>_0xFORUM
Sign in

Uninitialized stack token in a public RPC stub

in Exploits23 replies2.8k views

Patched. The stub did not zero a token and sometimes leaked a handle-shaped value. Detection is a code pattern, not a network signature.

I want YARA-for-code notes, not a capture file.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 23 REPLIES

@flux

Did this on ARM64 last week — same shape, different pain. «Uninitialized stack token in a public RPC stub» — specifically Patched. OOB read

Did this on ARM64 last week — same shape, different pain. You wrote «Patched». That is the sentence I keep. If you wrap memcpy, I want the check on every path. Took me 3 hours the first time.

This is the kind of thread that should be a sticky and is not. «Uninitialized stack token in a public RPC stub» — specifically Patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I reproduced it on lab build 1060.

@Flybancode

I will argue the opposite and then probably agree. On «Uninitialized stack token in a public RPC stub»: Patched. Date your heap notes. 2012

I disagree with the tone, not the bytes. «Uninitialized stack token in a public RPC stub» — specifically Patched. A saturating add that hangs is not a complete patch. Hunt the hang too. I reproduced it on lab build 1066.

Did this on ARM64 last week — same shape, different pain. «Uninitialized stack token in a public RPC stub» — specifically Patched. OOB read is a leak until proven otherwise. In the notes, not in a PoC. After you did that, did the decompiler pick it up or did you dump? Pinned a comment at 0x140004069 in the listing.

I will argue the opposite and then probably agree. You wrote «Patched». That is the sentence I keep. If you wrap memcpy, I want the check on every path. Pinned a comment at 0x140006cf1 in the listing.

@anthonyhub

I will argue the opposite and then probably agree. You wrote «Patched». That is the sentence I keep. If you wrap memcpy, I want the check on

I read the patch. You read a tweet. Those are not the same source. Good. Dated shot, version in the post. The load-bearing line: Patched. A saturating add that hangs is not a complete patch. Hunt the hang too. My note id for this: e0-06.

@bayo_k

Good. Dated shot, version in the post. The load-bearing line: Patched. A saturating add that hangs is not a complete patch. Hunt the hang to

I still keep a paper notebook for this kind of note. You wrote «Patched». That is the sentence I keep. OOB read is a leak until proven otherwise. In the notes, not in a PoC. I still have the snapshot named expl-224-pre.

The screenshot is the useful part of the post. On «Uninitialized stack token in a public RPC stub»: Patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Did page heap see it, or only the sanitizer? Took me 4 hours the first time.

@guard

Good. Dated shot, version in the post. You wrote «Patched». That is the sentence I keep. No samples, even public corpus files. Hashes and li

You are treating a checksum as a signature again. Please keep the hashes and drop the mystery zips. On «Uninitialized stack token in a public RPC stub»: Patched. Canonicalize last. Concatenate after realpath is how .. comes back. Did you force-create the function or did auto-analysis luck into it? Version in my shot: current lab snapshot, not last year's blog.

@christopherx

This is the kind of thread that should be a sticky and is not. «Uninitialized stack token in a public RPC stub» — specifically Patched. Vend

Do not call people skids because they use Ghidra. This matches a public n-day class from last patch Tuesday. «Uninitialized stack token in a public RPC stub» — specifically Patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Took me 2 hours the first time.

I reproduced it twice before I believed you. You wrote «Patched». That is the sentence I keep. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Version in my shot: current lab snapshot, not last year's blog.

I will argue the opposite and then probably agree. On «Uninitialized stack token in a public RPC stub»: Patched. Date your heap notes. 2012 grooming diagrams are history. Version in my shot: current lab snapshot, not last year's blog.

I failed this exact class in January. On «Uninitialized stack token in a public RPC stub»: Patched. system() on a user path is the class. execve with argv is the patch. I wrote a 12-line script and then threw it away. The listing was enough.

Also: If you wrap memcpy, I want the check on every path.

I still keep a paper notebook for this kind of note. The load-bearing line: Patched. system() on a user path is the class. execve with argv is the patch. My note id for this: e0-20.

Also: OOB read is a leak until proven otherwise. In the notes, not in a PoC.

I dumped after OEP and then did this. On «Uninitialized stack token in a public RPC stub»: Patched. system() on a user path is the class. execve with argv is the patch. I reproduced it on lab build 1407.

@darkx

I failed this exact class in January. On «Uninitialized stack token in a public RPC stub»: Patched. system() on a user path is the class. ex

I ran this on a licensed corpus binary. The load-bearing line: Patched. A saturating add that hangs is not a complete patch. Hunt the hang too. Did you snapshot before, or is this a restore-from-memory story? Version in my shot: current lab snapshot, not last year's blog.

@kenwise

I dumped after OEP and then did this. On «Uninitialized stack token in a public RPC stub»: Patched. system() on a user path is the class. ex

I am not moving this to DMs so you can yell. Stay on the class. The screenshot is the useful part of the post. On «Uninitialized stack token in a public RPC stub»: Patched. No samples, even public corpus files. Hashes and links. Attachments get pulled. If anyone DMs me a zip I will not open it. Hash in-thread.

Good. Dated shot, version in the post. You wrote «Patched». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. Same class as the March thread, different binary.

@downtownjay

I ran this on a licensed corpus binary. The load-bearing line: Patched. A saturating add that hangs is not a complete patch. Hunt the hang t

Take the telegram pitch to the bin. Market listing or nothing. I dumped after OEP and then did this. You wrote «Patched». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I reproduced it on lab build 1188.

@henrycube

Please keep the hashes and drop the mystery zips. On «Uninitialized stack token in a public RPC stub»: Patched. Canonicalize last. Concatena

If you only have the decompiler, you do not have the bug. «Uninitialized stack token in a public RPC stub» — specifically Patched. If you wrap memcpy, I want the check on every path. I reproduced it on lab build 1077.

Came back to this after a coffee. Still hold. «Uninitialized stack token in a public RPC stub» — specifically Patched. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Pinned a comment at 0x140006060 in the listing.

@timmyvibes

Came back to this after a coffee. Still hold. «Uninitialized stack token in a public RPC stub» — specifically Patched. OOB read is a leak un

This is the writeup I wanted when I was stuck. You wrote «Patched». That is the sentence I keep. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I still have the snapshot named expl-224-pre.

@virtz

This is the writeup I wanted when I was stuck. You wrote «Patched». That is the sentence I keep. Vendor bump is patch Tuesday. Forgotten tre

I am not moving this to DMs so you can yell. Stay on the class. Good. Dated shot, version in the post. «Uninitialized stack token in a public RPC stub» — specifically Patched. OOB read is a leak until proven otherwise. In the notes, not in a PoC. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.