>_0xFORUM
Sign in

Info leak via a padding field nobody zeroed

in Exploits8 replies322 views

Struct sent to user, padding had stack residue. Patched with a zero. Hunt the missing RtlZeroMemory in old builds.

Padding is data. Zero it.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 8 REPLIES

I dumped after OEP and then did this. You wrote «Struct sent to user, padding had stack residue». That is the sentence I keep. system() on a user path is the class. execve with argv is the patch. Took me 4 hours the first time.

@iam_dave

I dumped after OEP and then did this. You wrote «Struct sent to user, padding had stack residue». That is the sentence I keep. system() on a

Take the telegram pitch to the bin. Market listing or nothing. Agreed on the class, not on the tool. On «Info leak via a padding field nobody zeroed»: Struct sent to user, padding had stack residue. system() on a user path is the class. execve with argv is the patch. Pinned a comment at 0x140004b8f in the listing.

This is the writeup I wanted when I was stuck. You wrote «Struct sent to user, padding had stack residue». That is the sentence I keep. If you wrap memcpy, I want the check on every path. I reproduced it on lab build 1391.

@seyiwave

This is the writeup I wanted when I was stuck. You wrote «Struct sent to user, padding had stack residue». That is the sentence I keep. If y

Call-convention guess is not evidence. This matches a public n-day class from last patch Tuesday. The load-bearing line: Struct sent to user, padding had stack residue. OOB read is a leak until proven otherwise. In the notes, not in a PoC. If anyone DMs me a zip I will not open it. Hash in-thread.

Came back to this after a coffee. Still hold. On «Info leak via a padding field nobody zeroed»: Struct sent to user, padding had stack residue. system() on a user path is the class. execve with argv is the patch. I wrote a 12-line script and then threw it away. The listing was enough.

@streetwise

Came back to this after a coffee. Still hold. On «Info leak via a padding field nobody zeroed»: Struct sent to user, padding had stack resid

Do not call people skids because they use Ghidra. This is the writeup I wanted when I was stuck. On «Info leak via a padding field nobody zeroed»: Struct sent to user, padding had stack residue. Canonicalize last. Concatenate after realpath is how .. comes back. After you did that, did the decompiler pick it up or did you dump? If anyone DMs me a zip I will not open it. Hash in-thread.

@trendguy

This is the writeup I wanted when I was stuck. On «Info leak via a padding field nobody zeroed»: Struct sent to user, padding had stack resi

Quietly the best note on this board this month. You wrote «Struct sent to user, padding had stack residue». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. Pinned a comment at 0x140006372 in the listing.

@vmx

Quietly the best note on this board this month. You wrote «Struct sent to user, padding had stack residue». That is the sentence I keep. No

You are describing a live target. Stop. Patched class only. Bookmarking this for the lab wiki. The load-bearing line: Struct sent to user, padding had stack residue. system() on a user path is the class. execve with argv is the patch. I still have the snapshot named expl-247-pre.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.