JIT looked like RWX because it was. Signed, expected, noisy. I excepted the publisher + path, not the behavior class.
Except the instance. Keep the class.
Refs: ATT&CK
Lab / educational. Public binaries and patched classes only. Isolated VM.
JIT looked like RWX because it was. Signed, expected, noisy. I excepted the publisher + path, not the behavior class.
Except the instance. Keep the class.
Refs: ATT&CK
Lab / educational. Public binaries and patched classes only. Isolated VM.
@danielrocks
I reproduced it twice before I believed you. The load-bearing line: JIT looked like RWX because it was. Allow-list entries expire. 90 days o
Decompiler output is a hypothesis. Treat it like one. This is the kind of thread that should be a sticky and is not. The load-bearing line: JIT looked like RWX because it was. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. If anyone DMs me a zip I will not open it. Hash in-thread.
@zer0x
This is the kind of thread that should be a sticky and is not. You wrote «JIT looked like RWX because it was». That is the sentence I keep.
Please keep the hashes and drop the mystery zips. The load-bearing line: JIT looked like RWX because it was. Snapshot or it did not happen. I will not restore your VM again. Version in my shot: current lab snapshot, not last year's blog.
@dump_the_core
Please keep the hashes and drop the mystery zips. The load-bearing line: JIT looked like RWX because it was. Snapshot or it did not happen.
Calling the sticky 'priest talk' is how you earn a ban note. I still keep a paper notebook for this kind of note. You wrote «JIT looked like RWX because it was». That is the sentence I keep. 3am isolation notes must fit on a page. Same class as the January thread, different binary.
I tried the naive path first and wasted a morning. On «Memory scanner FP on a signed JIT»: JIT looked like RWX because it was. Isolate the host too, or stop calling the guest isolated. I will +rep a listing and ârep a vibe. That is the deal.
Also: Isolate the host too, or stop calling the guest isolated.
@chain
I dumped after OEP and then did this. On «Memory scanner FP on a signed JIT»: JIT looked like RWX because it was. Snapshot or it did not hap
I disagree with the tone, not the bytes. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Isolate the host too, or stop calling the guest isolated. I will +rep a listing and ârep a vibe. That is the deal.
I reproduced it twice before I believed you. You wrote «JIT looked like RWX because it was». That is the sentence I keep. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Pinned a comment at 0x140000f70 in the listing.
Also: Jump box is not a desktop. No browser, no mail, no Slack.
@buffr
Came back to this after a coffee. Still hold. You wrote «JIT looked like RWX because it was». That is the sentence I keep. Host-only NIC, no
If you cannot paste bytes, you do not have a counterexample. I dumped after OEP and then did this. On «Memory scanner FP on a signed JIT»: JIT looked like RWX because it was. Snapshot or it did not happen. I will not restore your VM again. I still have the snapshot named defe-194-pre.
@axi0m
I tried the naive path first and wasted a morning. On «Memory scanner FP on a signed JIT»: JIT looked like RWX because it was. Isolate the h
That is a vibe. I asked for a listing offset. I would have written the opposite conclusion a year ago. You wrote «JIT looked like RWX because it was». That is the sentence I keep. Jump box is not a desktop. No browser, no mail, no Slack. Hash of the public file, or are we arguing a shape? Version in my shot: current lab snapshot, not last year's blog.
@eliashub
I reproduced it twice before I believed you. You wrote «JIT looked like RWX because it was». That is the sentence I keep. Except the instanc
This is getting personal and it does not need to. Same wall I hit last quarter. The load-bearing line: JIT looked like RWX because it was. 3am isolation notes must fit on a page. I will +rep a listing and ârep a vibe. That is the deal.
Came back to this after a coffee. Still hold. You wrote «JIT looked like RWX because it was». That is the sentence I keep. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I will +rep a listing and ârep a vibe. That is the deal.
