19 ms·
Remote Code Execution on Most Dell Computers
- albertgoeswoof 7y agoThis is exactly why you should remove any bundled software from vendors and try to start afresh when picking up a new machine.
- NullPrefix 7y agoLenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.
- josteink 7y agoThat caused so much of a backlash that they released a new BIOS version without that stuff. As was absolutely fair. Abusing Windows' ability to obtain HW-drivers though UEFI (something which can be used for good) to bundle shit-ware is just absolutely rotten.
- twblalock 7y agoMicrosoft should prevent this. It's not in their interest to allow OEMs to circumvent the normal software installation methods for Windows. It should be prohibited in whatever agreement OEMs make with Microsoft, and maybe Windows should prevent execution of such code if it's possible to tell it apart from drivers.
- ru999gol 7y agothat's something Apple would do, but unfortunately Microsoft doesn't give a shit
- ilikehurdles 7y agoI'm inclined to agree. Microsoft's philosophy has been "give vendors all the rope they could think of asking for" for a really long time.
- bahmboo 7y agoPretty sure there was a USG lawsuit about what MSFT could require from OEMs.
- Gene_Parmesan 7y agoI don't think that settlement applies to this. The OEM part of that lawsuit, from my recollection, hinged on the fact that Microsoft's OEM licenses required that the OEM limit the percentage of computers they sold without a Windows OS pre-installed. I don't remember there being anything about how OEMs use their APIs. I think it would be perfectly fair for Microsoft to require OEM licensees to not use that feature for shitware installations. I can't see how that would fall afoul of antitrust or related regulations. Maybe I'm wrong though, that was a while ago and it wasn't my specialty when I practiced law.
- deogeo 7y agoFair would be sending executives to jail for hacking. Releasing a non-backdoored BIOS was the absolute minimum. Edit: As pointed out by josteink, the BIOS wasn't backdoored - it was used to install a backdoor. But calling what it installed "insecure Windows-software" is also inaccurate. According to https://en.wikipedia.org/wiki/Superfish#Lenovo_security_incident https://en.wikipedia.org/wiki/Superfish#Lenovo_security_inci..., its purpose was man-in-the-middle attacks against the user. So I still think criminal liability and jail time would be just. Ordinary people have been sent to jail for far less.
- stcredzero 7y agoFair would be sending executives to jail for hacking. That would be up to a prosecutor. A civil suit would take the form of a class action.
- josteink 7y agoTo be fair and technically correct, the BIOS itself was not backdoored. The BIOS itself was fine, but it contained insecure Windows-software which it requested/instructed Windows to install. Install any other OS (like Linux) and there would be no backdoor at all. To be clear I’m not trying to defend Lenovo’s actions here, I’m just trying to be clear about what this incident was actually about. The simplistic description is IMO a bit too simplistic in this case.
- walshemj 7y agoOr banning for a period of years the company from any government work as happened to Arthur Anderson in the UK.
- MisterTea 7y agoI wouldn't call that good. More like a bad solution to a problem which shouldn't exist. Nothing should ever be located in system firmware save for the boot firmware and perhaps a basic diagnostic tool like memtest.
- sneak 7y agoThat’s astounding. Suddenly my “zero the entire storage, including partition table” methodology which I always somewhat regarded as overkill appears to be reasonable and/or necessary.
- albertgoeswoof 7y agoYour approach won’t solve that, you’d need to also flash the chip with patched / clean firmware
- cryptonector 7y agoAnd you might not be able to.
- w8rbt 7y agoZero it and install Linux. Problem solved.
- cryptonector 7y agoIt could effectively a ring -2 rootkit, and it could prevent you from removing it.
- Wowfunhappy 7y agoShort of flashing the chip, which is impractical, are there any other "imperfect but probably sufficient" workarounds? For example, would loading Grub first, and then loading Windows from Grub, prevent the issue?
- snazz 7y agoBasically none. You’ve got the ME (or AMD’s equivalent) on the CPU anyway so you really can’t avoid having some kind of root kit. Older Intel hardware that doesn’t have the ME or can be neutered is the best bet, and these machines don’t use UEFI anyway. Otherwise you could go for a non-Intel/AMD architecture, but there aren’t that many of those around anymore.
