<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dielel</title><link>https://news.ycombinator.com/user?id=dielel</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 25 May 2026 20:28:19 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dielel" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Our First Weeks of Securing Windows 7 and Windows Server 2008 R2]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.0patch.com/2020/02/our-first-weeks-of-securing-windows-7.html">https://blog.0patch.com/2020/02/our-first-weeks-of-securing-windows-7.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=22394298">https://news.ycombinator.com/item?id=22394298</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 23 Feb 2020 00:29:42 +0000</pubDate><link>https://blog.0patch.com/2020/02/our-first-weeks-of-securing-windows-7.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=22394298</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22394298</guid></item><item><title><![CDATA[New comment by dielel in "Microsoft Has Manually Patched Their Equation Editor Executable"]]></title><description><![CDATA[
<p>Thanks for sharing this. I suspected that "not being sure if you have the exactly right source code" could be a real world reason to patch a binary, and now I know.</p>
]]></description><pubDate>Fri, 17 Nov 2017 23:38:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=15726888</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=15726888</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15726888</guid></item><item><title><![CDATA[Microsoft Has Manually Patched Their Equation Editor Executable]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.html">https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=15720923">https://news.ycombinator.com/item?id=15720923</a></p>
<p>Points: 553</p>
<p># Comments: 159</p>
]]></description><pubDate>Fri, 17 Nov 2017 10:55:08 +0000</pubDate><link>https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=15720923</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15720923</guid></item><item><title><![CDATA[0patching the “Immortal” CVE-2017-7269]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.si/2017/03/0patching-immortal-cve-2017-7269.html">https://0patch.blogspot.si/2017/03/0patching-immortal-cve-2017-7269.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13996248">https://news.ycombinator.com/item?id=13996248</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 30 Mar 2017 15:34:02 +0000</pubDate><link>https://0patch.blogspot.si/2017/03/0patching-immortal-cve-2017-7269.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13996248</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13996248</guid></item><item><title><![CDATA[0patching the “Immortal” CVE-2017-7269]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html">https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13995034">https://news.ycombinator.com/item?id=13995034</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 30 Mar 2017 13:15:45 +0000</pubDate><link>https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13995034</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13995034</guid></item><item><title><![CDATA[0patching Another 0-day: IE 11 Type Confusion by Google's Project Zero]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html">https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13834782">https://news.ycombinator.com/item?id=13834782</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 09 Mar 2017 23:18:20 +0000</pubDate><link>https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13834782</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13834782</guid></item><item><title><![CDATA[Another Windows 0day from Google's Project Zero Gets a Micropatch(CVE-2017-0037)]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.com/2017/03/0patching-another-0-day-internet.html">https://0patch.blogspot.com/2017/03/0patching-another-0-day-internet.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13830510">https://news.ycombinator.com/item?id=13830510</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 09 Mar 2017 16:50:38 +0000</pubDate><link>https://0patch.blogspot.com/2017/03/0patching-another-0-day-internet.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13830510</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13830510</guid></item><item><title><![CDATA[New comment by dielel in "0patching a 0-day: Windows gdi32.dll memory disclosure"]]></title><description><![CDATA[
<p>You're absolutely right - we have this information scattered around blog posts and other material but it should be laid out in one place and in not-too-techy language. Thanks for pointing it out.</p>
]]></description><pubDate>Fri, 03 Mar 2017 14:54:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=13783213</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13783213</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13783213</guid></item><item><title><![CDATA[New comment by dielel in "0patching a 0-day: Windows gdi32.dll memory disclosure"]]></title><description><![CDATA[
<p>Our micropatch (7 of them, really, for 4 different Windows OS versions) for CVE-2017-0038 is user-mode. As are currently all our micropatches. Processes using gdi32.dll do not need to be relaunched to have it applied.</p>