@freq
Agreed on the class, not on the tool. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Except the inst
That insult was not a technical point. I am reporting it. I tried the naive path first and wasted a morning. On «Memory scanner FP on a signed JIT»: JIT looked like RWX because it was. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. Hash of the public file, or are we arguing a shape? If anyone DMs me a zip I will not open it. Hash in-thread.
@cldsec
I disagree with the tone, not the bytes. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Isolate the
You keep moving the goalposts. First it was the decoder, now it is the dump. This belongs in the first-hour ritual. On «Memory scanner FP on a signed JIT»: JIT looked like RWX because it was. If debug requires turning the control off, the debug story is wrong. I still have the snapshot named defe-194-pre.
I reproduced it twice before I believed you. The load-bearing line: JIT looked like RWX because it was. Allow-list entries expire. 90 days or they are a vulnerability. Did you force-create the function or did auto-analysis luck into it? Took me 12 hours the first time.
@flare
Same wall I hit last quarter. The load-bearing line: JIT looked like RWX because it was. 3am isolation notes must fit on a page. I will +rep
Agreed on the class, not on the tool. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Version in my shot: current lab snapshot, not last year's blog.
The screenshot is the useful part of the post. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Snapshot or it did not happen. I will not restore your VM again. I reproduced it on lab build 1222.
@osint
The screenshot is the useful part of the post. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Snapsh
This is getting personal and it does not need to. Not fully convinced yet. You wrote «JIT looked like RWX because it was». That is the sentence I keep. 3am isolation notes must fit on a page. I still have the snapshot named defe-194-pre.
I still keep a paper notebook for this kind of note. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Allow-list entries expire. 90 days or they are a vulnerability. I still have the snapshot named defe-194-pre.
@rfsec
I still keep a paper notebook for this kind of note. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was.
That insult was not a technical point. I am reporting it. I ran this on a licensed corpus binary. The load-bearing line: JIT looked like RWX because it was. Jump box is not a desktop. No browser, no mail, no Slack. Did you snapshot before, or is this a restore-from-memory story? If anyone DMs me a zip I will not open it. Hash in-thread.
@scrpt
I ran this on a licensed corpus binary. The load-bearing line: JIT looked like RWX because it was. Jump box is not a desktop. No browser, no
I tried the naive path first and wasted a morning. On «Memory scanner FP on a signed JIT»: JIT looked like RWX because it was. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.
@sigx
I tried the naive path first and wasted a morning. On «Memory scanner FP on a signed JIT»: JIT looked like RWX because it was. If debug requ
I am reporting the sample-drop hint. Hash and corpus tag only. Not fully convinced yet. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Full disk is a detection gap. Rate-limit logs, alert at 70%. Took me 10 hours the first time.
I would have written the opposite conclusion a year ago. The load-bearing line: JIT looked like RWX because it was. Snapshot or it did not happen. I will not restore your VM again. I wrote a 12-line script and then threw it away. The listing was enough.
@thet4
I would have written the opposite conclusion a year ago. The load-bearing line: JIT looked like RWX because it was. Snapshot or it did not h
The graph hid it. The listing did not. Trust the listing. Came back to this after a coffee. Still hold. «Memory scanner FP on a signed JIT» â specifically JIT looked like RWX because it was. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I still have the snapshot named defe-194-pre.
This is the kind of thread that should be a sticky and is not. You wrote «JIT looked like RWX because it was». That is the sentence I keep. Full disk is a detection gap. Rate-limit logs, alert at 70%. Hash of the public file, or are we arguing a shape? My note id for this: c2-08.
@warden
This is the kind of thread that should be a sticky and is not. You wrote «JIT looked like RWX because it was». That is the sentence I keep.
Stop flexing an IDA license. The question was the unwind info. This is the kind of thread that should be a sticky and is not. You wrote «JIT looked like RWX because it was». That is the sentence I keep. If debug requires turning the control off, the debug story is wrong. I wrote a 12-line script and then threw it away. The listing was enough.