- mehrdadn 7y ago> Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install. Holy cow. Would you have a link on this?
- NullPrefix 7y agoThe tech is called Windows Platform Binary Table, WPBT for short. Here's a random article covering it https://www.howtogeek.com/226308/the-windows-platform-binary-table-why-crapware-can-come-back-after-a-clean-install/ https://www.howtogeek.com/226308/the-windows-platform-binary... You can find others by searching for "lenovo wpbt" or "lenovo unremovable crapware".
- mehrdadn 7y agoThanks!
- shawnz 7y agoI just checked on my Dell workstation at work and it seems they are now using this method to load the Lojack anti theft rootkit. I see the wpbbin.exe file and it's signed by Absolute Software. I guess that is what the feature is designed for, though.
- snazz 7y agoMany computer manufacturers seem to do this at least. There might be a way to trick the UEFI into thinking that you’re installing a non-Windows OS but I’m not sure.
- josteink 7y agoYou got it completely backwards. UEFI doesn't install anything. It provides a machine-specific binary for Windows to install (intended to ensure that Windows has proper drivers for all the machine’s hardware). Windows then decides to install this, based on the assumption that OEMs won’t bundle non-critical shit-ware using this method. Which has turned out to be the faulty assumption here. Either way: Use any other OS except Windows and these UEFI-bundled binaries does nothing. They’re duds. UEFI doesn’t need to be “tricked” and it can’t force the installation of anything into an OS not wanting it. It’s really simple, so no need to invent overly complicated threat models.
- vondur 7y agoLenovo has a program basically identical to this. I wonder if it’s got any of the same problems as the Dell version.
- criddell 7y agoMy last two computers have been Lenovo ThinkPads (T520 and Yoga S1) and they bundle more crappy software than just about any other business computer maker. It's good hardware and once you reformat and reinstall Windows (or Linux) they are great machines.
- Gene_Parmesan 7y agoI'm strongly considering the ThinkPad P1 as my next work machine -- any other issues you've experienced? I wouldn't have expected Lenovo to mess with the ThinkPad brand like that. My image of ThinkPad has always been no-nonsense, get-stuff-done, power-user-favored. Packing in a bunch of cruft doesn't seem to mesh with that image.
- jake_the_third 7y ago> I wouldn't have expected Lenovo to mess with the ThinkPad brand like that. My image of ThinkPad has always been no-nonsense, get-stuff-done, power-user-favored. I used to think the same until I got a T480. I was drawn to it because it was one of the few laptops that still has a direct hardware Function-key row (I use linux, so software Function Keys are not fun). The keyboard, while mechanically excellent, is horribly designed if you depend on it to do your job: They "innovated" by moving the Home/End keys up to the Function row, they "innovated" by completely removing the context menu key from the keyboard and placing the PrintScreen key (of all things) in its place, and they also placed the Fn key at the bottom left corner of the keyboard where Ctrl is usually located (you can fortunately swap Ctrl/Fn with each other in the bios, so the last one isn't a issue if you're willing to live with mislabeled keys). If you're a heavy keyboard user, I strongly suggest properly testing a laptop's keyboard before buying.
- neilv 7y agoThe T520 mentioned above is the last in the T5x0 line before Lenovo started changing the keyboard layout and action in a way that seemed anti-ThinkPad. Same with the move from T420 to T430, so your T480 was a few generations further along an anti-ThinkPad path. Personally, I'm currently standardized&stockpiled on two legacy ThinkPad models, and one of the reasons is keyboards. I also transplant keyboard parts manufactured to T60 specs, into later models, because Lenovo started making the keyboard flex-prone, even as the part was otherwise equivalent.
- tinus_hn 7y agoMicrosoft pulled a stunt before when they made Windows load an executable from inside UEFI during every boot.
- Wowfunhappy 7y agoI chuckled, but come now, that's not the same thing. Apple keeps track of what you type for autocorrect and word prediction. "Apple installs a keylogger on every iPhone."
