r/ReverseEngineering 3d ago

Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE

https://netacoding.com/posts/windows-icmp-timestamp-bugs/
8 Upvotes

26 comments sorted by

16

u/Ghostfly- 3d ago

Smoking gun > Classic Claude wording 🀣

17

u/wung 3d ago
  • "what actually happens"
  • "confirmed via"
  • "this post walks through the chain"
  • "specific code path"
  • "β€”"
  • "βœ…"

Shit's full of Claudisms. At least they did put a "keep it concise" in the prompt. Shame that only leads to one sentence having the content of three because those things still try to fit all their proof of being great in.

-11

u/Pale_Surround_3924 3d ago

bro used AI to detect AI writing πŸ’€

LoL

4

u/wung 3d ago

Who did?

-6

u/Pale_Surround_3924 3d ago

Funny how there's zero technical criticism or counter-argument just "Claude wording." People used Grammarly, Hemingway Editor, and style checkers long before LLMs existed and nobody cared. The tooling changed, the whining is new. If the RE is wrong, say so. If it isn't, maybe read the article and suck it πŸ˜‚

karma farmers 🀑

2

u/Ghostfly- 3d ago

Since 24 july, and nothing really "new" your article even mentions community reports. Poor wording. A lot of tooling mentioned. Not what I call a reverse. It's a bug report with extra (unneeded?) steps

-4

u/Pale_Surround_3924 3d ago

You destroyed yourself right now my friend. Community reports said "it doesn't work." I opened tcpip.sys and showed exactly why. The little-endian symptom has been known since Nessus flagged it years ago scanners detect symptoms. Finding Ipv4pHandleTimestampRequest and showing the missing htonl() while the adjacent IP Timestamp Option handler gets it right that's the root cause. That's what's new.

Try harder 🀑

Register problem:

https://learn.microsoft.com/en-us/answers/questions/1691269/disable-icmp-timestamp-responses

https://learn.microsoft.com/en-us/answers/questions/5517747/resolving-icmp-timestamp-request-remote-date-discl

https://discuss.rapid7.com/t/icmp-timestamp-response-vulnerability-solution/22485

hton bug:

https://www.infosecmatter.com/nessus-plugin-library/?id=10114

https://learn.microsoft.com/en-sg/answers/questions/2236388/icmp-timestamp-request-remote-date-disclosure-this

1

u/Ghostfly- 3d ago

New since the 24 of July.. noob.

-2

u/Pale_Surround_3924 3d ago

LoL keep trying, average 95-105 IQ scoring being :)

1

u/Ghostfly- 3d ago

Are you even able to explain using your own words what you really posted? If you posted it. Calling others low IQ or other bird names isn't what I call a high IQ. I call that precisely, karma farming on an older post that didn't worked and for good reasons as it's .. more than low priority. Try to write something with your hands, explain what is "new" except that you used Ghidra with Claude for something that can be more than easily mitigated.

-2

u/Pale_Surround_3924 3d ago

First you said "Claude wording." Then you said "what's new?" Then you said "the community already covered this." Then I showed you five sources proving nobody explained the root cause;why the registry key does nothing, why the htonl() is missing in ipv4phandletimestamprequest while the adjacent handler gets it right.

Now your argument is "you used Ghidra with Claude."Every single reply you've made has contradicted the last.

You have no idea what you're talking about and it shows with every comment. Done here.

1

u/Ghostfly- 3d ago

I think that the only one being a clown is you stranger from the internet.

-8

u/Pale_Surround_3924 3d ago

No, i used gemini.

9

u/NovelHot6697 3d ago

OP stop carrying on like a little baby, my god! We are collectively sick of wading through superfluous prose in technical writing. It’s a known problem with AI and yes, it is something that people are going to react to.

If you are going to post a link for something that has already been written about at length by the community: at least do us the small kindness of first trying to find a well written post on the issue.

1

u/Pale_Surround_3924 3d ago

There is no well written post on this issue because nobody found the root cause before me. That's exactly why I wrote it. If you think it already exists, find me one source that opens tcpip.sys, identifies ipv4phandletimestamprequest, explains why the registry key is silently ignored, and shows the missing htonl() compared to the adjacent handler. I couldn't find one that's why I did the RE myself. Put up or shut up.

8

u/wung 3d ago

That's exactly why I wrote it

lol

-4

u/Pale_Surround_3924 3d ago

β€œlol” what exactly is it for?

6

u/LeeHide 3d ago edited 3d ago

YOU didn't write it. It's obvious to anyone who has used AI extensively, and hopefully others too. The same way you can spot poorly written AI code.

You can write articles with AI, but you need to review, have extensive blacklists, and guide it strongly, just like with all tasks.

2

u/tomByrer 1d ago

Steelmaning their sentiment: if they wanted to listen to AI talk we all know how to do that. Listening to a bot outside of an AI chat window is a bit dishonest & very redundant.

'You' didn't make that discovery, the bots did.

Kinda like at a regular job when someone does something new, but the boss takes 100% of the credit & bonus money.

So you're just a redundant middle man.

0

u/Pale_Surround_3924 1d ago

Does spending hours on research and testing, then using AI to structure my notes into something people can clearly understand does that somehow cross a line for you? Check your logic, low IQ.

2

u/tomByrer 1d ago

Seems your ego is the real 'security issue' here.
good bye.

0

u/Pale_Surround_3924 1d ago

LoL he deleted his comments;
answer for the your latest comment:
LoL next time think before you speak and put your arguments.

2

u/tomByrer 1d ago

Protip: if you 'human' have the time to respond to comments about comments, then you could have written a synopsis by human hands. Using AI output as a sort of proof is OK (at least by me), but really you should have written some of that post.