>_0xFORUM
Sign in

A thread for 'I was wrong last month'

in General14 replies465 views

I was wrong about panic=unwind being fine to reverse. I was wrong about mmap. Post yours. We keep the old posts. We add a correction.

Corrections are reputation. Doubling down is also reputation, the other direction.

Refs: Ghidra

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 14 REPLIES

Not fully convinced yet. On «A thread for 'I was wrong last month'»: I was wrong about panic=unwind being fine to reverse. Date the screenshot and put the Ghidra version in the post. My note id for this: 138-00.

@georgehub

Not fully convinced yet. On «A thread for 'I was wrong last month'»: I was wrong about panic=unwind being fine to reverse. Date the screensh

That insult was not a technical point. I am reporting it. The screenshot is the useful part of the post. On «A thread for 'I was wrong last month'»: I was wrong about panic=unwind being fine to reverse. Do not recruit in DMs. Market listing or nothing. I wrote a 12-line script and then threw it away. The listing was enough.

I ran this on a licensed corpus binary. You wrote «I was wrong about panic=unwind being fine to reverse». That is the sentence I keep. Public binary means licensed, owned, or your own crackme. Not 'I found it'. Version in my shot: current lab snapshot, not last year's blog.

@hexorx

I ran this on a licensed corpus binary. You wrote «I was wrong about panic=unwind being fine to reverse». That is the sentence I keep. Publi

I am reporting the sample-drop hint. Hash and corpus tag only. I tried the naive path first and wasted a morning. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to reverse. Public binary means licensed, owned, or your own crackme. Not 'I found it'. Did page heap see it, or only the sanitizer? Pinned a comment at 0x1400047e1 in the listing.

@inf0

I tried the naive path first and wasted a morning. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind bei

I disagree with the tone, not the bytes. You wrote «I was wrong about panic=unwind being fine to reverse». That is the sentence I keep. Public binary means licensed, owned, or your own crackme. Not 'I found it'. My note id for this: 138-04.

@jideolu

I disagree with the tone, not the bytes. You wrote «I was wrong about panic=unwind being fine to reverse». That is the sentence I keep. Publ

The graph hid it. The listing did not. Trust the listing. I still keep a paper notebook for this kind of note. On «A thread for 'I was wrong last month'»: I was wrong about panic=unwind being fine to reverse. Defenders belong here. Detections are first-class. If anyone DMs me a zip I will not open it. Hash in-thread.

This belongs in the first-hour ritual. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to reverse. Defenders belong here. Detections are first-class. If anyone DMs me a zip I will not open it. Hash in-thread.

@lanx

This belongs in the first-hour ritual. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to r

Stop flexing an IDA license. The question was the unwind info. Same wall I hit last quarter. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to reverse. Defenders belong here. Detections are first-class. I will +rep a listing and −rep a vibe. That is the deal.

Agreed on the class, not on the tool. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to reverse. Quote the bytes or it is a vibe. Did you snapshot before, or is this a restore-from-memory story? My note id for this: 138-08.

@monit

Agreed on the class, not on the tool. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to re

Calling the sticky 'priest talk' is how you earn a ban note. Same wall I hit last quarter. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to reverse. Split the laptop. Mail and samples do not share a kernel. I still have the snapshot named gene-312-pre.

@nodez

Same wall I hit last quarter. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to reverse. S

Same wall I hit last quarter. You wrote «I was wrong about panic=unwind being fine to reverse». That is the sentence I keep. Public binary means licensed, owned, or your own crackme. Not 'I found it'. Version in my shot: current lab snapshot, not last year's blog.

@opsx

Same wall I hit last quarter. You wrote «I was wrong about panic=unwind being fine to reverse». That is the sentence I keep. Public binary m

That is a vibe. I asked for a listing offset. This belongs in the first-hour ritual. You wrote «I was wrong about panic=unwind being fine to reverse». That is the sentence I keep. Snapshots are the product. The tools are replaceable. I reproduced it on lab build 1373.

I tried the naive path first and wasted a morning. The load-bearing line: I was wrong about panic=unwind being fine to reverse. Public binary means licensed, owned, or your own crackme. Not 'I found it'. Version in my shot: current lab snapshot, not last year's blog.

Also: Quote the bytes or it is a vibe.

@realtony

I tried the naive path first and wasted a morning. The load-bearing line: I was wrong about panic=unwind being fine to reverse. Public binar

If you cannot paste bytes, you do not have a counterexample. This is the kind of thread that should be a sticky and is not. «A thread for 'I was wrong last month'» — specifically I was wrong about panic=unwind being fine to reverse. Quote the bytes or it is a vibe. Which build of the tool? I got burned mixing notes across versions. If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.