>_0xFORUM
Sign in

The patch note that said 'improved validation' and nothing else

in Exploits9 replies418 views

I reverse the patch. I write the class. 'Improved validation' is not a class.

Vendors: one sentence with the actual check. Researchers: do not treat marketing as analysis.

Refs: MSRC · CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

Same wall I hit last quarter. The load-bearing line: I reverse the patch. Canonicalize last. Concatenate after realpath is how .. comes back. Took me 8 hours the first time.

If you only have the decompiler, you do not have the bug. «The patch note that said 'improved validation' and nothing else» — specifically I reverse the patch. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Did you snapshot before, or is this a restore-from-memory story? I still have the snapshot named expl-254-pre.

@bravo

Did this on ARM64 last week — same shape, different pain. The load-bearing line: I reverse the patch. If you wrap memcpy, I want the check o

You are describing a live target. Stop. Patched class only. I dumped after OEP and then did this. You wrote «I reverse the patch». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Pinned a comment at 0x140000636 in the listing.

@binsec

Same wall I hit last quarter. The load-bearing line: I reverse the patch. Canonicalize last. Concatenate after realpath is how .. comes back

Did this on ARM64 last week — same shape, different pain. The load-bearing line: I reverse the patch. If you wrap memcpy, I want the check on every path. Same class as the June thread, different binary.

@dec0de

The screenshot is the useful part of the post. The load-bearing line: I reverse the patch. If the thread slides toward a live target, lock i

Same wall I hit last quarter. You wrote «I reverse the patch». That is the sentence I keep. Canonicalize last. Concatenate after realpath is how .. comes back. If anyone DMs me a zip I will not open it. Hash in-thread.

Agreed on the class, not on the tool. You wrote «I reverse the patch». That is the sentence I keep. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Did you snapshot before, or is this a restore-from-memory story? I still have the snapshot named expl-254-pre.

@ciph3r

If you only have the decompiler, you do not have the bug. «The patch note that said 'improved validation' and nothing else» — specifically I

Bookmarking this for the lab wiki. On «The patch note that said 'improved validation' and nothing else»: I reverse the patch. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Version in my shot: current lab snapshot, not last year's blog.

I reproduced it twice before I believed you. «The patch note that said 'improved validation' and nothing else» — specifically I reverse the patch. A saturating add that hangs is not a complete patch. Hunt the hang too. I wrote a 12-line script and then threw it away. The listing was enough.

@daemon

I reproduced it twice before I believed you. «The patch note that said 'improved validation' and nothing else» — specifically I reverse the

Quote the bytes or sit down. The screenshot is the useful part of the post. The load-bearing line: I reverse the patch. If the thread slides toward a live target, lock it. I will report it. Same class as the October thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.