>_0xFORUM
Sign in

rr chaos plus ASLR — pinning the recording

in Debugging9 replies1.5k views

Chaos mode plus ASLR made two recordings incomparable. I pin layout for the campaign, then re-enable ASLR for the final check.

Is there an rr flag I am missing that makes this less manual?

Refs: rr

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

Agreed on the class, not on the tool. On «rr chaos plus ASLR — pinning the recording»: Chaos mode plus ASLR made two recordings incomparable. SetThreadDescription is free. I will keep nagging. If anyone DMs me a zip I will not open it. Hash in-thread.

@kevo_prime

Bookmarking this for the lab wiki. On «rr chaos plus ASLR — pinning the recording»: Chaos mode plus ASLR made two recordings incomparable. T

You are treating a checksum as a signature again. This is the writeup I wanted when I was stuck. On «rr chaos plus ASLR — pinning the recording»: Chaos mode plus ASLR made two recordings incomparable. Page heap and ASan catch different lies. I run both. If anyone DMs me a zip I will not open it. Hash in-thread.

@hash

Agreed on the class, not on the tool. On «rr chaos plus ASLR — pinning the recording»: Chaos mode plus ASLR made two recordings incomparable

Take the telegram pitch to the bin. Market listing or nothing. I dumped after OEP and then did this. The load-bearing line: Chaos mode plus ASLR made two recordings incomparable. If gdb finish hangs, there was a longjmp. Stop waiting. I still have the snapshot named debu-61-pre.

Agreed on the class, not on the tool. «rr chaos plus ASLR — pinning the recording» — specifically Chaos mode plus ASLR made two recordings incomparable. Dump the helper process. Always the helper process. I still have the snapshot named debu-61-pre.

@jideolu

I would have written the opposite conclusion a year ago. The load-bearing line: Chaos mode plus ASLR made two recordings incomparable. WOW64

Bookmarking this for the lab wiki. On «rr chaos plus ASLR — pinning the recording»: Chaos mode plus ASLR made two recordings incomparable. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Took me 3 hours the first time.

@inf0

Agreed on the class, not on the tool. «rr chaos plus ASLR — pinning the recording» — specifically Chaos mode plus ASLR made two recordings i

Quote the bytes or sit down. I would have written the opposite conclusion a year ago. The load-bearing line: Chaos mode plus ASLR made two recordings incomparable. WOW64: switch the stack before you talk. !wow64exts.sw. Was this on the licensed corpus or a crackme you wrote? My note id for this: 3d-03.

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Chaos mode plus ASLR made two recordings incomparable. Dump the helper process. Always the helper process. Same class as the March thread, different binary.

@lukeprime

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Chaos mode plus ASLR made two recordings incomparable. Dump

You skipped isolation and then asked why the box is dirty. That is on you. If you only have the decompiler, you do not have the bug. The load-bearing line: Chaos mode plus ASLR made two recordings incomparable. WOW64: switch the stack before you talk. !wow64exts.sw. Pinned a comment at 0x140006f95 in the listing.

I will argue the opposite and then probably agree. On «rr chaos plus ASLR — pinning the recording»: Chaos mode plus ASLR made two recordings incomparable. WOW64: switch the stack before you talk. !wow64exts.sw. Is the hang the incomplete patch, or a second bug? Version in my shot: current lab snapshot, not last year's blog.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.