- tinus_hn 7y agoSure it isn’t the same thing. Microsoft created a system supporting malware that survives OS reinstallation. Lenovo was just using that system as intended.
- m463 7y agooh come on, it uninstalls itself after it has collected enough data. (sarcasm) [i thought it uninstalled itself after a few months]
- tssva 7y agoUnfortunately I have a MacBook and Apple won't even let me uninstall the chess program bundled with macOS.
- Razengan 7y agoIt's barely 5 megabytes.. and it's probably not connecting to anything. The protections for pre-installed apps help to make sure nothing else tampers with them, e.g. injecting some malware, but I'm sure you can remove those protections and reclaim the 5 MB if you really wanted to. https://developer.apple.com/library/archive/documentation/Security/Conceptual/System_Integrity_Protection_Guide/ConfiguringSystemIntegrityProtection/ConfiguringSystemIntegrityProtection.html https://developer.apple.com/library/archive/documentation/Se...
- tssva 7y agoChess was given as an example of the ridiculous situation that not even a game can be removed by default. There are a host of other larger apps I would like to remove such as Home, Maps, News, Books, FaceTime, Messages and Mail. I never use any of them and would prefer they were gone from my computer. Disabling system integrity protection to uninstall them should not be required and I'm guessing wouldn't be a long term solution anyways because likely they would reappear when upgrading macOS versions. There is also the issue of why does chess need greater protection from being tampered with than say Apple Pages.
- gerdesj 7y agoI installed Arch on this Dell laptop without even seeing Windows. I personally would do as you suggest if I wanted Windows on it but then I own an MS "partner". Everyone else has to run the uninstallers and hope that they actually remove everything and not leave things behind.
- tracker1 7y agoIt's been a while... but prior to my current laptop, I'd generally remove the factory HD and replace with an SSD before even booting once. Installing a fresh OS from the start.
- orf 7y agoI found something similar to this a few years back[1], where the daemon would download and run anything if just “dell” was in the referring host. It seems they have improved the security somewhat by using white lists, but their coding practices seem a bit shoddy. Why have an SDK token at all if it’s public and globally shared? I wouldn’t be surprised if a lot of the code was shared between the previous incarnation that I found an issue with and this pre-installed version. 1. https://tomforb.es/dell-system-detect-rce-vulnerability/ https://tomforb.es/dell-system-detect-rce-vulnerability/
- AdmiralAsshat 7y agoI've seen something similar when I open Dell's site. uMatrix shows an attempt to run a localhost script, which looks shady as hell. I've never let that run. Much easier to just flip the laptop over, enter the six digit service code, and see if there are any new drivers/BIOS updates available for my laptop.
- m00dy 7y agoI'm not going to buy Dell again...
- the_pwner224 7y agoThis is an exploit in the shitty software that OEMs put on their Windows images. Stuff like this is practically universal (minus Apple), and the fact that Dell hasn't (AFAIK) actively bundled very evil malware with their computers makes them far from the worst offender.
- deleted 7y ago[deleted]
- tssva 7y agoApple bundles plenty of software on their computers which I don't want, have never used, which increase the potential attack surface and which I can't uninstall. For example Apple Maps, Apple News, Home, and Books. In fact you can't uninstall any of the apps shipped with macOS. Not even the chess program.
- MagicPropmaker 7y agoExactly! With Windows you do have choices. I bought a desktop PC from ThinkMate configured exactly as I wanted it with a plain vanilla Windows 10.
- carleton 7y agoAs another user said- "It's barely 5 megabytes.. and it's probably not connecting to anything. The protections for pre-installed apps help to make sure nothing else tampers with them, e.g. injecting some malware, but I'm sure you can remove those protections and reclaim the 5 MB if you really wanted to." [1] https://news.ycombinator.com/item?id=19803067 https://news.ycombinator.com/item?id=19803067
- 7y ago
- Hamuko 7y agoA lot of government computers around this part of the world are Dell computers. Hopefully enterprise customers get fresh Windows installations.