]]></description><pubDate>Fri, 03 Mar 2017 14:45:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=13783152</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13783152</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13783152</guid></item><item><title><![CDATA[New comment by dielel in "0patching a 0-day: Windows gdi32.dll memory disclosure"]]></title><description><![CDATA[
<p>ryanburk, thanks a lot for your comment. We at 0patch are big fans of MS Patch Tuesday from it's very beginning. It was a huge improvement for appsec  for more than decade and it still is. But as active pentesters with more than 15 years of experiences we just noticed that our enterprise customers can not apply patches timely and usually their (also critical) systems remain unpatched for several months. It looks they cannot cope with the amount of update changes and testing so they rather decide not patch. That was even worse than not to have a patch from official vendor.<p>There is one important technical difference between small pre-PatchTuesday patches and micropatches: pre-PatchTuesday patches were installed binaries (actually complete new version of the product) that are here to stay forever – or at least until patch uninstall or product upgrade. Imagine how hard is patch uninstall on CEO's patch-corrupted system on a business travel, for instance. Micropatches only live in memory, they die with the process. They don’t change file system and installed product, just redirect maliciously used instruction (just instruction, not the whole function) to correct path, if possible. It’s just couple instructions any admin could review by himself and switch of, if there is a problem. I wish I could say that for today’s patching procedures.  For us it is the idea worth trying.  We just have to simplify updating process for users (and software vendors, too).<p>p.s.: we are aware Microsoft gave up the idea of hot patching some years ago, but as I know they were not changing just couple of instructions. Please correct me if I’m wrong.</p>
]]></description><pubDate>Fri, 03 Mar 2017 14:27:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=13783004</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13783004</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13783004</guid></item><item><title><![CDATA[New comment by dielel in "0patching a 0-day: Windows gdi32.dll memory disclosure"]]></title><description><![CDATA[
<p>Hi,
Stanka from 0patch here. If you want to enable or disable (aka "patch" or "unpatch" the application) you don't need do restart the application. Not even if your app is running and you've just install 0patch agent. This is how it is designed to work in user space. When the official MS patch is installed (hopefully with the fix) this particular 0patch won't apply anymore.<p>As we try to make 0patch agent robust and reliable we don't support kernel mode at this moment - we will make this step slow and with great caution.</p>
]]></description><pubDate>Fri, 03 Mar 2017 13:58:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=13782830</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13782830</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13782830</guid></item><item><title><![CDATA[0patching a 0-day: Windows gdi32.dll memory disclosure]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.com/2017/02/0patching-0-day-windows-gdi32dll-memory.html">https://0patch.blogspot.com/2017/02/0patching-0-day-windows-gdi32dll-memory.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13774397">https://news.ycombinator.com/item?id=13774397</a></p>
<p>Points: 108</p>
<p># Comments: 43</p>
]]></description><pubDate>Thu, 02 Mar 2017 14:58:16 +0000</pubDate><link>https://0patch.blogspot.com/2017/02/0patching-0-day-windows-gdi32dll-memory.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13774397</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13774397</guid></item><item><title><![CDATA[One Step Closer to Crowdpatching and Patch Bounties]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.com/2017/02/one-step-closer-to-crowdpatching-and.html">https://0patch.blogspot.com/2017/02/one-step-closer-to-crowdpatching-and.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13635502">https://news.ycombinator.com/item?id=13635502</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 13 Feb 2017 14:39:31 +0000</pubDate><link>https://0patch.blogspot.com/2017/02/one-step-closer-to-crowdpatching-and.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13635502</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13635502</guid></item><item><title><![CDATA[One Step Closer to Crowdpatching and Patch Bounties]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.com/2017/02/one-step-closer-to-crowdpatching-and.html">https://0patch.blogspot.com/2017/02/one-step-closer-to-crowdpatching-and.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13617839">https://news.ycombinator.com/item?id=13617839</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 10 Feb 2017 18:51:20 +0000</pubDate><link>https://0patch.blogspot.com/2017/02/one-step-closer-to-crowdpatching-and.