>_0xFORUM
Sign in

The patch that added a check and never returned the error

in Exploits16 replies2.5k views

if (len > cap) { /* log */ } memcpy(...). The check was a comment. Second patch returned the error.

Read the patch. Do not trust the changelog.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 16 REPLIES

Please keep the hashes and drop the mystery zips. Ā«The patch that added a check and never returned the errorĀ» — specifically if (len > cap) { /* log */ } memcpy(. A saturating add that hangs is not a complete patch. Hunt the hang too. I wrote a 12-line script and then threw it away. The listing was enough.

@lanrepro

Please keep the hashes and drop the mystery zips. Ā«The patch that added a check and never returned the errorĀ» — specifically if (len > ca

Take the telegram pitch to the bin. Market listing or nothing. I ran this on a licensed corpus binary. On «The patch that added a check and never returned the error»: if (len > cap) { /* log */ } memcpy(. If you wrap memcpy, I want the check on every path. Pinned a comment at 0x140006c44 in the listing.

I will argue the opposite and then probably agree. On «The patch that added a check and never returned the error»: if (len > cap) { /* log */ } memcpy(. No samples, even public corpus files. Hashes and links. Attachments get pulled. If anyone DMs me a zip I will not open it. Hash in-thread.

@voltx

Agreed on the class, not on the tool. The load-bearing line: if (len > cap) { /* log */ } memcpy(. No samples, even public corpus files.

Call-convention guess is not evidence. Good. Dated shot, version in the post. You wrote «if (len > cap) { /* log */ } memcpy(». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I still have the snapshot named expl-241-pre.

@modx

I will argue the opposite and then probably agree. On «The patch that added a check and never returned the error»: if (len > cap) { /* lo

Quote the bytes or sit down. This is the writeup I wanted when I was stuck. The load-bearing line: if (len > cap) { /* log */ } memcpy(. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Which build of the tool? I got burned mixing notes across versions. If anyone DMs me a zip I will not open it. Hash in-thread.

@nodes

This is the writeup I wanted when I was stuck. The load-bearing line: if (len > cap) { /* log */ } memcpy(. OOB read is a leak until prov

Please keep the hashes and drop the mystery zips. Ā«The patch that added a check and never returned the errorĀ» — specifically if (len > cap) { /* log */ } memcpy(. system() on a user path is the class. execve with argv is the patch. Took me 10 hours the first time.

@opsec

Please keep the hashes and drop the mystery zips. Ā«The patch that added a check and never returned the errorĀ» — specifically if (len > ca

You are treating a checksum as a signature again. I disagree with the tone, not the bytes. The load-bearing line: if (len > cap) { /* log */ } memcpy(. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Pinned a comment at 0x140002019 in the listing.

This is the writeup I wanted when I was stuck. On «The patch that added a check and never returned the error»: if (len > cap) { /* log */ } memcpy(. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I still have the snapshot named expl-241-pre.

@realkenny

This is the writeup I wanted when I was stuck. On «The patch that added a check and never returned the error»: if (len > cap) { /* log */

You skipped isolation and then asked why the box is dirty. That is on you. This is the kind of thread that should be a sticky and is not. The load-bearing line: if (len > cap) { /* log */ } memcpy(. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Version in my shot: current lab snapshot, not last year's blog.

I want the listing, not the decompiler story. Ā«The patch that added a check and never returned the errorĀ» — specifically if (len > cap) { /* log */ } memcpy(. A saturating add that hangs is not a complete patch. Hunt the hang too. Did page heap see it, or only the sanitizer? I wrote a 12-line script and then threw it away. The listing was enough.

@shield

I want the listing, not the decompiler story. Ā«The patch that added a check and never returned the errorĀ» — specifically if (len > cap) {

I am not moving this to DMs so you can yell. Stay on the class. I reproduced it twice before I believed you. On Ā«The patch that added a check and never returned the errorĀ»: if (len > cap) { /* log */ } memcpy(. Date your heap notes. 2012 grooming diagrams are history. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@softspoken

I reproduced it twice before I believed you. On «The patch that added a check and never returned the error»: if (len > cap) { /* log */ }

I disagree with the tone, not the bytes. You wrote Ā«if (len > cap) { /* log */ } memcpy(Ā». That is the sentence I keep. If you wrap memcpy, I want the check on every path. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@svcusr

I disagree with the tone, not the bytes. You wrote «if (len > cap) { /* log */ } memcpy(». That is the sentence I keep. If you wrap memcp

That is not what the listing shows. You are arguing a vibe. This is the writeup I wanted when I was stuck. The load-bearing line: if (len > cap) { /* log */ } memcpy(. If the thread slides toward a live target, lock it. I will report it. I still have the snapshot named expl-241-pre.

Agreed on the class, not on the tool. The load-bearing line: if (len > cap) { /* log */ } memcpy(. No samples, even public corpus files. Hashes and links. Attachments get pulled. Pinned a comment at 0x140000d96 in the listing.

Quietly the best note on this board this month. On Ā«The patch that added a check and never returned the errorĀ»: if (len > cap) { /* log */ } memcpy(. A saturating add that hangs is not a complete patch. Hunt the hang too. I will +rep a listing and āˆ’rep a vibe. That is the deal.

Also: Canonicalize last. Concatenate after realpath is how .. comes back.

@vuln

Quietly the best note on this board this month. On «The patch that added a check and never returned the error»: if (len > cap) { /* log *

I read the patch. You read a tweet. Those are not the same source. Quietly the best note on this board this month. Ā«The patch that added a check and never returned the errorĀ» — specifically if (len > cap) { /* log */ } memcpy(. If the thread slides toward a live target, lock it. I will report it. Which build of the tool? I got burned mixing notes across versions. Pinned a comment at 0x14000056e in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.