- davidw 7y agoDell Computers running Windows, it looks like?
- justryry 7y agoWindows and Dell's SupportAssist crapware.
- xeromal 7y agoYeah, 99% of dell computers
- davidw 7y agoI have a Dell XPS 13 with Ubuntu.
- basetop 7y agoSadly. It disappoints me so much that linux hasn't been able to crack Windows dominance on desktop/laptop. I was sure that as more people became computer "literate", they'd shift to linux or bsd in droves. Boy was I wrong.
- MagicPropmaker 7y agoI'm very computer literate. That's why I run Windows 10, and Linux / BSD in a VM. I want to get things done.
- DoofusOfDeath 7y agoBeautiful writeup. I'm a developer but never work on web stuff, and even I found the story interesting and readable.
- hazelnut 7y agototally agree. and that guy is 17!
- hypervis0r 7y agoOnly 355687428096000 years old? Mustn't have even finished college!
- _bxg1 7y agoSounds like the attacker has to be on the local network (or presumably VPN) to use the exploit? If so that's a nontrivial hurdle in many cases.
- Tehnix 7y agoLike a WiFi at a café or airport?
- Tharkun 7y agoPublic WiFi networks really should use client isolation. Sadly, many don't.
- deleted 7y ago[deleted]
- Xylakant 7y agoEven if client isolation is used, do you trust your local cafe’s WiFi AP?
- euroclydon 7y agoYou can just go to a public place and run your own hotspot.
- codedokode 7y agoAnd use a name and SSID of some well-known public WiFi network. Then make a captive portal to force the user open an attacker-controlled page in a browser.
- ru999gol 7y agoit should be mentioned that even with WPA2-PSK wifi you are vulnerable to arp spoofing
- deleted 7y ago
- jniedrauer 7y agoGeneral sanity aside, the whole exploit hinges on the fact that they used string parsing to check for the prefix "http". This wouldn't have been exploitable if they used a proper URL library.
- DiseasedBadger 7y agoHonestly, they could have just used a whitelist instead of a blacklist. One could easily fuck usage of a library. Common sense is required. Attempting to ban "http" as a method of ensuring "https", is obviously less ideal than ensuring "https"... by checking for "https".
- cced 7y agoDo you think that a proper Url library would have protected against a MITM’d DNS attack?
- shkkmo 7y agoIt that library allowed them to enforce connection via HTTPS, then yes.
- deleted 7y ago[deleted]
- bennofs 7y agoURL parsers also have bugs (or at least don't all agree on one parsing if you rely on more than one parser). Just take a look at https://i.blackhat.com/us-18/Wed-August-8/us-18-Orange-Tsai-Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out-2.pdf https://i.blackhat.com/us-18/Wed-August-8/us-18-Orange-Tsai-... for some fun examples.
- anfilt 7y agoI watched that talk a while ago. It convinced of one thing you should only have one URL parser in a project, and don't pass a url to any thing that may parse it differently. It also made it clear that trying to use a URL to restrict stuff is a bad idea. Like the dell updater could only load signed requests which means an attacker would have to get dell's private key for signing.
- throwaway5752 7y agoDell service advisory (DSA): https://www.dell.com/support/article/us/en/19/sln316857/dsa-2019-051-dell-supportassist-client-multiple-vulnerabilities?lang=en https://www.dell.com/support/article/us/en/19/sln316857/dsa-... (from this submission) first CVE: https://nvd.nist.gov/vuln/detail/CVE-2019-3718 https://nvd.nist.gov/vuln/detail/CVE-2019-3718 (from DSA) second CVE: https://nvd.nist.gov/vuln/detail/CVE-2019-3719 https://nvd.nist.gov/vuln/detail/CVE-2019-3719 (also from DSA, this is the exploit described in this submission)
- joshlegs 7y ago`DiableInstallNow` i liked this json key in the api
- nldoty 7y agoI really wish it was possible to purchase hardware from any manufacturer with this stuff removed.
