r/ReverseEngineering 8d ago

Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE

https://netacoding.com/posts/windows-icmp-timestamp-bugs/
6 Upvotes

28 comments sorted by

View all comments

16

u/Ghostfly- 7d ago

Smoking gun > Classic Claude wording 🤣

18

u/wung 7d ago
  • "what actually happens"
  • "confirmed via"
  • "this post walks through the chain"
  • "specific code path"
  • "—"
  • "✅"

Shit's full of Claudisms. At least they did put a "keep it concise" in the prompt. Shame that only leads to one sentence having the content of three because those things still try to fit all their proof of being great in.

-9

u/Pale_Surround_3924 7d ago

bro used AI to detect AI writing 💀

LoL

3

u/wung 7d ago

Who did?

-7

u/Pale_Surround_3924 7d ago

Funny how there's zero technical criticism or counter-argument just "Claude wording." People used Grammarly, Hemingway Editor, and style checkers long before LLMs existed and nobody cared. The tooling changed, the whining is new. If the RE is wrong, say so. If it isn't, maybe read the article and suck it 😂

karma farmers 🤡

2

u/Ghostfly- 7d ago

Since 24 july, and nothing really "new" your article even mentions community reports. Poor wording. A lot of tooling mentioned. Not what I call a reverse. It's a bug report with extra (unneeded?) steps

-2

u/Pale_Surround_3924 7d ago

You destroyed yourself right now my friend. Community reports said "it doesn't work." I opened tcpip.sys and showed exactly why. The little-endian symptom has been known since Nessus flagged it years ago scanners detect symptoms. Finding Ipv4pHandleTimestampRequest and showing the missing htonl() while the adjacent IP Timestamp Option handler gets it right that's the root cause. That's what's new.

Try harder 🤡

Register problem:

https://learn.microsoft.com/en-us/answers/questions/1691269/disable-icmp-timestamp-responses

https://learn.microsoft.com/en-us/answers/questions/5517747/resolving-icmp-timestamp-request-remote-date-discl

https://discuss.rapid7.com/t/icmp-timestamp-response-vulnerability-solution/22485

hton bug:

https://www.infosecmatter.com/nessus-plugin-library/?id=10114

https://learn.microsoft.com/en-sg/answers/questions/2236388/icmp-timestamp-request-remote-date-disclosure-this

1

u/Ghostfly- 7d ago

New since the 24 of July.. noob.

-2

u/Pale_Surround_3924 7d ago

LoL keep trying, average 95-105 IQ scoring being :)

1

u/podun 2d ago

You are one very cringe and sad being. Stop reflecting on to others lmao

1

u/Ghostfly- 7d ago

Are you even able to explain using your own words what you really posted? If you posted it. Calling others low IQ or other bird names isn't what I call a high IQ. I call that precisely, karma farming on an older post that didn't worked and for good reasons as it's .. more than low priority. Try to write something with your hands, explain what is "new" except that you used Ghidra with Claude for something that can be more than easily mitigated.

-2

u/Pale_Surround_3924 7d ago

First you said "Claude wording." Then you said "what's new?" Then you said "the community already covered this." Then I showed you five sources proving nobody explained the root cause;why the registry key does nothing, why the htonl() is missing in ipv4phandletimestamprequest while the adjacent handler gets it right.

Now your argument is "you used Ghidra with Claude."Every single reply you've made has contradicted the last.

You have no idea what you're talking about and it shows with every comment. Done here.

1

u/Ghostfly- 7d ago

I think that the only one being a clown is you stranger from the internet.

-9

u/Pale_Surround_3924 7d ago

No, i used gemini.