>_0xFORUM
Sign in

The ioctl that should have been a FILE_DEVICE check

in Exploits20 replies5.9k views

Public driver n-day. IOCTL from user, no device check, METHOD_NEITHER nostalgia. Patch added the check.

Hunt old drivers that still expose the ioctl. Do not ask for the triggering blob.

Refs: CVE Program · MSRC

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 20 REPLIES

@hex_olga

Bookmarking this for the lab wiki. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. A saturating ad

Take the telegram pitch to the bin. Market listing or nothing. Please keep the hashes and drop the mystery zips. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. Date your heap notes. 2012 grooming diagrams are history. My note id for this: dc-10.

Bookmarking this for the lab wiki. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. A saturating add that hangs is not a complete patch. Hunt the hang too. I reproduced it on lab build 1399.

@buffx

Agreed on the class, not on the tool. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. Vendor bump

You are treating a checksum as a signature again. Agreed on the class, not on the tool. The load-bearing line: Public driver n-day. Canonicalize last. Concatenate after realpath is how .. comes back. Version in my shot: current lab snapshot, not last year's blog.

I still keep a paper notebook for this kind of note. The load-bearing line: Public driver n-day. No samples, even public corpus files. Hashes and links. Attachments get pulled. I reproduced it on lab build 1327.

@black

Please keep the hashes and drop the mystery zips. You wrote «Public driver n-day». That is the sentence I keep. Patched class only. Hunt the

Agreed on the class, not on the tool. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Is the hang the incomplete patch, or a second bug? I will +rep a listing and −rep a vibe. That is the deal.

@cloud

Same wall I hit last quarter. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. No samples, even public corpus

I would have written the opposite conclusion a year ago. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. A saturating add that hangs is not a complete patch. Hunt the hang too. I still have the snapshot named expl-220-pre.

@danielwise

I would have written the opposite conclusion a year ago. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver

I am not moving this to DMs so you can yell. Stay on the class. Same wall I hit last quarter. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. A saturating add that hangs is not a complete patch. Hunt the hang too. Hash of the public file, or are we arguing a shape? Pinned a comment at 0x140006787 in the listing.

Please keep the hashes and drop the mystery zips. You wrote «Public driver n-day». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I still have the snapshot named expl-220-pre.

Also: Date your heap notes. 2012 grooming diagrams are history.

I would have written the opposite conclusion a year ago. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Version in my shot: current lab snapshot, not last year's blog.

Same wall I hit last quarter. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. No samples, even public corpus files. Hashes and links. Attachments get pulled. Pinned a comment at 0x1400003c1 in the listing.

@derekconnect

Same wall I hit last quarter. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. A saturating add that hangs is

Agreed on the class, not on the tool. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. No samples, even public corpus files. Hashes and links. Attachments get pulled. I wrote a 12-line script and then threw it away. The listing was enough.

I dumped after OEP and then did this. You wrote «Public driver n-day». That is the sentence I keep. If you wrap memcpy, I want the check on every path. My note id for this: dc-00.

@prosmart

I dumped after OEP and then did this. You wrote «Public driver n-day». That is the sentence I keep. If you wrap memcpy, I want the check on

I disagree with the tone, not the bytes. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. If the thread slides toward a live target, lock it. I will report it. I still have the snapshot named expl-220-pre.

@richkiddo

I disagree with the tone, not the bytes. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. If the th

I read the patch. You read a tweet. Those are not the same source. I will argue the opposite and then probably agree. The load-bearing line: Public driver n-day. system() on a user path is the class. execve with argv is the patch. Pinned a comment at 0x140000192 in the listing.

Did this on ARM64 last week — same shape, different pain. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver n-day. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Did page heap see it, or only the sanitizer? Pinned a comment at 0x140004e60 in the listing.

@slim_tony

Did this on ARM64 last week — same shape, different pain. «The ioctl that should have been a FILE_DEVICE check» — specifically Public driver

Good. Dated shot, version in the post. The load-bearing line: Public driver n-day. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Same class as the January thread, different binary.

Good. Dated shot, version in the post. The load-bearing line: Public driver n-day. A saturating add that hangs is not a complete patch. Hunt the hang too. Same class as the October thread, different binary.

@thndr

Good. Dated shot, version in the post. The load-bearing line: Public driver n-day. A saturating add that hangs is not a complete patch. Hunt

Do not call people skids because they use Ghidra. Please keep the hashes and drop the mystery zips. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. system() on a user path is the class. execve with argv is the patch. Same class as the June thread, different binary.

@vibeking

Please keep the hashes and drop the mystery zips. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. system() on

I will argue the opposite and then probably agree. On «The ioctl that should have been a FILE_DEVICE check»: Public driver n-day. system() on a user path is the class. execve with argv is the patch. I will +rep a listing and −rep a vibe. That is the deal.

Quietly the best note on this board this month. You wrote «Public driver n-day». That is the sentence I keep. A saturating add that hangs is not a complete patch. Hunt the hang too. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.