- ultrarunner 7y ago/r/buildapcsales is your friend
- taspeotis 7y agoMicrosoft sort of try with “Windows Signature.” https://www.laptopmag.com/articles/microsoft-signature-edition-windows-10-analysis https://www.laptopmag.com/articles/microsoft-signature-editi...
- deleted 7y ago[deleted]
- option_greek 7y agoThat's one of those garbage apps i proactively removed. Thank God.
- pojntfx 7y agoUse Linux.
- ergothus 7y agoI've not yet seen anyone comment on the fact that Dell was informed in late Oct, confirmed by late Nov...and the public was advised in mid April. That's a lot of time for a known and confirmed vulnerability to be undisclosed, isn't it?
- mosdl 7y agoCould be that it took a while to distribute the fix to all the affected PCs?
- ergothus 7y agoI'm sure it did, but this is the classic debate about disclosure: disclosing before the fix means that there will be more attackers. Not disclosing means anyone already exploiting the vulnerability is unwarned and defenseless. And sometimes, disclosing before a fix means the fix suddenly has resources and priority it didn't before. I usually hear about 90 day disclosure, not 160(ish). I'm not saying there should have been disclosure before the fix in this case...but I'd rather see more discussion on that than yet another vendorware complaint. (which are valid, but hardly news)
- driverdan 7y agoI would have publicly disclosed after 90 days. A single line of code would have closed the URL problem and could have been deployed the next day. Six months is ridiculous.
- obisw4n 7y agoI'm not surprised in the least, they have a Bugcrowd program and I've submitted atleast one P2 that took months to fix, and best of all - they don't pay bounties! what a joke if you ask me.
- cryptonector 7y agoOEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerable. Here's an idea: OEM: Let's differentiate our otherwise commodity hw product! OEM: Let's add NO bundled software. That would be fantastic.
- mro_master 7y agoYou forgot the last part: OEM: Profit
- agumonkey 7y agoit's almost a psychology experiment where brands con you just enough and let you absorb the pain long enough that they forgot and start browsing for a new machine, repeating the cycle
- mro_master 7y agoBut then the engineer in you says "I'll objectively choose the best hardware", and you end up with another lenovo. I really think it is the Windows Wizard Warriors that complain about bloatware, I always wipe it and start with a fresh install.
- bayareanative 7y agoI don't use Windows, but Lenovos ship without any bloatware. Vanilla Windows plus their drivers. That's it.
- agumonkey 7y agoThey used to have malware/rootkits class programs preinstalled not long ago. Unless you mean thinkpads.
- ocdtrekkie 7y agoFeel pretty validated on my decision that the OEM doesn't need a support backdoor on PCs. SupportAssist looked like a remote access tool combined with PC-Doctor.
- markbnj 7y agoPreinstalled crapware is one of the main reasons I still build my own desktops. Back when I used to buy Dells or HPs for the kids I always began the relationship with a reformat and reinstall. That was easy for me at the time because I had a complete MSDN sub with access to all versions of MS operating systems.
- anotheryou 7y agoThere is also the neat tool "Dell Display Manager". The only way to avoid the moody touch buttons on some Dell monitors to change their brightness: - updates served via HTTP through the browser only - as a binary (exe) - from a domain other than dell.com (delldisplaymanager.com) - signed by a 3rd party (En Tech Taiwan) - and nagging about updates every reboot (you can get an outdated version via dell.com, but it will want to update through said channel immediately) (And I bet this one gets pinged for updates, having the full url to the exe in the update check: https://www.entechtaiwan.com/updates/public/ddm.inf https://www.entechtaiwan.com/updates/public/ddm.inf )
- Liskni_si 7y agoNot the only way. I used to use ddctool [0] to change brightness on monitors and it worked even with some cheap old Benq displays. Unfortunately Linux doesn't support DDC over DisplayPort Multi-Stream Transport, but you won't need to worry about that. All you need is some Windows alternative to ddctool. This was the first search hit: https://www.clickmonitorddc.bplaced.net/ https://www.clickmonitorddc.bplaced.net/ [0]: https://github.com/danielng01/ddctool https://github.com/danielng01/ddctool
- anotheryou 7y agoOh thank you! I have an auto hotkey script triggering the DDM, but it's not working well.
