>_0xFORUM
Sign in

Signedness in a length compare, public PNG-adjacent class

in Exploits6 replies3.7k views

size_t vs int. The compare looked fine in the decompiler until you noticed the int. Patched.

Decompilers lie about signedness. Listing first.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 6 REPLIES

@zer0x

This belongs in the first-hour ritual. The load-bearing line: size_t vs int. Patched class only. Hunt the old immediate. Do not ask for a tr

Quote the bytes or sit down. The screenshot is the useful part of the post. You wrote «size_t vs int». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. If anyone DMs me a zip I will not open it. Hash in-thread.

Bookmarking this for the lab wiki. On «Signedness in a length compare, public PNG-adjacent class»: size_t vs int. If you wrap memcpy, I want the check on every path. I reproduced it on lab build 1296.

@stackr

Bookmarking this for the lab wiki. On «Signedness in a length compare, public PNG-adjacent class»: size_t vs int. If you wrap memcpy, I want

You are describing a live target. Stop. Patched class only. Bookmarking this for the lab wiki. You wrote «size_t vs int». That is the sentence I keep. If you wrap memcpy, I want the check on every path. I will +rep a listing and −rep a vibe. That is the deal.

Did this on ARM64 last week — same shape, different pain. The load-bearing line: size_t vs int. No samples, even public corpus files. Hashes and links. Attachments get pulled. If anyone DMs me a zip I will not open it. Hash in-thread.

@vectx

Did this on ARM64 last week — same shape, different pain. The load-bearing line: size_t vs int. No samples, even public corpus files. Hashes

Take the telegram pitch to the bin. Market listing or nothing. I would have written the opposite conclusion a year ago. «Signedness in a length compare, public PNG-adjacent class» — specifically size_t vs int. system() on a user path is the class. execve with argv is the patch. Is the hang the incomplete patch, or a second bug? Took me 12 hours the first time.

@warden

I would have written the opposite conclusion a year ago. «Signedness in a length compare, public PNG-adjacent class» — specifically size_t v

This belongs in the first-hour ritual. The load-bearing line: size_t vs int. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Version in my shot: current lab snapshot, not last year's blog.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.