>_0xFORUM
Sign in

Allow-lists that expire

in Defense9 replies6.2k views

A allow-list entry without an expiry is a vulnerability with a ticket number. 90 days, then re-justify.

I deleted 40 entries nobody would re-justify. Nothing broke. Something would have, later, in a worse way.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

Agreed on the class, not on the tool. The load-bearing line: A allow-list entry without an expiry is a vulnerability with a ticket number. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I will +rep a listing and −rep a vibe. That is the deal.

@alexwise

Agreed on the class, not on the tool. The load-bearing line: A allow-list entry without an expiry is a vulnerability with a ticket number. E

I reproduced it twice before I believed you. On «Allow-lists that expire»: A allow-list entry without an expiry is a vulnerability with a ticket number. Jump box is not a desktop. No browser, no mail, no Slack. I will +rep a listing and −rep a vibe. That is the deal.

@brightonx

This is the kind of thread that should be a sticky and is not. «Allow-lists that expire» — specifically A allow-list entry without an expiry

Did this on ARM64 last week — same shape, different pain. You wrote «A allow-list entry without an expiry is a vulnerability with a ticket number». That is the sentence I keep. Isolate the host too, or stop calling the guest isolated. I will +rep a listing and −rep a vibe. That is the deal.

@auditx

I reproduced it twice before I believed you. On «Allow-lists that expire»: A allow-list entry without an expiry is a vulnerability with a ti

Stop flexing an IDA license. The question was the unwind info. Agreed on the class, not on the tool. On «Allow-lists that expire»: A allow-list entry without an expiry is a vulnerability with a ticket number. Allow-list entries expire. 90 days or they are a vulnerability. Took me 5 hours the first time.

I still keep a paper notebook for this kind of note. «Allow-lists that expire» — specifically A allow-list entry without an expiry is a vulnerability with a ticket number. Jump box is not a desktop. No browser, no mail, no Slack. Pinned a comment at 0x140000a2e in the listing.

@cipher

I still keep a paper notebook for this kind of note. «Allow-lists that expire» — specifically A allow-list entry without an expiry is a vuln

That is a vibe. I asked for a listing offset. If you only have the decompiler, you do not have the bug. You wrote «A allow-list entry without an expiry is a vulnerability with a ticket number». That is the sentence I keep. If debug requires turning the control off, the debug story is wrong. Same class as the March thread, different binary.

This is the kind of thread that should be a sticky and is not. «Allow-lists that expire» — specifically A allow-list entry without an expiry is a vulnerability with a ticket number. Jump box is not a desktop. No browser, no mail, no Slack. Did page heap see it, or only the sanitizer? Pinned a comment at 0x140006a68 in the listing.

@cookx

If you only have the decompiler, you do not have the bug. You wrote «A allow-list entry without an expiry is a vulnerability with a ticket n

I would have written the opposite conclusion a year ago. On «Allow-lists that expire»: A allow-list entry without an expiry is a vulnerability with a ticket number. Jump box is not a desktop. No browser, no mail, no Slack. My note id for this: b1-07.

This matches a public n-day class from last patch Tuesday. On «Allow-lists that expire»: A allow-list entry without an expiry is a vulnerability with a ticket number. Allow-list entries expire. 90 days or they are a vulnerability. Which build of the tool? I got burned mixing notes across versions. If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.