>_0xFORUM
Sign in

A 'do we own this' checklist before I run strings on it

in Tools28 replies554 views

License, corpus tag, hash in the index. If it is not in the index it is not in the lab.

I will not strings a file with a story and no tag.

Refs: FLARE VM

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 28 REPLIES

Did this on ARM64 last week — same shape, different pain. On «A 'do we own this' checklist before I run strings on it»: License, corpus tag, hash in the index. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. My note id for this: 122-00.

@johnnyace

Did this on ARM64 last week — same shape, different pain. On «A 'do we own this' checklist before I run strings on it»: License, corpus tag,

I tried the naive path first and wasted a morning. The load-bearing line: License, corpus tag, hash in the index. FakeNet that can reach the internet is not a simulator. Version in my shot: current lab snapshot, not last year's blog.

@kilo

I tried the naive path first and wasted a morning. The load-bearing line: License, corpus tag, hash in the index. FakeNet that can reach the

Quote the bytes or sit down. I ran this on a licensed corpus binary. The load-bearing line: License, corpus tag, hash in the index. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. I still have the snapshot named tool-290-pre.

Quietly the best note on this board this month. The load-bearing line: License, corpus tag, hash in the index. Clipboard off on the detonation VM. I pasted a token once. Was this on the licensed corpus or a crackme you wrote? Same class as the June thread, different binary.

@malx

Quietly the best note on this board this month. The load-bearing line: License, corpus tag, hash in the index. Clipboard off on the detonati

Please keep the hashes and drop the mystery zips. You wrote «License, corpus tag, hash in the index». That is the sentence I keep. Transfer samples as a hashed read-only ISO. Not drag-drop. My note id for this: 122-04.

I would have written the opposite conclusion a year ago. The load-bearing line: License, corpus tag, hash in the index. Transfer samples as a hashed read-only ISO. Not drag-drop. I reproduced it on lab build 1338.

@novax

I would have written the opposite conclusion a year ago. The load-bearing line: License, corpus tag, hash in the index. Transfer samples as

You skipped isolation and then asked why the box is dirty. That is on you. Quietly the best note on this board this month. You wrote «License, corpus tag, hash in the index». That is the sentence I keep. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. Took me 10 hours the first time.

@orbit

Quietly the best note on this board this month. You wrote «License, corpus tag, hash in the index». That is the sentence I keep. Name snapsh

I dumped after OEP and then did this. The load-bearing line: License, corpus tag, hash in the index. Profile YARA. One looping regex will eat a core. Same class as the March thread, different binary.

@zenith

I dumped after OEP and then did this. The load-bearing line: License, corpus tag, hash in the index. Tools snapshot in 8 minutes or you will

Not fully convinced yet. «A 'do we own this' checklist before I run strings on it» — specifically License, corpus tag, hash in the index. PE-sieve is a lead. It is not a verdict. I reproduced it on lab build 1015.

If you only have the decompiler, you do not have the bug. On «A 'do we own this' checklist before I run strings on it»: License, corpus tag, hash in the index. PE-sieve is a lead. It is not a verdict. If anyone DMs me a zip I will not open it. Hash in-thread.

@ampx

If you only have the decompiler, you do not have the bug. On «A 'do we own this' checklist before I run strings on it»: License, corpus tag,

You are describing a live target. Stop. Patched class only. This matches a public n-day class from last patch Tuesday. The load-bearing line: License, corpus tag, hash in the index. Clipboard off on the detonation VM. I pasted a token once. Is the hang the incomplete patch, or a second bug? Pinned a comment at 0x140000498 in the listing.

@authx

This matches a public n-day class from last patch Tuesday. The load-bearing line: License, corpus tag, hash in the index. Clipboard off on t

I tried the naive path first and wasted a morning. The load-bearing line: License, corpus tag, hash in the index. Tools snapshot in 8 minutes or you will not restore it. I reproduced it on lab build 1193.

This matches a public n-day class from last patch Tuesday. «A 'do we own this' checklist before I run strings on it» — specifically License, corpus tag, hash in the index. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. I still have the snapshot named tool-290-pre.

Also: Caps on the drop folder saved the box. The 4GB 'txt' was a dump.

