<?xml version="1.0" encoding="UTF-8" ?><rss version="2.0"><channel><title>Top Topics in the &quot;Da Slop Pit&quot; Group Forum | SpaceHey</title><link>https://groups.spacehey.com/forum?id=15912</link><description>Forum Topics in the &quot;Da Slop Pit&quot; Group Forum on SpaceHey, created by users.</description><item><title>sloppy certificate enrollment protocol, for ghosts (cve-2021-3060)</title><link>https://forum.spacehey.com/topic?id=83646</link><guid>https://forum.spacehey.com/topic?id=83646</guid><description>i found a rce (Really Cool Exploit) in the sslmgr component of globalprotect a while ago. this exploit is particularly fun because it combines a default crypto key, command parameter injection, and creative uses of the openssl command. requests to sslmgr require a few parameters: - scep-profile-name: the configured name of the scep profile - user-email: the email of the user - user: the name of th...</description><pubDate>Mon, 18 Apr 2022 04:52:32 +0000</pubDate></item><item><title>Too late for BGGP3, too early for starships</title><link>https://forum.spacehey.com/topic?id=93101</link><guid>https://forum.spacehey.com/topic?id=93101</guid><description>I found out about BGGP3 late, but I wanted to make a late entry to say hi to da slop pit. I was able to slightly modify some symbolic execution tooling I have been playing with to quickly generate a minimal crashing case. Procmod64.exe falls over easily when loading PML files and I&#039;ve been using the crashes to show off some of my symbolic execution triage tooling. I&#039;ll post a larger blog post abou...</description><pubDate>Sat, 22 Oct 2022 18:55:56 +0000</pubDate></item><item><title>attacker controlled format string in PAN-OS captive portal NTLM authentication</title><link>https://forum.spacehey.com/topic?id=83542</link><guid>https://forum.spacehey.com/topic?id=83542</guid><description>greetings fellow scene queens, emo wolf girls, and sloppy ghosts. today i have a special treat for you (and no, this time it&#039;s not a bottle of piss). after writing an exploit for CVE-2019-1579, a format string bug in globalprotect, i wrote a tool to look for format string bugs using ghidra. i ran this script against a few dozen libraries and executables, and as it turns out, there are a lot of for...</description><pubDate>Sat, 16 Apr 2022 23:51:05 +0000</pubDate></item><item><title>Python3.7+ Multi-arch .pyc shellcode dropper</title><link>https://forum.spacehey.com/topic?id=89320</link><guid>https://forum.spacehey.com/topic?id=89320</guid><description>Python pyc files are a binary format that is used to speed up the process of interpreting imported files. They contain a small header, metadata about the code object, and the bytecode itself. There&#039;s a lot of resources for Python2.7, but since Python 2.x has been deprecated, there aren&#039;t many resources for Python3, specifically Python3.7+. Much of the main difference between Python versions is the...</description><pubDate>Tue, 09 Aug 2022 22:29:47 +0000</pubDate></item><item><title>Wireshark is a lolbin</title><link>https://forum.spacehey.com/topic?id=84164</link><guid>https://forum.spacehey.com/topic?id=84164</guid><description>If you haven&#039;t heard of lolbins check out: https://lolbas-project.github.io/ Wireshark is capable of running Lua scripts from the command line directly. The -X flag is for eXtension options, which focus primarily on running Lua scripts. Since the Lua engine is used to run dissectors, this should be part of your base Wireshark installation. Command line options: https://www.wireshark.org/docs/wsug_...