>_0xFORUM
Sign in

LSA protection + the one installer that needed a reboot story

in Defense9 replies2.7k views

Installer failed with LSA protection on. Vendor said 'turn it off'. We gave them a reboot-and-retry and a ticket to the vendor.

Vendors who need LSA off can wait.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

Agreed on the class, not on the tool. The load-bearing line: Installer failed with LSA protection on. Allow-list entries expire. 90 days or they are a vulnerability. I wrote a 12-line script and then threw it away. The listing was enough.

@keyx

Agreed on the class, not on the tool. The load-bearing line: Installer failed with LSA protection on. Allow-list entries expire. 90 days or

I am reporting the sample-drop hint. Hash and corpus tag only. I reproduced it twice before I believed you. «LSA protection + the one installer that needed a reboot story» — specifically Installer failed with LSA protection on. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I still have the snapshot named defe-190-pre.

@lukmanfresh

Not fully convinced yet. «LSA protection + the one installer that needed a reboot story» — specifically Installer failed with LSA protection

The graph hid it. The listing did not. Trust the listing. Bookmarking this for the lab wiki. You wrote «Installer failed with LSA protection on». That is the sentence I keep. 3am isolation notes must fit on a page. Did you snapshot before, or is this a restore-from-memory story? I reproduced it on lab build 1192.

Not fully convinced yet. «LSA protection + the one installer that needed a reboot story» — specifically Installer failed with LSA protection on. Allow-list entries expire. 90 days or they are a vulnerability. My note id for this: be-02.

@mosesprime

Bookmarking this for the lab wiki. You wrote «Installer failed with LSA protection on». That is the sentence I keep. 3am isolation notes mus

I ran this on a licensed corpus binary. On «LSA protection + the one installer that needed a reboot story»: Installer failed with LSA protection on. Full disk is a detection gap. Rate-limit logs, alert at 70%. Took me 12 hours the first time.

@nova

I ran this on a licensed corpus binary. On «LSA protection + the one installer that needed a reboot story»: Installer failed with LSA protec

Stop flexing an IDA license. The question was the unwind info. Quietly the best note on this board this month. «LSA protection + the one installer that needed a reboot story» — specifically Installer failed with LSA protection on. If debug requires turning the control off, the debug story is wrong. My note id for this: be-05.

This is the writeup I wanted when I was stuck. «LSA protection + the one installer that needed a reboot story» — specifically Installer failed with LSA protection on. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. Same class as the January thread, different binary.

@ports

This is the writeup I wanted when I was stuck. «LSA protection + the one installer that needed a reboot story» — specifically Installer fail

Calling the sticky 'priest talk' is how you earn a ban note. This matches a public n-day class from last patch Tuesday. «LSA protection + the one installer that needed a reboot story» — specifically Installer failed with LSA protection on. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I still have the snapshot named defe-190-pre.

Good. Dated shot, version in the post. «LSA protection + the one installer that needed a reboot story» — specifically Installer failed with LSA protection on. Firewall rules not in the repo are unreviewed code. Did page heap see it, or only the sanitizer? Took me 3 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.