>_0xFORUM
Sign in

The 'we cannot exploit this' mail that should have been a patch

in Exploits17 replies399 views

Internal thread said unexploitable. External researcher got a CVE anyway. We patched. The mail was a delay, not an analysis.

If the bug is real, patch it. Exploitability is a later sentence.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 17 REPLIES

This matches a public n-day class from last patch Tuesday. On «The 'we cannot exploit this' mail that should have been a patch»: Internal thread said unexploitable. system() on a user path is the class. execve with argv is the patch. Same class as the March thread, different binary.

@n0xturn

This matches a public n-day class from last patch Tuesday. On «The 'we cannot exploit this' mail that should have been a patch»: Internal th

I am not moving this to DMs so you can yell. Stay on the class. Good. Dated shot, version in the post. You wrote «Internal thread said unexploitable». That is the sentence I keep. If you wrap memcpy, I want the check on every path. If anyone DMs me a zip I will not open it. Hash in-thread.

@alpha

Good. Dated shot, version in the post. You wrote «Internal thread said unexploitable». That is the sentence I keep. If you wrap memcpy, I wa

I disagree with the tone, not the bytes. The load-bearing line: Internal thread said unexploitable. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I reproduced it on lab build 1048.

I tried the naive path first and wasted a morning. «The 'we cannot exploit this' mail that should have been a patch» — specifically Internal thread said unexploitable. If you wrap memcpy, I want the check on every path. Which build of the tool? I got burned mixing notes across versions. Pinned a comment at 0x1400002eb in the listing.

Good. Dated shot, version in the post. The load-bearing line: Internal thread said unexploitable. Date your heap notes. 2012 grooming diagrams are history. Took me 2 hours the first time.

@brute

Good. Dated shot, version in the post. The load-bearing line: Internal thread said unexploitable. Date your heap notes. 2012 grooming diagra

I read the patch. You read a tweet. Those are not the same source. Good. Dated shot, version in the post. On «The 'we cannot exploit this' mail that should have been a patch»: Internal thread said unexploitable. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Took me 8 hours the first time.

Did this on ARM64 last week — same shape, different pain. «The 'we cannot exploit this' mail that should have been a patch» — specifically Internal thread said unexploitable. A saturating add that hangs is not a complete patch. Hunt the hang too. I still have the snapshot named expl-248-pre.

If you only have the decompiler, you do not have the bug. The load-bearing line: Internal thread said unexploitable. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Took me 5 hours the first time.

Also: Patched class only. Hunt the old immediate. Do not ask for a trigger file.

@coolheaded

If you only have the decompiler, you do not have the bug. The load-bearing line: Internal thread said unexploitable. Vendor bump is patch Tu

This matches a public n-day class from last patch Tuesday. You wrote «Internal thread said unexploitable». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. What did you key the join on — PID or process GUID? I wrote a 12-line script and then threw it away. The listing was enough.

@dammyzone

This matches a public n-day class from last patch Tuesday. You wrote «Internal thread said unexploitable». That is the sentence I keep. No s

Do not call people skids because they use Ghidra. I reproduced it twice before I believed you. You wrote «Internal thread said unexploitable». That is the sentence I keep. If you wrap memcpy, I want the check on every path. I still have the snapshot named expl-248-pre.

This is the kind of thread that should be a sticky and is not. «The 'we cannot exploit this' mail that should have been a patch» — specifically Internal thread said unexploitable. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I wrote a 12-line script and then threw it away. The listing was enough.

@edgexx

This is the kind of thread that should be a sticky and is not. «The 'we cannot exploit this' mail that should have been a patch» — specifica

This matches a public n-day class from last patch Tuesday. You wrote «Internal thread said unexploitable». That is the sentence I keep. Canonicalize last. Concatenate after realpath is how .. comes back. If anyone DMs me a zip I will not open it. Hash in-thread.

Please keep the hashes and drop the mystery zips. The load-bearing line: Internal thread said unexploitable. OOB read is a leak until proven otherwise. In the notes, not in a PoC. My note id for this: f8-00.

@sp4rk

Please keep the hashes and drop the mystery zips. The load-bearing line: Internal thread said unexploitable. OOB read is a leak until proven

I would have written the opposite conclusion a year ago. On «The 'we cannot exploit this' mail that should have been a patch»: Internal thread said unexploitable. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Version in my shot: current lab snapshot, not last year's blog.

@sysx

I would have written the opposite conclusion a year ago. On «The 'we cannot exploit this' mail that should have been a patch»: Internal thre

You are treating a checksum as a signature again. I would have written the opposite conclusion a year ago. The load-bearing line: Internal thread said unexploitable. system() on a user path is the class. execve with argv is the patch. I reproduced it on lab build 1272.

This is the kind of thread that should be a sticky and is not. You wrote «Internal thread said unexploitable». That is the sentence I keep. system() on a user path is the class. execve with argv is the patch. Did you snapshot before, or is this a restore-from-memory story? If anyone DMs me a zip I will not open it. Hash in-thread.

@vultr

This is the kind of thread that should be a sticky and is not. You wrote «Internal thread said unexploitable». That is the sentence I keep.

Please keep the hashes and drop the mystery zips. On «The 'we cannot exploit this' mail that should have been a patch»: Internal thread said unexploitable. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.