>_0xFORUM
Sign in

Path canonicalization bugs that survive 'we use realpath'

in Exploits9 replies4.5k views

realpath then concatenate. The concatenate reintroduced .. . Public, patched, embarrassing.

Canonicalize last, or stop concatenating.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

@xcrypt

I will argue the opposite and then probably agree. You wrote «realpath then concatenate». That is the sentence I keep. A saturating add that

You skipped isolation and then asked why the box is dirty. That is on you. I still keep a paper notebook for this kind of note. The load-bearing line: realpath then concatenate. No samples, even public corpus files. Hashes and links. Attachments get pulled. I will +rep a listing and āˆ’rep a vibe. That is the deal.

I would have written the opposite conclusion a year ago. The load-bearing line: realpath then concatenate. Patched class only. Hunt the old immediate. Do not ask for a trigger file. After you did that, did the decompiler pick it up or did you dump? I reproduced it on lab build 1344.

Same wall I hit last quarter. The load-bearing line: realpath then concatenate. Date your heap notes. 2012 grooming diagrams are history. I wrote a 12-line script and then threw it away. The listing was enough.

@rsec

Same wall I hit last quarter. The load-bearing line: realpath then concatenate. Date your heap notes. 2012 grooming diagrams are history. I

Take the telegram pitch to the bin. Market listing or nothing. Did this on ARM64 last week — same shape, different pain. Ā«Path canonicalization bugs that survive 'we use realpath'Ā» — specifically realpath then concatenate. If the thread slides toward a live target, lock it. I will report it. Pinned a comment at 0x140002529 in the listing.

I tried the naive path first and wasted a morning. The load-bearing line: realpath then concatenate. If you wrap memcpy, I want the check on every path. If anyone DMs me a zip I will not open it. Hash in-thread.

@sock

I tried the naive path first and wasted a morning. The load-bearing line: realpath then concatenate. If you wrap memcpy, I want the check on

Quote the bytes or sit down. I will argue the opposite and then probably agree. The load-bearing line: realpath then concatenate. system() on a user path is the class. execve with argv is the patch. Is the hang the incomplete patch, or a second bug? I will +rep a listing and āˆ’rep a vibe. That is the deal.

@stan_kay

I will argue the opposite and then probably agree. The load-bearing line: realpath then concatenate. system() on a user path is the class. e

I dumped after OEP and then did this. On «Path canonicalization bugs that survive 'we use realpath'»: realpath then concatenate. If the thread slides toward a live target, lock it. I will report it. If anyone DMs me a zip I will not open it. Hash in-thread.

@tonybliss

I dumped after OEP and then did this. On «Path canonicalization bugs that survive 'we use realpath'»: realpath then concatenate. If the thre

You are treating a checksum as a signature again. The screenshot is the useful part of the post. Ā«Path canonicalization bugs that survive 'we use realpath'Ā» — specifically realpath then concatenate. Date your heap notes. 2012 grooming diagrams are history. My note id for this: dd-05.

I will argue the opposite and then probably agree. You wrote «realpath then concatenate». That is the sentence I keep. A saturating add that hangs is not a complete patch. Hunt the hang too. I reproduced it on lab build 1059.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.