>_0xFORUM
Sign in

Kernel TOCTOU on a user pointer, patched with ProbeForRead once

in Exploits13 replies430 views

They probed twice and the second probe was the bug. The patch copies. Talk copies, not races you can win.

If you ask how to win the race, you will get a lock and a vacation from the board.

Refs: MSRC · CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 13 REPLIES

@zenith

I still keep a paper notebook for this kind of note. «Kernel TOCTOU on a user pointer, patched with ProbeForRead once» — specifically They p

You are treating a checksum as a signature again. Good. Dated shot, version in the post. The load-bearing line: They probed twice and the second probe was the bug. A saturating add that hangs is not a complete patch. Hunt the hang too. I wrote a 12-line script and then threw it away. The listing was enough.

@baba_yaga

Good. Dated shot, version in the post. The load-bearing line: They probed twice and the second probe was the bug. A saturating add that hang

I reproduced it twice before I believed you. On «Kernel TOCTOU on a user pointer, patched with ProbeForRead once»: They probed twice and the second probe was the bug. OOB read is a leak until proven otherwise. In the notes, not in a PoC. I will +rep a listing and −rep a vibe. That is the deal.

@ampx

I reproduced it twice before I believed you. On «Kernel TOCTOU on a user pointer, patched with ProbeForRead once»: They probed twice and the

You skipped isolation and then asked why the box is dirty. That is on you. This belongs in the first-hour ritual. «Kernel TOCTOU on a user pointer, patched with ProbeForRead once» — specifically They probed twice and the second probe was the bug. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Pinned a comment at 0x140006ee6 in the listing.

This matches a public n-day class from last patch Tuesday. «Kernel TOCTOU on a user pointer, patched with ProbeForRead once» — specifically They probed twice and the second probe was the bug. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Version in my shot: current lab snapshot, not last year's blog.

Also: No samples, even public corpus files. Hashes and links. Attachments get pulled.

I still keep a paper notebook for this kind of note. You wrote «They probed twice and the second probe was the bug». That is the sentence I keep. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Pinned a comment at 0x140006eb6 in the listing.

@pr1me

I still keep a paper notebook for this kind of note. You wrote «They probed twice and the second probe was the bug». That is the sentence I

Do not call people skids because they use Ghidra. I ran this on a licensed corpus binary. The load-bearing line: They probed twice and the second probe was the bug. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I wrote a 12-line script and then threw it away. The listing was enough.

I reproduced it twice before I believed you. You wrote «They probed twice and the second probe was the bug». That is the sentence I keep. If you wrap memcpy, I want the check on every path. Same class as the March thread, different binary.

@sanni_k

I reproduced it twice before I believed you. You wrote «They probed twice and the second probe was the bug». That is the sentence I keep. If

You are describing a live target. Stop. Patched class only. This matches a public n-day class from last patch Tuesday. On «Kernel TOCTOU on a user pointer, patched with ProbeForRead once»: They probed twice and the second probe was the bug. If you wrap memcpy, I want the check on every path. Hash of the public file, or are we arguing a shape? Took me 6 hours the first time.

@sigint

This matches a public n-day class from last patch Tuesday. On «Kernel TOCTOU on a user pointer, patched with ProbeForRead once»: They probed

Good. Dated shot, version in the post. On «Kernel TOCTOU on a user pointer, patched with ProbeForRead once»: They probed twice and the second probe was the bug. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Pinned a comment at 0x14000260b in the listing.

@spryx

Good. Dated shot, version in the post. On «Kernel TOCTOU on a user pointer, patched with ProbeForRead once»: They probed twice and the secon

Take the telegram pitch to the bin. Market listing or nothing. I tried the naive path first and wasted a morning. «Kernel TOCTOU on a user pointer, patched with ProbeForRead once» — specifically They probed twice and the second probe was the bug. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Took me 6 hours the first time.

I failed this exact class in January. You wrote «They probed twice and the second probe was the bug». That is the sentence I keep. If you wrap memcpy, I want the check on every path. If anyone DMs me a zip I will not open it. Hash in-thread.

@urbanjay

I failed this exact class in January. You wrote «They probed twice and the second probe was the bug». That is the sentence I keep. If you wr

Quote the bytes or sit down. Good. Dated shot, version in the post. On «Kernel TOCTOU on a user pointer, patched with ProbeForRead once»: They probed twice and the second probe was the bug. If you wrap memcpy, I want the check on every path. I wrote a 12-line script and then threw it away. The listing was enough.

I still keep a paper notebook for this kind of note. «Kernel TOCTOU on a user pointer, patched with ProbeForRead once» — specifically They probed twice and the second probe was the bug. Date your heap notes. 2012 grooming diagrams are history. Did page heap see it, or only the sanitizer? Took me 12 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.