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13617839</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13617839</guid></item><item><title><![CDATA[Micropatching gstreamer bug CVE-2016-9445 with 0patch Agent on Linux]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.com/2017/02/0patch-agent-on-linux-micropatching-cve.html">https://0patch.blogspot.com/2017/02/0patch-agent-on-linux-micropatching-cve.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13580636">https://news.ycombinator.com/item?id=13580636</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 06 Feb 2017 16:00:54 +0000</pubDate><link>https://0patch.blogspot.com/2017/02/0patch-agent-on-linux-micropatching-cve.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=13580636</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13580636</guid></item><item><title><![CDATA[The Birth of the World's First Self-Healing Micropatch]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.si/2016/09/the-birth-of-worlds-first-self-healing.html">https://0patch.blogspot.si/2016/09/the-birth-of-worlds-first-self-healing.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=12429912">https://news.ycombinator.com/item?id=12429912</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 05 Sep 2016 12:50:56 +0000</pubDate><link>https://0patch.blogspot.si/2016/09/the-birth-of-worlds-first-self-healing.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=12429912</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12429912</guid></item><item><title><![CDATA[The story about how we created 0patch for Foxit Reader CVE-2016-3740]]></title><description><![CDATA[
<p>Article URL: <a href="https://0patch.blogspot.com/2016/07/0patching-foxit-readers-heap-buffer.html">https://0patch.blogspot.com/2016/07/0patching-foxit-readers-heap-buffer.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=12165469">https://news.ycombinator.com/item?id=12165469</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 26 Jul 2016 13:34:57 +0000</pubDate><link>https://0patch.blogspot.com/2016/07/0patching-foxit-readers-heap-buffer.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=12165469</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12165469</guid></item><item><title><![CDATA[Just 11 bytes – a 3rd-party “micropatch” for a vulnerability in Acrobat Reader]]></title><description><![CDATA[
<p>Article URL: <a href="http://0patch.blogspot.com/2016/06/writing-0patch-for-acrobat-readers-use.html">http://0patch.blogspot.com/2016/06/writing-0patch-for-acrobat-readers-use.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=11937114">https://news.ycombinator.com/item?id=11937114</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 20 Jun 2016 10:14:21 +0000</pubDate><link>http://0patch.blogspot.com/2016/06/writing-0patch-for-acrobat-readers-use.html</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=11937114</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11937114</guid></item><item><title><![CDATA[Just 11 bytes – a 3rd-party “micropatch” for a vulnerability in Acrobat Reader]]></title><description><![CDATA[
<p>Article URL: <a href="http://0patch.blogspot.com/2016/06/writing-0patch-for-acrobat-readers-use.h">http://0patch.blogspot.com/2016/06/writing-0patch-for-acrobat-readers-use.h</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=11937106">https://news.ycombinator.com/item?id=11937106</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 20 Jun 2016 10:12:17 +0000</pubDate><link>http://0patch.blogspot.com/2016/06/writing-0patch-for-acrobat-readers-use.h</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=11937106</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11937106</guid></item><item><title><![CDATA[3rd-party “micropatch” for a vulnerability in Acrobat Reader]]></title><description><![CDATA[
<p>We have just published our own "micropatch" for a remotely exploitable memory corruption vulnerability in Adobe's Acrobat Reader DC, which was fixed by Adobe with their latest update.<p>Why did we do this? We want to fix the way vulnerabilities are getting fixed (the sheer amount of breaches tells us something <i>is</i> broken here), and we're going to do it with micropatching.<p>Vulnerability micropatching is a refreshing alternative to traditional security updates, which replace a large chunk of a software application or operating system, often require a restart and are tremendously difficult to revert in case of any problems. Our mighty little patching machine, 0patch (pronounced 'zero patch', https://0patch.com), allows for creation and deployment of tiny patches that can be applied directly and instantaneously to the memory of a running process, and can also be removed just as easily.
No restarts either way.<p>For more information, please see our blog post "Writing a 0patch for Acrobat Reader's Use-After-Free Vulnerability CVE-2016-1077"
(http://0patch.blogspot.com/2016/06/writing-0patch-for-acrobat-readers-use.h
tml).<p>0patch team
https://0patch.com
@0patch</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=11924254">https://news.ycombinator.com/item?id=11924254</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 17 Jun 2016 17:50:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=11924254</link><dc:creator>dielel</dc:creator><comments>https://news.ycombinator.com/item?id=11924254</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11924254</guid></item></channel></rss>