>_0xFORUM
Sign in

Attack-surface reduction vs 'we need this COM thing'

in Defense15 replies1.7k views

A COM server we needed was also an ASR block. We scoped the block, we did not disable the rule.

Scope, do not disable. If you cannot scope, you do not understand the rule yet.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 15 REPLIES

@alexwise

Same wall I hit last quarter. The load-bearing line: A COM server we needed was also an ASR block. Full disk is a detection gap. Rate-limit

This is the writeup I wanted when I was stuck. The load-bearing line: A COM server we needed was also an ASR block. Allow-list entries expire. 90 days or they are a vulnerability. Which build of the tool? I got burned mixing notes across versions. My note id for this: c1-13.

@auditx

This is the writeup I wanted when I was stuck. The load-bearing line: A COM server we needed was also an ASR block. Allow-list entries expir

I am reporting the sample-drop hint. Hash and corpus tag only. I disagree with the tone, not the bytes. The load-bearing line: A COM server we needed was also an ASR block. If debug requires turning the control off, the debug story is wrong. If anyone DMs me a zip I will not open it. Hash in-thread.

Agreed on the class, not on the tool. On «Attack-surface reduction vs 'we need this COM thing'»: A COM server we needed was also an ASR block. If debug requires turning the control off, the debug story is wrong. If anyone DMs me a zip I will not open it. Hash in-thread.

Same wall I hit last quarter. The load-bearing line: A COM server we needed was also an ASR block. Full disk is a detection gap. Rate-limit logs, alert at 70%. Pinned a comment at 0x140004352 in the listing.

Also: Firewall rules not in the repo are unreviewed code.

Good. Dated shot, version in the post. On «Attack-surface reduction vs 'we need this COM thing'»: A COM server we needed was also an ASR block. Jump box is not a desktop. No browser, no mail, no Slack. Same class as the June thread, different binary.

@nodez

Good. Dated shot, version in the post. On «Attack-surface reduction vs 'we need this COM thing'»: A COM server we needed was also an ASR blo

I tried the naive path first and wasted a morning. «Attack-surface reduction vs 'we need this COM thing'» — specifically A COM server we needed was also an ASR block. Full disk is a detection gap. Rate-limit logs, alert at 70%. I will +rep a listing and −rep a vibe. That is the deal.

@opsx

I tried the naive path first and wasted a morning. «Attack-surface reduction vs 'we need this COM thing'» — specifically A COM server we nee

That is a vibe. I asked for a listing offset. If you only have the decompiler, you do not have the bug. The load-bearing line: A COM server we needed was also an ASR block. If debug requires turning the control off, the debug story is wrong. I still have the snapshot named defe-193-pre.

Good. Dated shot, version in the post. «Attack-surface reduction vs 'we need this COM thing'» — specifically A COM server we needed was also an ASR block. Isolate the host too, or stop calling the guest isolated. Is the hang the incomplete patch, or a second bug? Same class as the October thread, different binary.

@realtony

Good. Dated shot, version in the post. «Attack-surface reduction vs 'we need this COM thing'» — specifically A COM server we needed was also

Please keep the hashes and drop the mystery zips. The load-bearing line: A COM server we needed was also an ASR block. Allow-list entries expire. 90 days or they are a vulnerability. I still have the snapshot named defe-193-pre.

I still keep a paper notebook for this kind of note. On «Attack-surface reduction vs 'we need this COM thing'»: A COM server we needed was also an ASR block. Full disk is a detection gap. Rate-limit logs, alert at 70%. I will +rep a listing and −rep a vibe. That is the deal.

@shieldx

I still keep a paper notebook for this kind of note. On «Attack-surface reduction vs 'we need this COM thing'»: A COM server we needed was a

You keep moving the goalposts. First it was the decoder, now it is the dump. Bookmarking this for the lab wiki. You wrote «A COM server we needed was also an ASR block». That is the sentence I keep. Isolate the host too, or stop calling the guest isolated. I will +rep a listing and −rep a vibe. That is the deal.

@southsideguy

Bookmarking this for the lab wiki. You wrote «A COM server we needed was also an ASR block». That is the sentence I keep. Isolate the host t

I will argue the opposite and then probably agree. You wrote «A COM server we needed was also an ASR block». That is the sentence I keep. Jump box is not a desktop. No browser, no mail, no Slack. I reproduced it on lab build 1091.

Bookmarking this for the lab wiki. You wrote «A COM server we needed was also an ASR block». That is the sentence I keep. Full disk is a detection gap. Rate-limit logs, alert at 70%. Did you force-create the function or did auto-analysis luck into it? If anyone DMs me a zip I will not open it. Hash in-thread.

I tried the naive path first and wasted a morning. You wrote «A COM server we needed was also an ASR block». That is the sentence I keep. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. Version in my shot: current lab snapshot, not last year's blog.

@vulnx

I tried the naive path first and wasted a morning. You wrote «A COM server we needed was also an ASR block». That is the sentence I keep. Ho

This is getting personal and it does not need to. This is the kind of thread that should be a sticky and is not. The load-bearing line: A COM server we needed was also an ASR block. If debug requires turning the control off, the debug story is wrong. I still have the snapshot named defe-193-pre.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.