</description><pubDate>Mon, 25 Apr 2022 21:40:27 +0000</pubDate></item><item><title>manually encrypting/decrypting data with your pan-os device master key</title><link>https://forum.spacehey.com/topic?id=84978</link><guid>https://forum.spacehey.com/topic?id=84978</guid><description>the device master key is used for encrypting secrets in your config, generating api tokens, and probably a bunch of other stuff i havent looked into much yet. despite the default master key (&#039;p1a2l3o4a5l6t7o8&#039;) being widely available, there isn&#039;t any public information about how to use this key to manually encrypt and decrypt data. by default, and on all systems before pan-os 10.0, master key encr...</description><pubDate>Thu, 05 May 2022 07:11:05 +0000</pubDate></item><item><title>i have a potentially awkward question,,</title><link>https://forum.spacehey.com/topic?id=83380</link><guid>https://forum.spacehey.com/topic?id=83380</guid><description>is anyone else here a ghost? 👻 i wasn’t for a long time and i’m not sure how it happened. last thing i remember i was in line at sizzler???</description><pubDate>Thu, 14 Apr 2022 23:10:35 +0000</pubDate></item><item><title>PAN-OS sysd: privescs 4 dayz</title><link>https://forum.spacehey.com/topic?id=84127</link><guid>https://forum.spacehey.com/topic?id=84127</guid><description>sysd provides a key/value database with powerful callback functionality for IPC and configuration storage. Data is stored hierarchically with paths such as cfg.platform.serial. Data can be queried programatically or with the sdb command line tool. For example, you can query the management interface MAC address using sdb cfg.platform.mac and you could also modify this using sdb cfg.platform.mac=aa:...</description><pubDate>Mon, 25 Apr 2022 16:18:04 +0000</pubDate></item><item><title>intel apx 432</title><link>https://forum.spacehey.com/topic?id=83397</link><guid>https://forum.spacehey.com/topic?id=83397</guid><description>from the manual: One of the unique features of the Intel 432 is its instruction encoding. Instructions are bit-variable in length and can start on any bit boundary. The instruction pointer thus contains the bit offset into the current instruction segment, which can be up to 8K bytes in size. An instruction consists of up to four fields, as shown in Figure 9-14. The fields themselves are also varia...</description><pubDate>Fri, 15 Apr 2022 02:24:18 +0000</pubDate></item><item><title>sloppy memory</title><link>https://forum.spacehey.com/topic?id=89094</link><guid>https://forum.spacehey.com/topic?id=89094</guid><description>have u ever been so sloppy as to allocate the same shared memory region multiple times, but with different page protections #include   #include            #include           #include #include #include #include #include          #include /* the mem u get     0x7ffff796e000     0x7ffff7a6e000 r-xp   100000 0      /dev/shm/ipc     0x7ffff7a6e000     0x7ffff7b6e000 rw-p   100000 0      /dev/shm/ipc   ...</description><pubDate>Fri, 05 Aug 2022 07:28:30 +0000</pubDate></item><item><title>sloppy logging in da slop pit</title><link>https://forum.spacehey.com/topic?id=89978</link><guid>https://forum.spacehey.com/topic?id=89978</guid><description>Among other uses, PAN-OS uses the device master key to encrypt secrets in the config. Most of the time, a malicious administrator can simply decrypt the passwords using the AES-256-CBC key &#039;8103850245b9b48f0428c5b74e2615528103850245b9b48f0428c5b74e261552&#039;, but occasionally administrators will actually remember to change the default master key. Luckily, Palo Alto Networks made sure to provide an al...</description><pubDate>Tue, 23 Aug 2022 06:26:41 +0000</pubDate></item><item><title>How to set up a Gemini capsule</title><link>https://forum.spacehey.com/topic?id=89852</link><guid>https://forum.spacehey.com/topic?id=89852</guid><description>How to set up a Gemini capsule Intro Hello!  Setting up a gemini capsule can be fun and rewarding, and it&#039;s not too hard! However, there are some tricky parts that stumped me for a bit when I was starting mine. I figured, since I ran into trouble, I might as well write a guide on how to host your own gemini capsule for anyone running into similar problems. What server to use? Personally, I used ag...