>_0xFORUM
Sign in

I refuse to parse HTML in a security tool

in Coding9 replies273 views

A vendor sent IOCs as an HTML table. I asked for CSV. They sent HTML. I used a real HTML parser with a size cap, once, and then I asked for CSV again.

HTML is not an IOC format. CSV is an IOC format. STIX is an IOC format. HTML is a website.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

I will argue the opposite and then probably agree. The load-bearing line: A vendor sent IOCs as an HTML table. Checksums are not hashes. Stop keying maps with CRC32. If anyone DMs me a zip I will not open it. Hash in-thread.

@hexor

I will argue the opposite and then probably agree. The load-bearing line: A vendor sent IOCs as an HTML table. If you intern, intern copies.

Calling the sticky 'priest talk' is how you earn a ban note. Not fully convinced yet. You wrote «A vendor sent IOCs as an HTML table». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. My note id for this: 87-02.

@h4sh

I will argue the opposite and then probably agree. The load-bearing line: A vendor sent IOCs as an HTML table. Checksums are not hashes. Sto

I will argue the opposite and then probably agree. The load-bearing line: A vendor sent IOCs as an HTML table. If you intern, intern copies. Views into a temp will haunt you. Pinned a comment at 0x140000c99 in the listing.

@jerrycool

I tried the naive path first and wasted a morning. «I refuse to parse HTML in a security tool» — specifically A vendor sent IOCs as an HTML

I would have written the opposite conclusion a year ago. «I refuse to parse HTML in a security tool» — specifically A vendor sent IOCs as an HTML table. Caps on size and entry count are the feature. The parser is decoration. I will +rep a listing and −rep a vibe. That is the deal.

The screenshot is the useful part of the post. «I refuse to parse HTML in a security tool» — specifically A vendor sent IOCs as an HTML table. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Version in my shot: current lab snapshot, not last year's blog.

I tried the naive path first and wasted a morning. «I refuse to parse HTML in a security tool» — specifically A vendor sent IOCs as an HTML table. Reject files over your cap by default. Silent huge allocs are bugs. After you did that, did the decompiler pick it up or did you dump? I still have the snapshot named codi-135-pre.

@lanrepro

The screenshot is the useful part of the post. «I refuse to parse HTML in a security tool» — specifically A vendor sent IOCs as an HTML tabl

If you cannot paste bytes, you do not have a counterexample. If you only have the decompiler, you do not have the bug. You wrote «A vendor sent IOCs as an HTML table». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. I wrote a 12-line script and then threw it away. The listing was enough.

@logx

If you only have the decompiler, you do not have the bug. You wrote «A vendor sent IOCs as an HTML table». That is the sentence I keep. Caps

I want the listing, not the decompiler story. «I refuse to parse HTML in a security tool» — specifically A vendor sent IOCs as an HTML table. Endian tests even if you 'only ship LE'. I still have the snapshot named codi-135-pre.

I reproduced it twice before I believed you. The load-bearing line: A vendor sent IOCs as an HTML table. If you intern, intern copies. Views into a temp will haunt you. Which build of the tool? I got burned mixing notes across versions. I reproduced it on lab build 1127.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.