- IshKebab 7y agoYeah it's not the only way. Windows actually provides and easy-to-use API to change screen brightness (since it's a standardised feature). I made a little physical knob that connects via USB to control mine since those capacitative buttons are a right pain.
- bredren 7y agoWhat is the bounty on a report like this, and does Dell operate an official bug bounty program? How much do you think a report like this should be worth? "Dell bug bounty program" and the like don't turn up obvious results to me.
- cjbprime 7y agoDell probably doesn't run one. If it did, I'd guess somewhere on the order of $20k? If the exploit was being bought by a company who traffics in zero-day exploits, some multiples larger of that.
- BillDemirkapi 7y agoUnfortunately Dell doesn't pay bounties no matter how serious the bug is.
- f311a 7y agoDell could send you a laptop at least.
- decotz 7y agojesus fucking christ. gotta block that port ASAP
- peter_d_sherman 7y agoFirst off, great article. But, like so many other articles about security vulnerabilities, there seems to be a general attitude among most people (including many IT shops) that "it's an isolated incident", and "the experts will fix it...". "It's an isolated incident", and "The experts will fix it...". They said the same thing about Spectre, Meltdown, Rowhammer attacks, what have you. "It's an isolated incident", and "The experts will fix it...". Well, if you read HN long enough, you'd know that there's too much of this on too regular a basis to continue to espouse those views. I'm going to go for broke here. I'm going to put on my conspiracy "what if" tin-foil hat, and ask two questions. The first is related to Virus-Checking and Security Software -- like Norton, McAfee, etc. how do we know that any of it doesn't contain remote code execution (aka major security) vulnerabilities? You see, if I were the bad guys, that's where I'd put it. Also, let's say you have Nation States. Could you see one of these guys "persuading, for the good of their country" one or more of their same-nationality corporations to put such vulnerabilities into their "Security" software? In other words, maybe you have a Chinese producer of anti-virus/security software, and maybe it has little "surprises" for non-Chinese Citizens. Maybe you have an American producer of anti-virus/security software, and it too has little "surprises" for non-American Citizens. You see? Nation A thinks that it's permissible and OK for it to compromise Nation B's "Security" software. And Nation B thinks the same thing, but in reverse. Even if Nation States are removed from the equation, you still have the Virus Checker/Security software company themselves. How do you know that random employees at that company haven't tainted that software in some way? In other words, "Who guards the guardians?" Which is my second question. It's an ancient philosophical question. "Who guards the guardians?" We The People - do not seem to be doing such a good job these days... All I know is that you might be seeing a whole lot more "isolated incidents" that "the experts will have to fix" in the future, unless We The People - step up to the plate...
- ilaksh 7y agoWell I think it's very possible that backdoors are set up by governments like you say. But I also think that even if they don't, it also seems very possible that vulnerabilities are quite common as mistakes. Just due to the realities of security. In my opinion security is much more difficult than people realize. For example in this case there seems to be a majority opinion something along the lines of "What an idiot! _I_ would never make that mistake!". It's much easier to say that in hindsight than it is to really execute secure code that no one can defeat. The response might be "well, no one broke into any of _my_ systems so far" and I would say .. how do you know they didn't? And also, maybe no one bothered to try to exploit you because you are not a high value target. Or they are just busy and will get to trying to penetrate you next week. I think this is due to the complexity of software and IT rather than general negligence.
- pg_is_a_butt 7y agoWeird how Dell signs exclusivity deals with Intel, and can't keep their computers secure. It's like they don't care.
- gloflo 7y agoSlightly tongue in cheek to counter the anti-(Chinese/Russians) tone in recent times: Seeing how close Dell (both the company and the man) are to the US government, surely this is a backdoor by the Americans?
- kpU8efre7r 7y agoIs the anti-China or anti-Russia unwarranted? Dell fucked up and should be held accountable. Being in America they will more than likely face legal action of some sort over this. I would hope so anyway.
