Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

1–10 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#4
This all seems a bit silly, and could easily be attributed to a communication issue.

On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected.

Even modzero themselves admitted that the vulnerability is not of great severity so the motivation for the security triage team to put more resources in validating a non-severe bug are probably very low. They likely just tried to run the exploit, and didn't think much of it after it didn't work.

Also if modzero is not participating in a bug bounty program then CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix.

I'm no fan of CrowdStrike (in fact, one of the more memorable moments for me at my previous job was my boss calling them "ClownStrike"), but it seems as if this is just a bit of overzealous entitlement from modzero as well as not enough testing on CrowdStrike's end.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#5
post #4

This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected. Even modzero…

> Even modzero themselves admitted that the vulnerability is not of great severity

They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway.

> CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix

Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sure they'll work it out if this gets noticed.

My first direct experience with CrowdStrike was the announcement of VENOM back in 2015 [1], which they coordinated with a few friendlies like FireEye but left most of us in the dark about (I was at Palo Alto Networks, not exactly a small company). Looks like they still struggle with this stuff.

1. https://web.archive.org/web/20150514062749/https://venom.cro..., possibly the origin of named and marketed vulnerabilities.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#6
post #4

This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected. Even modzero…

> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sur…

> privilege escalation tends to be easy on Windows anyway

Well, Crowdstrike is supposed to catch and prevent that...

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#8
Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers.

Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers after all.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#9
post #4

This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected. Even modzero…

To me it looks like like a very clear case of a writing/speaking words which they know (or the company clearly should have known) not to be true.

One could perhaps call this a "communication problem", but I'd like to think most people would call it lying

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#10
post #2

That doesn't give me the impression of a company focussed on security. That they marked the installer of the PoC as "malicious" shows they do have a process, but don't take it seriously.

It’s the snake oil industry. They don’t sell security, they sell CISO get out of jail cards in the form of client agents that constantly remind you of their divine presence by being on top of the CPU utilization sorted process list.
Post reply on HN