>_0xFORUM
Sign in

Command injection in a 'helper' that called system()

in Exploits16 replies2k views

Public appliance, patched. The helper concatenated a filename into system(). The patch is execve with argv.

If your appliance still has system() on a user path, that is the class. No payloads in this thread.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 16 REPLIES

I would have written the opposite conclusion a year ago. You wrote «Public appliance, patched». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. Version in my shot: current lab snapshot, not last year's blog.

Not fully convinced yet. The load-bearing line: Public appliance, patched. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Same class as the October thread, different binary.

@abdulpro

I would have written the opposite conclusion a year ago. You wrote «Public appliance, patched». That is the sentence I keep. No samples, eve

Call-convention guess is not evidence. Same wall I hit last quarter. The load-bearing line: Public appliance, patched. No samples, even public corpus files. Hashes and links. Attachments get pulled. If anyone DMs me a zip I will not open it. Hash in-thread.

@bukunmivibe

Did this on ARM64 last week — same shape, different pain. «Command injection in a 'helper' that called system()» — specifically Public appli

You are describing a live target. Stop. Patched class only. I failed this exact class in January. The load-bearing line: Public appliance, patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I still have the snapshot named expl-227-pre.

Quietly the best note on this board this month. On «Command injection in a 'helper' that called system()»: Public appliance, patched. If you wrap memcpy, I want the check on every path. Hash of the public file, or are we arguing a shape? My note id for this: e3-08.

@enc0de

I want the listing, not the decompiler story. You wrote «Public appliance, patched». That is the sentence I keep. Patched class only. Hunt t

You are treating a checksum as a signature again. This is the kind of thread that should be a sticky and is not. On «Command injection in a 'helper' that called system()»: Public appliance, patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I will +rep a listing and −rep a vibe. That is the deal.

@bashirhub

Not fully convinced yet. The load-bearing line: Public appliance, patched. OOB read is a leak until proven otherwise. In the notes, not in a

Do not call people skids because they use Ghidra. Agreed on the class, not on the tool. On «Command injection in a 'helper' that called system()»: Public appliance, patched. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Can you quote the offset instead of the graph screenshot? Version in my shot: current lab snapshot, not last year's blog.

@darknet

Quietly the best note on this board this month. On «Command injection in a 'helper' that called system()»: Public appliance, patched. If you

Quote the bytes or sit down. This is the writeup I wanted when I was stuck. «Command injection in a 'helper' that called system()» — specifically Public appliance, patched. A saturating add that hangs is not a complete patch. Hunt the hang too. I wrote a 12-line script and then threw it away. The listing was enough.

@block

Agreed on the class, not on the tool. On «Command injection in a 'helper' that called system()»: Public appliance, patched. Patched class on

Did this on ARM64 last week — same shape, different pain. «Command injection in a 'helper' that called system()» — specifically Public appliance, patched. If you wrap memcpy, I want the check on every path. Pinned a comment at 0x1400022aa in the listing.

@cmdx

I tried the naive path first and wasted a morning. The load-bearing line: Public appliance, patched. Date your heap notes. 2012 grooming dia

Take the telegram pitch to the bin. Market listing or nothing. I dumped after OEP and then did this. You wrote «Public appliance, patched». That is the sentence I keep. system() on a user path is the class. execve with argv is the patch. Pinned a comment at 0x140006177 in the listing.

I tried the naive path first and wasted a morning. The load-bearing line: Public appliance, patched. Date your heap notes. 2012 grooming diagrams are history. Same class as the March thread, different binary.

@dotunhub

This is the writeup I wanted when I was stuck. «Command injection in a 'helper' that called system()» — specifically Public appliance, patch

I want the listing, not the decompiler story. You wrote «Public appliance, patched». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Version in my shot: current lab snapshot, not last year's blog.

@heapz

I ran this on a licensed corpus binary. «Command injection in a 'helper' that called system()» — specifically Public appliance, patched. If

I am not moving this to DMs so you can yell. Stay on the class. Came back to this after a coffee. Still hold. «Command injection in a 'helper' that called system()» — specifically Public appliance, patched. No samples, even public corpus files. Hashes and links. Attachments get pulled. Version in my shot: current lab snapshot, not last year's blog.

Not fully convinced yet. The load-bearing line: Public appliance, patched. If the thread slides toward a live target, lock it. I will report it. Same class as the October thread, different binary.

Also: If the thread slides toward a live target, lock it. I will report it.

@g4te

Not fully convinced yet. The load-bearing line: Public appliance, patched. If the thread slides toward a live target, lock it. I will report

You skipped isolation and then asked why the box is dirty. That is on you. I dumped after OEP and then did this. The load-bearing line: Public appliance, patched. No samples, even public corpus files. Hashes and links. Attachments get pulled. Did page heap see it, or only the sanitizer? I will +rep a listing and −rep a vibe. That is the deal.

I ran this on a licensed corpus binary. «Command injection in a 'helper' that called system()» — specifically Public appliance, patched. If you wrap memcpy, I want the check on every path. Version in my shot: current lab snapshot, not last year's blog.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.