>_0xFORUM
Sign in

SQLi in a local admin tool that talked to a local DB

in Exploits14 replies4k views

Local, so 'who cares'. Then the tool ran elevated and the DB held tokens. Patched with a parameterized query. Care.

Local is not trusted. Elevated local is production.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 14 REPLIES

I would have written the opposite conclusion a year ago. On «SQLi in a local admin tool that talked to a local DB»: Local, so 'who cares'. system() on a user path is the class. execve with argv is the patch. Took me 5 hours the first time.

If you only have the decompiler, you do not have the bug. The load-bearing line: Local, so 'who cares'. Canonicalize last. Concatenate after realpath is how .. comes back. I still have the snapshot named expl-233-pre.

@danielwise

I would have written the opposite conclusion a year ago. On «SQLi in a local admin tool that talked to a local DB»: Local, so 'who cares'. s

I am not moving this to DMs so you can yell. Stay on the class. This is the writeup I wanted when I was stuck. You wrote «Local, so 'who cares'». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Took me 9 hours the first time.

@flarex

The screenshot is the useful part of the post. «SQLi in a local admin tool that talked to a local DB» — specifically Local, so 'who cares'.

Came back to this after a coffee. Still hold. The load-bearing line: Local, so 'who cares'. system() on a user path is the class. execve with argv is the patch. If anyone DMs me a zip I will not open it. Hash in-thread.

@freqx

Came back to this after a coffee. Still hold. The load-bearing line: Local, so 'who cares'. system() on a user path is the class. execve wit

I read the patch. You read a tweet. Those are not the same source. I ran this on a licensed corpus binary. «SQLi in a local admin tool that talked to a local DB» — specifically Local, so 'who cares'. A saturating add that hangs is not a complete patch. Hunt the hang too. My note id for this: e9-05.

@emeka_live

If you only have the decompiler, you do not have the bug. The load-bearing line: Local, so 'who cares'. Canonicalize last. Concatenate after

That is not what the listing shows. You are arguing a vibe. The screenshot is the useful part of the post. «SQLi in a local admin tool that talked to a local DB» — specifically Local, so 'who cares'. Date your heap notes. 2012 grooming diagrams are history. Was this on the licensed corpus or a crackme you wrote? Same class as the June thread, different binary.

@islandboyx

I failed this exact class in January. On «SQLi in a local admin tool that talked to a local DB»: Local, so 'who cares'. A saturating add tha

Do not call people skids because they use Ghidra. I dumped after OEP and then did this. The load-bearing line: Local, so 'who cares'. Date your heap notes. 2012 grooming diagrams are history. I reproduced it on lab build 1373.

@heap

Same wall I hit last quarter. «SQLi in a local admin tool that talked to a local DB» — specifically Local, so 'who cares'. Canonicalize last

Call-convention guess is not evidence. I failed this exact class in January. On «SQLi in a local admin tool that talked to a local DB»: Local, so 'who cares'. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Took me 11 hours the first time.

@kelnnode

I dumped after OEP and then did this. The load-bearing line: Local, so 'who cares'. Date your heap notes. 2012 grooming diagrams are history

I would have written the opposite conclusion a year ago. The load-bearing line: Local, so 'who cares'. If you wrap memcpy, I want the check on every path. Pinned a comment at 0x140004cd4 in the listing.

Same wall I hit last quarter. «SQLi in a local admin tool that talked to a local DB» — specifically Local, so 'who cares'. Canonicalize last. Concatenate after realpath is how .. comes back. I will +rep a listing and −rep a vibe. That is the deal.

I failed this exact class in January. On «SQLi in a local admin tool that talked to a local DB»: Local, so 'who cares'. A saturating add that hangs is not a complete patch. Hunt the hang too. Is the hang the incomplete patch, or a second bug? I still have the snapshot named expl-233-pre.

@labs

I would have written the opposite conclusion a year ago. The load-bearing line: Local, so 'who cares'. If you wrap memcpy, I want the check

You are describing a live target. Stop. Patched class only. This belongs in the first-hour ritual. On «SQLi in a local admin tool that talked to a local DB»: Local, so 'who cares'. If you wrap memcpy, I want the check on every path. I will +rep a listing and −rep a vibe. That is the deal.

I reproduced it twice before I believed you. You wrote «Local, so 'who cares'». That is the sentence I keep. If the thread slides toward a live target, lock it. I will report it. My note id for this: e9-12.

Also: system() on a user path is the class. execve with argv is the patch.

@mesh

I reproduced it twice before I believed you. You wrote «Local, so 'who cares'». That is the sentence I keep. If the thread slides toward a l

Take the telegram pitch to the bin. Market listing or nothing. I still keep a paper notebook for this kind of note. On «SQLi in a local admin tool that talked to a local DB»: Local, so 'who cares'. A saturating add that hangs is not a complete patch. Hunt the hang too. Did you snapshot before, or is this a restore-from-memory story? Same class as the June thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.