HN user

dielel

374 karma
Posts26
Comments5
View on HN
blog.0patch.com 6y ago

Our First Weeks of Securing Windows 7 and Windows Server 2008 R2

dielel
1pts0
0patch.blogspot.com 8y ago

Microsoft Has Manually Patched Their Equation Editor Executable

dielel
553pts159
0patch.blogspot.si 9y ago

0patching the “Immortal” CVE-2017-7269

dielel
1pts0
0patch.blogspot.com 9y ago

0patching the “Immortal” CVE-2017-7269

dielel
2pts0
0patch.blogspot.si 9y ago

0patching Another 0-day: IE 11 Type Confusion by Google's Project Zero

dielel
1pts0
0patch.blogspot.com 9y ago

Another Windows 0day from Google's Project Zero Gets a Micropatch(CVE-2017-0037)

dielel
3pts0
0patch.blogspot.com 9y ago

0patching a 0-day: Windows gdi32.dll memory disclosure

dielel
108pts43
0patch.blogspot.com 9y ago

One Step Closer to Crowdpatching and Patch Bounties

dielel
1pts0
0patch.blogspot.com 9y ago

One Step Closer to Crowdpatching and Patch Bounties

dielel
2pts0
0patch.blogspot.com 9y ago

Micropatching gstreamer bug CVE-2016-9445 with 0patch Agent on Linux

dielel
1pts0
0patch.blogspot.si 9y ago

The Birth of the World's First Self-Healing Micropatch

dielel
1pts0
0patch.blogspot.com 9y ago

The story about how we created 0patch for Foxit Reader CVE-2016-3740

dielel
2pts0
0patch.blogspot.com 10y ago

Just 11 bytes – a 3rd-party “micropatch” for a vulnerability in Acrobat Reader

dielel
1pts0
0patch.blogspot.com 10y ago

Just 11 bytes – a 3rd-party “micropatch” for a vulnerability in Acrobat Reader

dielel
1pts0
news.ycombinator.com 10y ago

3rd-party “micropatch” for a vulnerability in Acrobat Reader

dielel
1pts0
0patch.blogspot.com 10y ago

0patch Open Beta Is Launched

dielel
2pts0
blog.acrossecurity.com 10y ago

Bridging the “Security Update Gap” with 0patch

dielel
1pts0
blog.acrossecurity.com 14y ago

Anatomy Of An Online Bank Robbery

dielel
1pts0
blog.acrossecurity.com 14y ago

Adobe Reader X (10.1.2) msiexec.exe Planting

dielel
2pts0
blog.acrossecurity.com 14y ago

Downloads Folder: A Binary Planting Minefield

dielel
1pts0
blog.acrossecurity.com 14y ago

Should We Be Focusing On Vulnerabilities Or Exploits?

dielel
1pts0
blog.acrossecurity.com 14y ago

Is Your Online Bank Vulnerable To Currency Rounding Attacks?

dielel
8pts1
blog.acrossecurity.com 14y ago

Google Chrome HTTPS Address Bar Spoofing

dielel
103pts4
blog.acrossecurity.com 14y ago

Google Chrome pkcs11.txt File Planting

dielel
2pts0
blog.acrossecurity.com 14y ago

More Misconceptions About Binary Planting

dielel
1pts0
blog.acrossecurity.com 15y ago

The Unbearable Lightness Of Non-Fixing

dielel
2pts0

ryanburk, thanks a lot for your comment. We at 0patch are big fans of MS Patch Tuesday from it's very beginning. It was a huge improvement for appsec for more than decade and it still is. But as active pentesters with more than 15 years of experiences we just noticed that our enterprise customers can not apply patches timely and usually their (also critical) systems remain unpatched for several months. It looks they cannot cope with the amount of update changes and testing so they rather decide not patch. That was even worse than not to have a patch from official vendor.

There is one important technical difference between small pre-PatchTuesday patches and micropatches: pre-PatchTuesday patches were installed binaries (actually complete new version of the product) that are here to stay forever – or at least until patch uninstall or product upgrade. Imagine how hard is patch uninstall on CEO's patch-corrupted system on a business travel, for instance. Micropatches only live in memory, they die with the process. They don’t change file system and installed product, just redirect maliciously used instruction (just instruction, not the whole function) to correct path, if possible. It’s just couple instructions any admin could review by himself and switch of, if there is a problem. I wish I could say that for today’s patching procedures. For us it is the idea worth trying. We just have to simplify updating process for users (and software vendors, too).

p.s.: we are aware Microsoft gave up the idea of hot patching some years ago, but as I know they were not changing just couple of instructions. Please correct me if I’m wrong.

Hi, Stanka from 0patch here. If you want to enable or disable (aka "patch" or "unpatch" the application) you don't need do restart the application. Not even if your app is running and you've just install 0patch agent. This is how it is designed to work in user space. When the official MS patch is installed (hopefully with the fix) this particular 0patch won't apply anymore.

As we try to make 0patch agent robust and reliable we don't support kernel mode at this moment - we will make this step slow and with great caution.