Day[0] cover image

[binary] TOCTOUs in Intel SMM and Shannon Baseband Bugs

Day[0]

00:00

Logic Bugs in Xenos Devices

A lot of the times when I see these kinds of logic bugs that lead to like bypasses of authorization checks it is because they try to stick like multiple fields into the into one bitfield instead of having like an opcode field and then the flag separately. That kind of pattern is a lot harder to get wrong in this sort of way but yeah I mean it is I think this is somewhat older code so you know maybe it is from a time when penny pinching the the argument buffer made a bit more sense for example. If I saw this kind of bitwise going on for an operation like that would be kind of a code smell for me in and of itselfso yeah an interesting bug

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app