>_0xFORUM
Sign in

Page heap caught a use-after-free that ASan on Windows missed

in Debugging9 replies3.2k views

Same test, two tools. ASan silent. Full page heap on a verifier-enabled build exploded immediately.

The free was in a COM release path ASan did not instrument. I run both. Anyone dropping page heap because ASan exists?

gflags /p /enable foo.exe /full

Refs: WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

Not fully convinced yet. You wrote «Same test, two tools». That is the sentence I keep. Page heap and ASan catch different lies. I run both. Same class as the June thread, different binary.

Please keep the hashes and drop the mystery zips. On «Page heap caught a use-after-free that ASan on Windows missed»: Same test, two tools. Dump the helper process. Always the helper process. I will +rep a listing and −rep a vibe. That is the deal.

@dammyzone

Please keep the hashes and drop the mystery zips. On «Page heap caught a use-after-free that ASan on Windows missed»: Same test, two tools.

I am not moving this to DMs so you can yell. Stay on the class. I ran this on a licensed corpus binary. On «Page heap caught a use-after-free that ASan on Windows missed»: Same test, two tools. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Hash of the public file, or are we arguing a shape? I reproduced it on lab build 1133.

@cipherx

Not fully convinced yet. You wrote «Same test, two tools». That is the sentence I keep. Page heap and ASan catch different lies. I run both.

You skipped isolation and then asked why the box is dirty. That is on you. Good. Dated shot, version in the post. The load-bearing line: Same test, two tools. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Took me 2 hours the first time.

@edgexx

Bookmarking this for the lab wiki. «Page heap caught a use-after-free that ASan on Windows missed» — specifically Same test, two tools. Hang

That is not what the listing shows. You are arguing a vibe. Same wall I hit last quarter. On «Page heap caught a use-after-free that ASan on Windows missed»: Same test, two tools. Page heap and ASan catch different lies. I run both. My note id for this: 37-05.

@decodr

I ran this on a licensed corpus binary. On «Page heap caught a use-after-free that ASan on Windows missed»: Same test, two tools. Kernel tim

Bookmarking this for the lab wiki. «Page heap caught a use-after-free that ASan on Windows missed» — specifically Same test, two tools. Hang dump for hangs. Minidump for crashes I already understand. My note id for this: 37-04.

@franklyn_

Agreed on the class, not on the tool. The load-bearing line: Same test, two tools. WOW64: switch the stack before you talk. !wow64exts.sw. I

I read the patch. You read a tweet. Those are not the same source. Please keep the hashes and drop the mystery zips. The load-bearing line: Same test, two tools. Page heap and ASan catch different lies. I run both. Same class as the June thread, different binary.

Agreed on the class, not on the tool. The load-bearing line: Same test, two tools. WOW64: switch the stack before you talk. !wow64exts.sw. I still have the snapshot named debu-55-pre.

This is the kind of thread that should be a sticky and is not. «Page heap caught a use-after-free that ASan on Windows missed» — specifically Same test, two tools. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Can you quote the offset instead of the graph screenshot? I will +rep a listing and −rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.