</description><pubDate>Sat, 20 Aug 2022 18:11:26 +0000</pubDate></item><item><title>Small file hasher written in hare</title><link>https://forum.spacehey.com/topic?id=89815</link><guid>https://forum.spacehey.com/topic?id=89815</guid><description>Hi :) I wrote a quick file hasher in hare.  Run the program and pass whatever file you want hashed as an argument and it&#039;ll make the sha256 hash for it and print it out for you</description><pubDate>Fri, 19 Aug 2022 22:27:24 +0000</pubDate></item><item><title>Wowee wow</title><link>https://forum.spacehey.com/topic?id=83364</link><guid>https://forum.spacehey.com/topic?id=83364</guid><description>Hehe neat</description><pubDate>Thu, 14 Apr 2022 22:21:49 +0000</pubDate></item><item><title>vmalloc-out-of-bounds Write in imageblit </title><link>https://forum.spacehey.com/topic?id=83367</link><guid>https://forum.spacehey.com/topic?id=83367</guid><description>A few months ago I saw this bug but wasn&#039;t sure if anyone actually did anything with it so here are the notes. The Crash From:  https://syzkaller.appspot.com/bug?id=c46757660a2b99103a2f46a15bfcd8d687d5dabc KASAN: vmalloc-out-of-bounds Write in imageblit (2) BUG: unable to handle page fault for address: fffff520008b2208 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-presen...</description><pubDate>Thu, 14 Apr 2022 22:24:11 +0000</pubDate></item><item><title>where da slop at </title><link>https://forum.spacehey.com/topic?id=83773</link><guid>https://forum.spacehey.com/topic?id=83773</guid><description>where da slop at where da slop at Lorem ipsum Lorem ipsum Lorem ipsum where da slop at Lorem ipsum Lore where da slop at Lorem ipsum Lore where da slop at m where da slop at where da slop at where da slop at where da slop at</description><pubDate>Tue, 19 Apr 2022 07:49:47 +0000</pubDate></item><item><title>sloppy data base (cve-2021-3061)</title><link>https://forum.spacehey.com/topic?id=83846</link><guid>https://forum.spacehey.com/topic?id=83846</guid><description>hewwo :3 yesterday i showed you how to get code remote code execution as some preppy loser. today i will show you one easy trick to escalate privileges until ur cooler than boxxy. pan-os internally uses a neat database/ipc service called sysd. sysd allows querying and storing objects (such as the serial number or configuration data) as well as registering as a handler for object accesses and being...</description><pubDate>Wed, 20 Apr 2022 06:14:35 +0000</pubDate></item><item><title>zomg curl in my php!!! (cve-2021-3058)</title><link>https://forum.spacehey.com/topic?id=83750</link><guid>https://forum.spacehey.com/topic?id=83750</guid><description>hey you little pissbabiez you think php is so cool, huh? you think php is so great? you talk a lotta big game for someone with such a vuln box!! while grepping for command injection, i came across this code in /var/appweb/htdocs/php/rest/RestApi.php, which handles requests for the pan-os xml api. $url = self::assertParamPresent(&quot;url&quot;); $userName = self::param(&quot;user&quot;, &quot;dummy&quot;); $password = self::pa...</description><pubDate>Mon, 18 Apr 2022 23:04:42 +0000</pubDate></item><item><title>favorite late night snack</title><link>https://forum.spacehey.com/topic?id=84292</link><guid>https://forum.spacehey.com/topic?id=84292</guid><description>What is everyone&#039;s favorite late night snack? I know it was in the title but I&#039;m just curious haha I find that I like really salty things, so a bold chex mix or sour cream and onion potato chips really hit the spot. But my favorite? Mozzarella cheese sticks with marinara. Hands down. I keep a bag in my freezer and they only take like 10 minutes to bake! What about you?