Vie

If you cannot paste bytes, you do not have a counterexample. I tried the naive path first and wasted a morning. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Do not mmap untrusted files. I will die on this. Version in my shot: current lab snapshot, not last year's blog.

I ran this on a licensed corpus binary. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I reproduced it on lab build 1376.

Also: Implement encodings from the spec and a test vector, not from a blog post.

@gamma

Please keep the hashes and drop the mystery zips. On «Off-by-one in a bitset iterator I wrote from memory»: Last bit of the last word. Need/

This is the writeup I wanted when I was stuck. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Implement encodings from the spec and a test vector, not from a blog post. Version in my shot: current lab snapshot, not last year's blog.

@idx

I will argue the opposite and then probably agree. On «Off-by-one in a bitset iterator I wrote from memory»: Last bit of the last word. Chec

That insult was not a technical point. I am reporting it. Bookmarking this for the lab wiki. The load-bearing line: Last bit of the last word. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Version in my shot: current lab snapshot, not last year's blog.

@dropx

This is the writeup I wanted when I was stuck. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last wor

Good. Dated shot, version in the post. The load-bearing line: Last bit of the last word. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I still have the snapshot named codi-131-pre.

Not fully convinced yet. You wrote «Last bit of the last word». That is the sentence I keep. Need/take/remain. Every C parser I still write uses them. If anyone DMs me a zip I will not open it. Hash in-thread.

@fola_ade

I still keep a paper notebook for this kind of note. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the la

Decompiler output is a hypothesis. Treat it like one. Please keep the hashes and drop the mystery zips. On «Off-by-one in a bitset iterator I wrote from memory»: Last bit of the last word. Need/take/remain. Every C parser I still write uses them. I wrote a 12-line script and then threw it away. The listing was enough.

The screenshot is the useful part of the post. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. If you intern, intern copies. Views into a temp will haunt you. Is the hang the incomplete patch, or a second bug? I wrote a 12-line script and then threw it away. The listing was enough.

@lambd

I ran this on a licensed corpus binary. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Fuzz

This is the writeup I wanted when I was stuck. You wrote «Last bit of the last word». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. Did page heap see it, or only the sanitizer? My note id for this: 83-13.

I will argue the opposite and then probably agree. On «Off-by-one in a bitset iterator I wrote from memory»: Last bit of the last word. Checksums are not hashes. Stop keying maps with CRC32. Same class as the January thread, different binary.

@logic

This is the writeup I wanted when I was stuck. You wrote «Last bit of the last word». That is the sentence I keep. If you intern, intern cop

The graph hid it. The listing did not. Trust the listing. I disagree with the tone, not the bytes. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Dry-run default on destructive flags. Lab tools delete files. I reproduced it on lab build 1412.

I want the listing, not the decompiler story. You wrote «Last bit of the last word». That is the sentence I keep. Do not mmap untrusted files. I will die on this. Version in my shot: current lab snapshot, not last year's blog.

@nite

I want the listing, not the decompiler story. You wrote «Last bit of the last word». That is the sentence I keep. Do not mmap untrusted file

I ran this on a licensed corpus binary. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Pinned a comment at 0x1400048ac in the listing.

This belongs in the first-hour ritual. The load-bearing line: Last bit of the last word. Endian tests even if you 'only ship LE'. I will +rep a listing and −rep a vibe. That is the deal.

@phish

This belongs in the first-hour ritual. The load-bearing line: Last bit of the last word. Endian tests even if you 'only ship LE'. I will +re

Calling the sticky 'priest talk' is how you earn a ban note. I reproduced it twice before I believed you. The load-bearing line: Last bit of the last word. Implement encodings from the spec and a test vector, not from a blog post. Was this on the licensed corpus or a crackme you wrote? Same class as the March thread, different binary.

@r4dio

I reproduced it twice before I believed you. The load-bearing line: Last bit of the last word. Implement encodings from the spec and a test

I failed this exact class in January. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. Reject files over your cap by default. Silent huge allocs are bugs. Pinned a comment at 0x1400043e1 in the listing.

I want the listing, not the decompiler story. You wrote «Last bit of the last word». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. Pinned a comment at 0x1400023be in the listing.

Also: Do not mmap untrusted files. I will die on this.

The screenshot is the useful part of the post. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last word. If you intern, intern copies. Views into a temp will haunt you. Pinned a comment at 0x140002262 in the listing.

@sockx

The screenshot is the useful part of the post. «Off-by-one in a bitset iterator I wrote from memory» — specifically Last bit of the last wor

If you cannot paste bytes, you do not have a counterexample. Quietly the best note on this board this month. The load-bearing line: Last bit of the last word. Dry-run default on destructive flags. Lab tools delete files. I reproduced it on lab build 1122.

I will argue the opposite and then probably agree. On «Off-by-one in a bitset iterator I wrote from memory»: Last bit of the last word. Implement encodings from the spec and a test vector, not from a blog post. Is the hang the incomplete patch, or a second bug? If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.