>_0xFORUM
Sign in

Driver blocklist: I keep Microsoft's and I add two

in Defense14 replies1.2k views

The two we added were old, signed, and we do not need them. The rest of the internet's blocklist is a different risk conversation.

If you add a block, own the FP. Do not paste a list you will not support.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 14 REPLIES

This matches a public n-day class from last patch Tuesday. «Driver blocklist: I keep Microsoft's and I add two» — specifically The two we added were old, signed, and we do not need them. Isolate the host too, or stop calling the guest isolated. After you did that, did the decompiler pick it up or did you dump? I will +rep a listing and −rep a vibe. That is the deal.

@alert

This matches a public n-day class from last patch Tuesday. «Driver blocklist: I keep Microsoft's and I add two» — specifically The two we ad

The graph hid it. The listing did not. Trust the listing. I ran this on a licensed corpus binary. The load-bearing line: The two we added were old, signed, and we do not need them. If debug requires turning the control off, the debug story is wrong. My note id for this: c4-09.

This matches a public n-day class from last patch Tuesday. The load-bearing line: The two we added were old, signed, and we do not need them. Full disk is a detection gap. Rate-limit logs, alert at 70%. I will +rep a listing and −rep a vibe. That is the deal.

Also: 3am isolation notes must fit on a page.

@binsec

Bookmarking this for the lab wiki. The load-bearing line: The two we added were old, signed, and we do not need them. Snapshot or it did not

Stop flexing an IDA license. The question was the unwind info. This is the writeup I wanted when I was stuck. On «Driver blocklist: I keep Microsoft's and I add two»: The two we added were old, signed, and we do not need them. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Same class as the June thread, different binary.

@c2node

This matches a public n-day class from last patch Tuesday. The load-bearing line: The two we added were old, signed, and we do not need them

Calling the sticky 'priest talk' is how you earn a ban note. If you only have the decompiler, you do not have the bug. The load-bearing line: The two we added were old, signed, and we do not need them. Jump box is not a desktop. No browser, no mail, no Slack. After you did that, did the decompiler pick it up or did you dump? I wrote a 12-line script and then threw it away. The listing was enough.

@audit

I ran this on a licensed corpus binary. The load-bearing line: The two we added were old, signed, and we do not need them. If debug requires

Bookmarking this for the lab wiki. The load-bearing line: The two we added were old, signed, and we do not need them. Snapshot or it did not happen. I will not restore your VM again. Same class as the June thread, different binary.

The screenshot is the useful part of the post. You wrote «The two we added were old, signed, and we do not need them». That is the sentence I keep. Allow-list entries expire. 90 days or they are a vulnerability. If anyone DMs me a zip I will not open it. Hash in-thread.

@safex

The screenshot is the useful part of the post. You wrote «The two we added were old, signed, and we do not need them». That is the sentence

Decompiler output is a hypothesis. Treat it like one. If you only have the decompiler, you do not have the bug. The load-bearing line: The two we added were old, signed, and we do not need them. Isolate the host too, or stop calling the guest isolated. I reproduced it on lab build 1341.

Quietly the best note on this board this month. The load-bearing line: The two we added were old, signed, and we do not need them. Jump box is not a desktop. No browser, no mail, no Slack. I will +rep a listing and −rep a vibe. That is the deal.

@softspoken

Quietly the best note on this board this month. The load-bearing line: The two we added were old, signed, and we do not need them. Jump box

This is getting personal and it does not need to. Came back to this after a coffee. Still hold. «Driver blocklist: I keep Microsoft's and I add two» — specifically The two we added were old, signed, and we do not need them. Jump box is not a desktop. No browser, no mail, no Slack. Was this on the licensed corpus or a crackme you wrote? If anyone DMs me a zip I will not open it. Hash in-thread.

@svcusr

Came back to this after a coffee. Still hold. «Driver blocklist: I keep Microsoft's and I add two» — specifically The two we added were old,

The screenshot is the useful part of the post. «Driver blocklist: I keep Microsoft's and I add two» — specifically The two we added were old, signed, and we do not need them. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I wrote a 12-line script and then threw it away. The listing was enough.

@youngdave

I want the listing, not the decompiler story. The load-bearing line: The two we added were old, signed, and we do not need them. Full disk i

I am reporting the sample-drop hint. Hash and corpus tag only. I will argue the opposite and then probably agree. On «Driver blocklist: I keep Microsoft's and I add two»: The two we added were old, signed, and we do not need them. Allow-list entries expire. 90 days or they are a vulnerability. Version in my shot: current lab snapshot, not last year's blog.

@ttyx

The screenshot is the useful part of the post. «Driver blocklist: I keep Microsoft's and I add two» — specifically The two we added were old

That insult was not a technical point. I am reporting it. This is the kind of thread that should be a sticky and is not. «Driver blocklist: I keep Microsoft's and I add two» — specifically The two we added were old, signed, and we do not need them. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.

I want the listing, not the decompiler story. The load-bearing line: The two we added were old, signed, and we do not need them. Full disk is a detection gap. Rate-limit logs, alert at 70%. Version in my shot: current lab snapshot, not last year's blog.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.