- lone_haxx0r 7y agoIt's really hypocritical to call out Chinese companies for spying on people when most American tech companies spy on their users.
- artursapek 7y agoYeah but here we call it "analytics", not spying!
- deleted 7y ago[deleted]
- delfinom 7y ago>Being in America they will more than likely face legal action of some sort over this. Which America are talking about here? The one that let Equifax off scott free for leaking the entire countries personal financial info with security that resembles geocities? Dell won't get punished for shit.
- kpU8efre7r 7y agoYou mean the Equifax, the company currently being sued for that? https://www.law.com/dailyreportonline/2019/01/28/judge-oks-equifax-lawsuit-over-massive-data-breach/ https://www.law.com/dailyreportonline/2019/01/28/judge-oks-e...
- GordonS 7y agoGiven this is an RCE, and affects so many machines, does anyone else think it's unreasonable that it took Dell 5 months to fix this? Aside from anything else, it would have been terrible publicity for Dell if an exploit for this vulnerability was used in a large malware campaign - I just don't get why they would wait so long to fix it.
- taspeotis 7y agoThe author exploited this by adding a space to the URL so it no longer started with http:// http:// rather (space)http:// http:// but it looks like the call to Replace would be ineffective if the URL started with HTTP:// as well. bool flag2 = file.Location.ToLower().StartsWith("http://"); if (flag2) { file.Location = file.Location.Replace("http://", "https://"); } I trust the new version isn’t vulnerable to this...
- BillDemirkapi 7y agoThere were a bunch of ways to bypass the check. For example another way would be to use "http:\\" which wouldn't get detected either. The new version isn't vulnerable.
- codedokode 7y agoCannot this vulnerability be exploited by creating a free wi-fi access point, opening a captive portal on user's device and attacking them from there? Another option is to wait until the victim requests something with HTTP (some ad networks still use it) and inject the payload into the traffic.
- BillDemirkapi 7y agoYep.
- itslennysfault 7y agoGlad I wiped my XPS and put Ubuntu on it.
- elagost 7y agoI don't think there will ever come a time when 1) savvy users will stop suggesting/recommending clean Windows installs on new computers and 2) OEM bloatware will stop being crap. I clean-installed Win10 recently. There was no driver installation I had to do - everything works great, and there are no unidentified devices in Device Manager. Say what you will about Windows 10, but that part is really cool. Save for video cards, the pack-in drivers are often better and less hassle. Plus they auto update.
- ericfrederich 7y agoI have a Lenovo Thinkpad Yoga x1. I'm afraid to reinstall fresh Windows because of stylus
- robk 7y agoWorks fine w one exe from Lenovo
- hi5eyes 7y agorecently reinstalled w10 onto a laptop (dual booting on with legacy/uefi is somewhat of a headache) the hoops you have to jump through during installation is downright hell cortana just yells at you until you can turn it off, you have to deselect every invasive feature and then get to some windows sign into your ms account bullshit just.... why... since when did installing operating systems turn into avoiding landmines linux and mac install pretty quick, but windows? fuck off
- waddlesworth 7y agoI definitely advocate for Windows 10, it has a lot of features I like, but the auto-installing drivers has been a nuisance for me. The biggest issue is when I have a computer with both integrated graphics, and a dedicated graphics card. I used to disable integrated graphics in the BIOS, but this causes a litany of problems now. Even with integrated disabled, Windows 10 will still try and install the drivers for it, and every time it does this, they seem to take precedence over my dedicated drivers. I ended up giving up and just enabling integrated and leaving the drivers there.
- deleted 7y ago[deleted]
- dontbenebby 7y agoDo they also install this stuff on their linux offerings? :/
- Tiki 7y agoI bought an Alienware that cost 4300$ last year, and that's after 900$ in savings. The computer arrived in a box that had 2 handle sized holes in it and I could see the computer directly exposed from the outside without the box being open. It had shipment dust and debris INSIDE THE BOX. It's the saddest, cheapest, most sorry ass excuse for a shipment I've ever seen. I took pictures, I couldn't believe it. Then I booted it up and was inundated with Dell pre-installed software. Wiped the thing clean, got a Win10 ISO directly from MS and called it a day. This will be the last Dell I ever buy. Lesson learned.
