>_0xFORUM
Sign in

Patch Tuesday as a detection: who missed the out-of-band

in Defense16 replies1.3k views

Not every fix waits for Tuesday. The forgot-VM problem is worse on out-of-band because the process is 'someone saw the mail'.

I hunt the old immediate in binaries, and I hunt the unpatched VM by build.

Refs: MSRC · CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 16 REPLIES

I would have written the opposite conclusion a year ago. On «Patch Tuesday as a detection: who missed the out-of-band»: Not every fix waits for Tuesday. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I wrote a 12-line script and then threw it away. The listing was enough.

@danielcrest

I failed this exact class in January. On «Patch Tuesday as a detection: who missed the out-of-band»: Not every fix waits for Tuesday. If deb

I am reporting the sample-drop hint. Hash and corpus tag only. I tried the naive path first and wasted a morning. The load-bearing line: Not every fix waits for Tuesday. Snapshot or it did not happen. I will not restore your VM again. I will +rep a listing and −rep a vibe. That is the deal.

Agreed on the class, not on the tool. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. I reproduced it on lab build 1276.

@baba_yaga

I would have written the opposite conclusion a year ago. On «Patch Tuesday as a detection: who missed the out-of-band»: Not every fix waits

You keep moving the goalposts. First it was the decoder, now it is the dump. I would have written the opposite conclusion a year ago. «Patch Tuesday as a detection: who missed the out-of-band» — specifically Not every fix waits for Tuesday. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. After you did that, did the decompiler pick it up or did you dump? Pinned a comment at 0x140006726 in the listing.

This is the writeup I wanted when I was stuck. The load-bearing line: Not every fix waits for Tuesday. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. Which build of the tool? I got burned mixing notes across versions. Version in my shot: current lab snapshot, not last year's blog.

@authx

I dumped after OEP and then did this. «Patch Tuesday as a detection: who missed the out-of-band» — specifically Not every fix waits for Tues

Decompiler output is a hypothesis. Treat it like one. This matches a public n-day class from last patch Tuesday. «Patch Tuesday as a detection: who missed the out-of-band» — specifically Not every fix waits for Tuesday. Jump box is not a desktop. No browser, no mail, no Slack. I will +rep a listing and −rep a vibe. That is the deal.

@ampx

I would have written the opposite conclusion a year ago. «Patch Tuesday as a detection: who missed the out-of-band» — specifically Not every

I dumped after OEP and then did this. «Patch Tuesday as a detection: who missed the out-of-band» — specifically Not every fix waits for Tuesday. Isolate the host too, or stop calling the guest isolated. I wrote a 12-line script and then threw it away. The listing was enough.

@bryanwest

Agreed on the class, not on the tool. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. Snapshot or it did not happe

This is getting personal and it does not need to. I ran this on a licensed corpus binary. The load-bearing line: Not every fix waits for Tuesday. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Version in my shot: current lab snapshot, not last year's blog.

@cipherz

This is the writeup I wanted when I was stuck. The load-bearing line: Not every fix waits for Tuesday. Host-only NIC, no shared folders, no

That insult was not a technical point. I am reporting it. I would have written the opposite conclusion a year ago. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. Pinned a comment at 0x1400026bf in the listing.

I would have written the opposite conclusion a year ago. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. Isolate the host too, or stop calling the guest isolated. Took me 10 hours the first time.

Also: Allow-list entries expire. 90 days or they are a vulnerability.

@core

I would have written the opposite conclusion a year ago. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. Snapshot

I failed this exact class in January. On «Patch Tuesday as a detection: who missed the out-of-band»: Not every fix waits for Tuesday. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.

@edwardconnect

I would have written the opposite conclusion a year ago. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. Isolate t

The graph hid it. The listing did not. Trust the listing. Same wall I hit last quarter. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. Allow-list entries expire. 90 days or they are a vulnerability. Is the hang the incomplete patch, or a second bug? I will +rep a listing and −rep a vibe. That is the deal.

I dumped after OEP and then did this. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. 3am isolation notes must fit on a page. I wrote a 12-line script and then threw it away. The listing was enough.

@frankybee

I dumped after OEP and then did this. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. 3am isolation notes must fit

Stop flexing an IDA license. The question was the unwind info. Did this on ARM64 last week — same shape, different pain. You wrote «Not every fix waits for Tuesday». That is the sentence I keep. Jump box is not a desktop. No browser, no mail, no Slack. I will +rep a listing and −rep a vibe. That is the deal.

If you only have the decompiler, you do not have the bug. «Patch Tuesday as a detection: who missed the out-of-band» — specifically Not every fix waits for Tuesday. 3am isolation notes must fit on a page. Version in my shot: current lab snapshot, not last year's blog.

@vx-u

If you only have the decompiler, you do not have the bug. «Patch Tuesday as a detection: who missed the out-of-band» — specifically Not ever

If you cannot paste bytes, you do not have a counterexample. I want the listing, not the decompiler story. On «Patch Tuesday as a detection: who missed the out-of-band»: Not every fix waits for Tuesday. Allow-list entries expire. 90 days or they are a vulnerability. I reproduced it on lab build 1394.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.