Earlier quoted context omitted.
I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Calling it a "backdoor" ascribes a certain intentionality to the vulnerability that's not clear is warranted. It's about the code quality I expect from the management shovelware that comes preloaded on laptops from any major brand. Source: I've written kernel drivers and exploits.
What is not malicious about a driver whose pure function (this thing literally has no other value or purpose) is maintaining an invincible NT_AUTHORITY process of their pre-installed management software? And achieving that by allocating a RWX page in services.exe? What are we even doing W^X for? Maybe we have different expectations of what a driver is. Take a look for yourself, even the updated PC Manager Software on…
Microsoft finds privilege escalation vulnerability in Huawei driver
61–70 of 138 posts
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#62Earlier quoted context omitted.
I guess it's because Defender ATP is basically some kind of cloud-service for security and because everyone is running Windows for everything it's targeted at managers or so. I have no idea how useful it is, but I guess they have some advanced techniques to detect certain attacks (like this one, or the dropped DoublePulsar) - If you have to defend some important Active Directory Setup it's probably not a bad deal. It…
Wow, that Logitech app is crazy huh, they just opened a port from all their Logitech Options users to anyone enabling them to make a remote keylogger. MS must have written a huge exposé on that one, can't seem to find it on their Security site though.
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#63Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#64Earlier quoted context omitted.
So now every bug on a privilege boundary is a backdoor, because of "plausible deniability"?
Then what other kinds of software need to use a privilege escalation?
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#65Earlier quoted context omitted.
Wow, that Logitech app is crazy huh, they just opened a port from all their Logitech Options users to anyone enabling them to make a remote keylogger. MS must have written a huge exposé on that one, can't seem to find it on their Security site though.
Google writes about the bugs they find, Microsoft writes about the bugs they find. What's strange to you?
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#66Earlier quoted context omitted.
What is not malicious about a driver whose pure function (this thing literally has no other value or purpose) is maintaining an invincible NT_AUTHORITY process of their pre-installed management software? And achieving that by allocating a RWX page in services.exe? What are we even doing W^X for? Maybe we have different expectations of what a driver is. Take a look for yourself, even the updated PC Manager Software on…
Writing "drivers" that do questionable things for even more questionable reasons seems to be par for the course in the Windows ecosystem. If I understand the whole situation correctly, Fortnite installs WHQL certified kernel driver, whose sole purpose is to cause BSOD when LSASS.EXE maps pages from the Fortnite process...
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#67But can each country has their own manufactured computer and os? Or region?
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#68Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#69From scanning the page it sounds like Huawei used a hack to make their MateBookService unkillable, unremovable, by unhooking in to services.exe. That in the process of that they left the possibility that the device they were using HwOs.*\.sys was only protected from being used by checking the program had the right path, thus leaving it open to crackers (it being basically g+rw) to use to get the ring-0 permissions ne…
I guess it's because Defender ATP is basically some kind of cloud-service for security and because everyone is running Windows for everything it's targeted at managers or so. I have no idea how useful it is, but I guess they have some advanced techniques to detect certain attacks (like this one, or the dropped DoublePulsar) - If you have to defend some important Active Directory Setup it's probably not a bad deal. It…
It's a familiar pattern. If a large company were a biological organism, one of it's main pain signals would be negative PR. Prod the beast in other ways and it doesn't respond.
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#70Earlier quoted context omitted.
Hey, Scientology is about making money, aka apples and oranges. Lots of religious movements and suppression’s would be more apt, try puritans.
From what I've heard, Falun Gong is about making money too. It's basically "hey we'll help you and be real nice to you and help you get back on your feet. Now it's your turn to pay up with donations". Which seems better than scientology, I'd say it's most comparable to mormonism
As far as I know, among them, Falun Gong and The Church of Almighty God was making false promise about their ability of "getting people back on their feet".
I don't know why people here are suddenly on fire when saw me put Falun Gong and cult together. In China, we use word "神棍"[0] to describe someone who fake their supernatural ability and pretend to be the messenger of god. And the word was come out before CCP even a thing, that alone can tell you something does it?
[0] https://zh.wikipedia.org/wiki/%E6%A3%8D%E9%A8%99#%E7%A5%9E%E...