- lopmotr 7y agoThis doesn't sound quite as scary as the title. You still have to do one of these things that will all be nearly impossible in general. It's not like you can just set up a website and wait for victims to visit it. - XSS on one of Dell's sites. - Find a Subdomain Takeover vulnerability on a Dell site. - Make the request from a local program. - DNS Hijack the victim.
- sannee 7y ago> - DNS Hijack the victim. This is the trivial one. You can just set up a free Wi-Fi access point next to a restaurant that people from company-you-want-to-hack like to visit.
- cryptokernel 7y agoYet another exploit? Just leaving this here: do tasks, get paid. https://coincircle.com/l/50VVxbObg3 https://coincircle.com/l/50VVxbObg3
- nanahgafvsva 7y agoNice writeup! Only feedback is it seems like you dont need to dna hijack anything. Seems like you can just register localhost-lollolanything.com and pull the attack off, no?
- c- 7y agoThere's code that checks for the domain ending in .dell.com (etc) so it wouldn't work.
- deleted 7y ago[deleted]
- amaccuish 7y agoIf this was Huawei it'd be called a backdoor.
- kristianp 7y agoIntel has a similar update assistant that runs on thinkpads at least: https://www.intel.com/content/www/us/en/support/intel-driver-support-assistant.html https://www.intel.com/content/www/us/en/support/intel-driver...
- Jonnax 7y agoIntel also has a similar tool that you install to check for updates and you visit a web page to get your updates. Does it work in a similar way?
- olefoo 7y agoHmm. I have a Dell laptop, but replaced Windows 10 with Ubuntu. I doubt I'm vulnerable to that... but my security stance is probably not as strong as it could be.
- deleted 7y ago[deleted]
- thrower123 7y agoAmazing, Dell bullshit antivirus is bullshit
- sara1232364 7y agoWorld's biggest cat Even you can't believe it's size See her video https://howto105.blogspot.com/2019/04/worlds-biggest-cat.html https://howto105.blogspot.com/2019/04/worlds-biggest-cat.htm... They found world's biggest fish Even you can't believe how big fish is this That's unbelievable http://bit.ly/2FHl4pM http://bit.ly/2FHl4pM Even some goats are better than humans See that she did and they made her as mayor of city http://bit.ly/2UjTcS5 http://bit.ly/2UjTcS5
- bayareanative 7y agoSpeaking of exploits... aren't nearly all Intel-processor systems vulnerable to attacks against IME? Has anyone disabled IME by putting it into HAP mode or another mode?
- Iv 7y agotl;dr: A software opens a port to allow a remote website trigger "download and execute" actions on a URL pointing to an .exe file. The security check they have is that they check the domain is dell.com and that the string starts with "https://" https://". If it starts with http:// http:// it is replaced by the https version. In theory I could consider this risky but safe. The mistake is that they do not force a URL that starts with something else to fail. The attacker could bypass the check by providing " http://fakedns.dell.com/haxorz.exe" http://fakedns.dell.com/haxorz.exe" (with a space at the beginning) and it passed the check. This is not the first flaw of this style I am seeing. I don't think a teacher ever explicitly told it to me but I always assumed that relying on DNS for authentication was a dangerous thing to do and that URLs were doing too many things behind the scenes to be trustworthy without being extremely picky. Maybe it all changed with https, but trusting the execution of an exe without at least checking the a crypto signature lights some red flags in my brain.
- chunsj 7y agoIs this related to Dell Computers (so it does include laptops with Linux OS) or Windows OS (which I mean spywares on Windows OS)?
- Erin_Smith 7y agoNote to those lurking that the author could not achieve RCE without man in the middle from the local network.
- Jacksoft 7y agoHP use a similar service (HP support assistant) that permits HP website to discover your machine and driver. It would be nice to discover if it have the same vulnerability...
- daveheq 7y agoI thought this was old news... I swear I heard and read about this last year, maybe even before mid-year.