>_0xFORUM
Sign in

A one-page 'if you are paged at 3am' for isolation

in Defense27 replies1.2k views

Unplug is not always right. The page says: isolate NIC, snapshot if VM, do not reboot yet, call the human. Reboot is a last resort.

3am instructions must fit on a page. Ours do.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 27 REPLIES

Did this on ARM64 last week — same shape, different pain. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. If anyone DMs me a zip I will not open it. Hash in-thread.

@bytefx

Did this on ARM64 last week — same shape, different pain. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always righ

Please keep the hashes and drop the mystery zips. «A one-page 'if you are paged at 3am' for isolation» — specifically Unplug is not always right. Allow-list entries expire. 90 days or they are a vulnerability. Took me 10 hours the first time.

@cryptz

Quietly the best note on this board this month. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. Snapsho

I dumped after OEP and then did this. «A one-page 'if you are paged at 3am' for isolation» — specifically Unplug is not always right. Snapshot or it did not happen. I will not restore your VM again. Version in my shot: current lab snapshot, not last year's blog.

@chrisvibe

Please keep the hashes and drop the mystery zips. «A one-page 'if you are paged at 3am' for isolation» — specifically Unplug is not always r

This is getting personal and it does not need to. Same wall I hit last quarter. The load-bearing line: Unplug is not always right. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Pinned a comment at 0x140004f9b in the listing.

Quietly the best note on this board this month. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. Snapshot or it did not happen. I will not restore your VM again. Which build of the tool? I got burned mixing notes across versions. Version in my shot: current lab snapshot, not last year's blog.

@encodr

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Unplug is not always right. 3am isolation notes must fit on

Agreed on the class, not on the tool. You wrote «Unplug is not always right». That is the sentence I keep. Allow-list entries expire. 90 days or they are a vulnerability. I will +rep a listing and −rep a vibe. That is the deal.

I will argue the opposite and then probably agree. The load-bearing line: Unplug is not always right. Isolate the host too, or stop calling the guest isolated. Hash of the public file, or are we arguing a shape? I will +rep a listing and −rep a vibe. That is the deal.

If you only have the decompiler, you do not have the bug. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. Jump box is not a desktop. No browser, no mail, no Slack. I reproduced it on lab build 1187.

Came back to this after a coffee. Still hold. The load-bearing line: Unplug is not always right. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I reproduced it on lab build 1335.

@dropx

Came back to this after a coffee. Still hold. The load-bearing line: Unplug is not always right. Host-only NIC, no shared folders, no drag-d

I am reporting the sample-drop hint. Hash and corpus tag only. Did this on ARM64 last week — same shape, different pain. The load-bearing line: Unplug is not always right. 3am isolation notes must fit on a page. Version in my shot: current lab snapshot, not last year's blog.

I ran this on a licensed corpus binary. The load-bearing line: Unplug is not always right. Allow-list entries expire. 90 days or they are a vulnerability. Took me 9 hours the first time.

@guardx

If you only have the decompiler, you do not have the bug. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always righ

Stop flexing an IDA license. The question was the unwind info. I want the listing, not the decompiler story. The load-bearing line: Unplug is not always right. Jump box is not a desktop. No browser, no mail, no Slack. I wrote a 12-line script and then threw it away. The listing was enough.

@jasonconnect

I ran this on a licensed corpus binary. The load-bearing line: Unplug is not always right. Firewall rules not in the repo are unreviewed cod

I will argue the opposite and then probably agree. The load-bearing line: Unplug is not always right. Allow-list entries expire. 90 days or they are a vulnerability. Did page heap see it, or only the sanitizer? I still have the snapshot named defe-205-pre.

I reproduced it twice before I believed you. The load-bearing line: Unplug is not always right. Allow-list entries expire. 90 days or they are a vulnerability. Version in my shot: current lab snapshot, not last year's blog.

@ken_davids

I will argue the opposite and then probably agree. The load-bearing line: Unplug is not always right. Allow-list entries expire. 90 days or

That is a vibe. I asked for a listing offset. This matches a public n-day class from last patch Tuesday. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. Full disk is a detection gap. Rate-limit logs, alert at 70%. Pinned a comment at 0x140006dcd in the listing.

I ran this on a licensed corpus binary. The load-bearing line: Unplug is not always right. Firewall rules not in the repo are unreviewed code. My note id for this: cd-12.

Also: Full disk is a detection gap. Rate-limit logs, alert at 70%.

@logic

I reproduced it twice before I believed you. The load-bearing line: Unplug is not always right. Allow-list entries expire. 90 days or they a

This belongs in the first-hour ritual. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. Firewall rules not in the repo are unreviewed code. Version in my shot: current lab snapshot, not last year's blog.

I will argue the opposite and then probably agree. «A one-page 'if you are paged at 3am' for isolation» — specifically Unplug is not always right. Firewall rules not in the repo are unreviewed code. Pinned a comment at 0x1400041e7 in the listing.

@nite

I will argue the opposite and then probably agree. «A one-page 'if you are paged at 3am' for isolation» — specifically Unplug is not always

You keep moving the goalposts. First it was the decoder, now it is the dump. The screenshot is the useful part of the post. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. Jump box is not a desktop. No browser, no mail, no Slack. Did you force-create the function or did auto-analysis luck into it? Pinned a comment at 0x140002a4a in the listing.

@omega

The screenshot is the useful part of the post. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. Jump box

I still keep a paper notebook for this kind of note. «A one-page 'if you are paged at 3am' for isolation» — specifically Unplug is not always right. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I wrote a 12-line script and then threw it away. The listing was enough.

Came back to this after a coffee. Still hold. You wrote «Unplug is not always right». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. My note id for this: cd-20.

Also: Firewall rules not in the repo are unreviewed code.

I dumped after OEP and then did this. The load-bearing line: Unplug is not always right. If debug requires turning the control off, the debug story is wrong. If anyone DMs me a zip I will not open it. Hash in-thread.

@rseclab

I dumped after OEP and then did this. The load-bearing line: Unplug is not always right. If debug requires turning the control off, the debu

This is getting personal and it does not need to. Quietly the best note on this board this month. You wrote «Unplug is not always right». That is the sentence I keep. If debug requires turning the control off, the debug story is wrong. Pinned a comment at 0x14000697c in the listing.

Bookmarking this for the lab wiki. On «A one-page 'if you are paged at 3am' for isolation»: Unplug is not always right. If debug requires turning the control off, the debug story is wrong. Did page heap see it, or only the sanitizer? My note id for this: cd-23.

Came back to this after a coffee. Still hold. You wrote «Unplug is not always right». That is the sentence I keep. Firewall rules not in the repo are unreviewed code. If anyone DMs me a zip I will not open it. Hash in-thread.

@streetwise

Came back to this after a coffee. Still hold. You wrote «Unplug is not always right». That is the sentence I keep. Firewall rules not in the

This belongs in the first-hour ritual. You wrote «Unplug is not always right». That is the sentence I keep. If debug requires turning the control off, the debug story is wrong. Same class as the October thread, different binary.

@trendguy

This belongs in the first-hour ritual. You wrote «Unplug is not always right». That is the sentence I keep. If debug requires turning the co

I am reporting the sample-drop hint. Hash and corpus tag only. This belongs in the first-hour ritual. You wrote «Unplug is not always right». That is the sentence I keep. Isolate the host too, or stop calling the guest isolated. Same class as the January thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.