I dumped after OEP and then did this. The load-bearing line: License, corpus tag, hash in the index. Transfer samples as a hashed read-only ISO. Not drag-drop. Took me 12 hours the first time.

@calmstan

I dumped after OEP and then did this. The load-bearing line: License, corpus tag, hash in the index. Transfer samples as a hashed read-only

Quote the bytes or sit down. I dumped after OEP and then did this. You wrote «License, corpus tag, hash in the index». That is the sentence I keep. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. Same class as the January thread, different binary.

Came back to this after a coffee. Still hold. The load-bearing line: License, corpus tag, hash in the index. Tools snapshot in 8 minutes or you will not restore it. Which build of the tool? I got burned mixing notes across versions. I still have the snapshot named tool-290-pre.

Bookmarking this for the lab wiki. The load-bearing line: License, corpus tag, hash in the index. Dirty VM means throw it. Do not apt upgrade a dirty box. If anyone DMs me a zip I will not open it. Hash in-thread.

@danielcrest

Bookmarking this for the lab wiki. The load-bearing line: License, corpus tag, hash in the index. Dirty VM means throw it. Do not apt upgrad

Quietly the best note on this board this month. The load-bearing line: License, corpus tag, hash in the index. Profile YARA. One looping regex will eat a core. Took me 5 hours the first time.

@deleconnect

Quietly the best note on this board this month. The load-bearing line: License, corpus tag, hash in the index. Profile YARA. One looping reg

You skipped isolation and then asked why the box is dirty. That is on you. I reproduced it twice before I believed you. «A 'do we own this' checklist before I run strings on it» — specifically License, corpus tag, hash in the index. PE-sieve is a lead. It is not a verdict. Took me 3 hours the first time.

I still keep a paper notebook for this kind of note. You wrote «License, corpus tag, hash in the index». That is the sentence I keep. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. Version in my shot: current lab snapshot, not last year's blog.

This is the writeup I wanted when I was stuck. «A 'do we own this' checklist before I run strings on it» — specifically License, corpus tag, hash in the index. Transfer samples as a hashed read-only ISO. Not drag-drop. Is the hang the incomplete patch, or a second bug? If anyone DMs me a zip I will not open it. Hash in-thread.

I disagree with the tone, not the bytes. On «A 'do we own this' checklist before I run strings on it»: License, corpus tag, hash in the index. Transfer samples as a hashed read-only ISO. Not drag-drop. If anyone DMs me a zip I will not open it. Hash in-thread.

@sanni_k

I disagree with the tone, not the bytes. On «A 'do we own this' checklist before I run strings on it»: License, corpus tag, hash in the inde

That is not what the listing shows. You are arguing a vibe. Bookmarking this for the lab wiki. On «A 'do we own this' checklist before I run strings on it»: License, corpus tag, hash in the index. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. If anyone DMs me a zip I will not open it. Hash in-thread.

The screenshot is the useful part of the post. The load-bearing line: License, corpus tag, hash in the index. Transfer samples as a hashed read-only ISO. Not drag-drop. If anyone DMs me a zip I will not open it. Hash in-thread.

Agreed on the class, not on the tool. You wrote «License, corpus tag, hash in the index». That is the sentence I keep. PE-sieve is a lead. It is not a verdict. Pinned a comment at 0x140002db5 in the listing.

Also: Tools snapshot in 8 minutes or you will not restore it.

@taiwoflex

Agreed on the class, not on the tool. You wrote «License, corpus tag, hash in the index». That is the sentence I keep. PE-sieve is a lead. I

This is the kind of thread that should be a sticky and is not. «A 'do we own this' checklist before I run strings on it» — specifically License, corpus tag, hash in the index. Clipboard off on the detonation VM. I pasted a token once. Is the hang the incomplete patch, or a second bug? I reproduced it on lab build 1398.

@urbanjay

This is the kind of thread that should be a sticky and is not. «A 'do we own this' checklist before I run strings on it» — specifically Lice

Call-convention guess is not evidence. I failed this exact class in January. The load-bearing line: License, corpus tag, hash in the index. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. I still have the snapshot named tool-290-pre.

I dumped after OEP and then did this. The load-bearing line: License, corpus tag, hash in the index. Tools snapshot in 8 minutes or you will not restore it. I will +rep a listing and −rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.