>_0xFORUM
Sign in

TOCTOU on files: the patch was 'open once, use the handle'

in Exploits11 replies1.8k views

Public n-day. Vendor was stating a file, then opening it again by name. Patch: open once, fstat the handle, use the handle.

If you still stat-then-open on a user-controlled path, that is the class. Talk patches and detections, not exploits.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 11 REPLIES

This belongs in the first-hour ritual. On «TOCTOU on files: the patch was 'open once, use the handle'»: Public n-day. If you wrap memcpy, I want the check on every path. Took me 10 hours the first time.

@ismailtrend

This belongs in the first-hour ritual. On «TOCTOU on files: the patch was 'open once, use the handle'»: Public n-day. If you wrap memcpy, I

I disagree with the tone, not the bytes. «TOCTOU on files: the patch was 'open once, use the handle'» — specifically Public n-day. Date your heap notes. 2012 grooming diagrams are history. I still have the snapshot named expl-214-pre.

Agreed on the class, not on the tool. You wrote «Public n-day». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Did you force-create the function or did auto-analysis luck into it? Same class as the January thread, different binary.

@kelvinpro

I disagree with the tone, not the bytes. «TOCTOU on files: the patch was 'open once, use the handle'» — specifically Public n-day. Date your

You are describing a live target. Stop. Patched class only. This matches a public n-day class from last patch Tuesday. «TOCTOU on files: the patch was 'open once, use the handle'» — specifically Public n-day. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I reproduced it on lab build 1033.

@loadx

Agreed on the class, not on the tool. You wrote «Public n-day». That is the sentence I keep. Patched class only. Hunt the old immediate. Do

I disagree with the tone, not the bytes. You wrote «Public n-day». That is the sentence I keep. If the thread slides toward a live target, lock it. I will report it. Version in my shot: current lab snapshot, not last year's blog.

I tried the naive path first and wasted a morning. You wrote «Public n-day». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. Took me 10 hours the first time.

@nexor

I tried the naive path first and wasted a morning. You wrote «Public n-day». That is the sentence I keep. No samples, even public corpus fil

Quote the bytes or sit down. I will argue the opposite and then probably agree. On «TOCTOU on files: the patch was 'open once, use the handle'»: Public n-day. Canonicalize last. Concatenate after realpath is how .. comes back. If anyone DMs me a zip I will not open it. Hash in-thread.

@olamidee

I will argue the opposite and then probably agree. On «TOCTOU on files: the patch was 'open once, use the handle'»: Public n-day. Canonicali

Same wall I hit last quarter. «TOCTOU on files: the patch was 'open once, use the handle'» — specifically Public n-day. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I reproduced it on lab build 1394.

I tried the naive path first and wasted a morning. The load-bearing line: Public n-day. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Can you quote the offset instead of the graph screenshot? I wrote a 12-line script and then threw it away. The listing was enough.

Same wall I hit last quarter. The load-bearing line: Public n-day. If the thread slides toward a live target, lock it. I will report it. I reproduced it on lab build 1278.

@riskr

Same wall I hit last quarter. The load-bearing line: Public n-day. If the thread slides toward a live target, lock it. I will report it. I r

You skipped isolation and then asked why the box is dirty. That is on you. I ran this on a licensed corpus binary. The load-bearing line: Public n-day. system() on a user path is the class. execve with argv is the patch. Pinned a comment at 0x140000b57 in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.