</description><pubDate>Tue, 26 Apr 2022 20:23:43 +0000</pubDate></item><item><title>disassembler mistrust (dis-trust)</title><link>https://forum.spacehey.com/topic?id=91512</link><guid>https://forum.spacehey.com/topic?id=91512</guid><description>a haiku about disassembler trust, bfu trust disassemblers? or do you have trust issues i think i do too dis-trust i tend to use ida, but sometimes i don&#039;t and when i don&#039;t, i tend to double check.. in ida what if i can&#039;t double check in ida? today i used ghidra (nsa implant) i think i publicly complain enough about ghidra. this is fine, whatever, it&#039;s adequate - but ida is better. anyways, i saw s...</description><pubDate>Tue, 20 Sep 2022 23:40:16 +0000</pubDate></item><item><title>mips for a sane x86 RE</title><link>https://forum.spacehey.com/topic?id=89669</link><guid>https://forum.spacehey.com/topic?id=89669</guid><description>so recently, i had to learn how to read mips granted, i had avoided it, because it&#039;s hard (ok not anymore but i really thought it was hard but i don&#039;t smell toast anymore so i think its ok) heres a table that makes me feel a little better, where n is a number (has ARM energy) mips register(s) probably x86 equivalent thoughts $zero literally the number zero no thots brain empty $at no clue for the ...</description><pubDate>Wed, 17 Aug 2022 00:20:16 +0000</pubDate></item><item><title>Things that are not BGGP3 Entries</title><link>https://forum.spacehey.com/topic?id=89761</link><guid>https://forum.spacehey.com/topic?id=89761</guid><description>Looking for crashes has been fun and I have learned a lot. I have been down some rabbit holes and found some funny bugs. Here are some things that are NOT BGGP3 submissions that i wanted to share :) #1 CHASOPRO 4.0.249 (latest) Buffer Overrun ------------------------------------------- Buffer overrun when importing a jpg named: BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3BGGP3...</description><pubDate>Fri, 19 Aug 2022 00:26:54 +0000</pubDate></item><item><title>pan-os rce in dynamic slopdates (cve-2021-3059) </title><link>https://forum.spacehey.com/topic?id=84548</link><guid>https://forum.spacehey.com/topic?id=84548</guid><description>every hour, a cron job on pan-os runs the /usr/local/bin/pan-gpdatafile-updater script. this is a shell script which checks for updates to some data files used by the system. at a high level, the script will: - check if there is an update available from the server. - if there are no updates available, don&#039;t do anything - if there are updates available, use the URL returned by the update check endp...</description><pubDate>Fri, 29 Apr 2022 06:16:22 +0000</pubDate></item><item><title>o p t i m i z e</title><link>https://forum.spacehey.com/topic?id=83538</link><guid>https://forum.spacehey.com/topic?id=83538</guid><description>in this thread we&#039;re making yaxpeax-x86 faster. i have a super bad microbenchmark that lives in the repo, it&#039;s my spot check for &quot;did i make it obviously worse&quot;. it involves disassembling like 500 bytes of instructions or something, so the whole disassembler and dataset pretty quickly end up in cache. it gets really good ipc numbers and makes me feel good about acing synthetic workloads :) perf lo...</description><pubDate>Sat, 16 Apr 2022 23:23:22 +0000</pubDate></item><item><title>readelf 2.30 DOS (Assertion Fail/OOB read)</title><link>https://forum.spacehey.com/topic?id=83556</link><guid>https://forum.spacehey.com/topic?id=83556</guid><description>I haven&#039;t written about this anywhere but figured I should share. This is a DOS I found in readelf 2.30. Here are the two binaries that triggered this crash $ readelf --version GNU readelf (GNU Binutils for Ubuntu) 2.30 $ cat readelfcrash1.bin | base64 f0VMRgIBAQAAAAAAAAAAAAKdpwA+AAEAAAB4AEAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAQAA4 EAEAAAAA1BQAAQAAAAUAAAAAAAAAAAAAAAAAQAAAAAAAAABAAAAAAACAAAAAAAAAAIAAAA...</description><pubDate>Sun, 17 Apr 2022 03:29:03 +0000</pubDate></item></channel></rss>