>_0xFORUM
Sign in

Tiny PE parser in Rust — no crates, just bytes

in Coding39 replies6.7k views

Tired of pulling goblin for throwaway lab tools. ~400 lines: DOS stub, COFF, optional header, section table, export dir.

Not a replacement for a real parser. Useful when you want something you can read in one sitting. MIT, no samples.

let magic = u16::from_le_bytes(b[0..2].try_into().unwrap());
assert_eq!(magic, 0x5A4D);

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 39 REPLIES

The screenshot is the useful part of the post. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. Did you force-create the function or did auto-analysis luck into it? Pinned a comment at 0x1400046f8 in the listing.

@arrx

The screenshot is the useful part of the post. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Cap

The graph hid it. The listing did not. Trust the listing. This matches a public n-day class from last patch Tuesday. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Implement encodings from the spec and a test vector, not from a blog post. If anyone DMs me a zip I will not open it. Hash in-thread.

@brandonhub

I tried the naive path first and wasted a morning. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Need/take/remain.

Stop flexing an IDA license. The question was the unwind info. Quietly the best note on this board this month. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. My note id for this: 60-11.

I tried the naive path first and wasted a morning. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. If you intern, intern copies. Views into a temp will haunt you. I still have the snapshot named codi-96-pre.

Also: Endian tests even if you 'only ship LE'.

@kernx

Came back to this after a coffee. Still hold. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Chec

That insult was not a technical point. I am reporting it. This belongs in the first-hour ritual. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Do not mmap untrusted files. I will die on this. Same class as the January thread, different binary.

Good. Dated shot, version in the post. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Dry-run default on destructive flags. Lab tools delete files. I reproduced it on lab build 1345.

@stagor

I will argue the opposite and then probably agree. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin f

I am reporting the sample-drop hint. Hash and corpus tag only. This is the kind of thread that should be a sticky and is not. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Caps on size and entry count are the feature. The parser is decoration. If anyone DMs me a zip I will not open it. Hash in-thread.

@davidxo

Bookmarking this for the lab wiki. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Caps on size an

I would have written the opposite conclusion a year ago. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Reject files over your cap by default. Silent huge allocs are bugs. I wrote a 12-line script and then threw it away. The listing was enough.

@foren

Did this on ARM64 last week — same shape, different pain. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence

You keep moving the goalposts. First it was the decoder, now it is the dump. Did this on ARM64 last week — same shape, different pain. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Do not mmap untrusted files. I will die on this. Pinned a comment at 0x1400007d2 in the listing.

@bf0rc

This matches a public n-day class from last patch Tuesday. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence

I tried the naive path first and wasted a morning. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Need/take/remain. Every C parser I still write uses them. Same class as the October thread, different binary.

I tried the naive path first and wasted a morning. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Do not mmap untrusted files. I will die on this. Version in my shot: current lab snapshot, not last year's blog.

@chukwuebuka

I tried the naive path first and wasted a morning. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin f

Calling the sticky 'priest talk' is how you earn a ban note. I will argue the opposite and then probably agree. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Caps on size and entry count are the feature. The parser is decoration. Is the hang the incomplete patch, or a second bug? Version in my shot: current lab snapshot, not last year's blog.

@echo

I would have written the opposite conclusion a year ago. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for th

If you cannot paste bytes, you do not have a counterexample. This is the kind of thread that should be a sticky and is not. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Do not mmap untrusted files. I will die on this. I still have the snapshot named codi-96-pre.

Quietly the best note on this board this month. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. Version in my shot: current lab snapshot, not last year's blog.

Also: If you intern, intern copies. Views into a temp will haunt you.

@cybx

I tried the naive path first and wasted a morning. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep.

That is a vibe. I asked for a listing offset. Bookmarking this for the lab wiki. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. I will +rep a listing and −rep a vibe. That is the deal.

Came back to this after a coffee. Still hold. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. Version in my shot: current lab snapshot, not last year's blog.

@logx

Good. Dated shot, version in the post. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Dry-run default on destructiv

I am reporting the sample-drop hint. Hash and corpus tag only. Please keep the hashes and drop the mystery zips. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Endian tests even if you 'only ship LE'. Took me 10 hours the first time.

Did this on ARM64 last week — same shape, different pain. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. Was this on the licensed corpus or a crackme you wrote? I wrote a 12-line script and then threw it away. The listing was enough.

@h4sh

Quietly the best note on this board this month. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Ca

Decompiler output is a hypothesis. Treat it like one. I would have written the opposite conclusion a year ago. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. I will +rep a listing and −rep a vibe. That is the deal.

@hexor

I would have written the opposite conclusion a year ago. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I

This matches a public n-day class from last patch Tuesday. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Implement encodings from the spec and a test vector, not from a blog post. I wrote a 12-line script and then threw it away. The listing was enough.

@index

This matches a public n-day class from last patch Tuesday. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling

This is getting personal and it does not need to. Did this on ARM64 last week — same shape, different pain. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Dry-run default on destructive flags. Lab tools delete files. Hash of the public file, or are we arguing a shape? Same class as the March thread, different binary.

@modx

Please keep the hashes and drop the mystery zips. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway

Same wall I hit last quarter. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Endian tests even if you 'only ship LE'. After you did that, did the decompiler pick it up or did you dump? Same class as the March thread, different binary.

@nodes

Same wall I hit last quarter. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Endian tests even if

The graph hid it. The listing did not. Trust the listing. This is the writeup I wanted when I was stuck. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Caps on size and entry count are the feature. The parser is decoration. Same class as the January thread, different binary.

I reproduced it twice before I believed you. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Need/take/remain. Every C parser I still write uses them. I will +rep a listing and −rep a vibe. That is the deal.

@pktsec

I reproduced it twice before I believed you. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for thr

Stop flexing an IDA license. The question was the unwind info. I dumped after OEP and then did this. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Took me 6 hours the first time.

Quietly the best note on this board this month. The load-bearing line: Tired of pulling goblin for throwaway lab tools. If you intern, intern copies. Views into a temp will haunt you. Pinned a comment at 0x140004210 in the listing.

I reproduced it twice before I believed you. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Implement encodings from the spec and a test vector, not from a blog post. Took me 11 hours the first time.

@safex

Quietly the best note on this board this month. The load-bearing line: Tired of pulling goblin for throwaway lab tools. If you intern, inter

Calling the sticky 'priest talk' is how you earn a ban note. I disagree with the tone, not the bytes. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. After you did that, did the decompiler pick it up or did you dump? I wrote a 12-line script and then threw it away. The listing was enough.

@shield

I disagree with the tone, not the bytes. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tool

Bookmarking this for the lab wiki. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Need/take/remain. Every C parser I still write uses them. Took me 6 hours the first time.

@shadow

I reproduced it twice before I believed you. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab

Decompiler output is a hypothesis. Treat it like one. Good. Dated shot, version in the post. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Checksums are not hashes. Stop keying maps with CRC32. I will +rep a listing and −rep a vibe. That is the deal.

I will argue the opposite and then probably agree. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Do not mmap untrusted files. I will die on this. I still have the snapshot named codi-96-pre.

Did this on ARM64 last week — same shape, different pain. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Reject files over your cap by default. Silent huge allocs are bugs. Pinned a comment at 0x14000432d in the listing.

@softspoken

Bookmarking this for the lab wiki. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Nee

That is a vibe. I asked for a listing offset. Not fully convinced yet. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. I reproduced it on lab build 1043.

@sudo

Did this on ARM64 last week — same shape, different pain. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling g

This is getting personal and it does not need to. Not fully convinced yet. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Dry-run default on destructive flags. Lab tools delete files. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1234.

I failed this exact class in January. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. My note id for this: 60-36.

Also: Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer.

@trevorhub

Not fully convinced yet. The load-bearing line: Tired of pulling goblin for throwaway lab tools. Dry-run default on destructive flags. Lab t

Please keep the hashes and drop the mystery zips. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway lab tools. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I will +rep a listing and −rep a vibe. That is the deal.

@ttyx

I failed this exact class in January. You wrote «Tired of pulling goblin for throwaway lab tools». That is the sentence I keep. Reject files

If you cannot paste bytes, you do not have a counterexample. I reproduced it twice before I believed you. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Do not mmap untrusted files. I will die on this. I reproduced it on lab build 1070.

@volt

Please keep the hashes and drop the mystery zips. On «Tiny PE parser in Rust — no crates, just bytes»: Tired of pulling goblin for throwaway

That insult was not a technical point. I am reporting it. Agreed on the class, not on the tool. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Implement encodings from the spec and a test vector, not from a blog post. If anyone DMs me a zip I will not open it. Hash in-thread.

This belongs in the first-hour ritual. «Tiny PE parser in Rust — no crates, just bytes» — specifically Tired of pulling goblin for throwaway lab tools. Implement encodings from the spec and a test vector, not from a blog post. Can you quote the offset instead of the graph screenshot? I still have the snapshot named codi-96-pre.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.