Working as a developer inside large enterprise is increasingly intolerable by the day, made possible by tools such as crowdstrike falcon. By the time your workstation is saddled with endpoint security, DLP, zero trust networking, antivirus, etc. it barely functions. And you can get in trouble for doing anything. Installing tree from homebrew can get you flagged on some naughty list where you have to justify why you n…
I recently finished an internship in a large company. I wanted to install netcat to troubleshoot networking issues between windows and docker containers I was running. Right when it was downloaded from scoop, it got deleted and I got a scary automated email. My manager called me immediately, in the end it was cleared quickly but I did learn to be very carefull about what I try to download. At first I didn't understan…
Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
41–50 of 167 posts
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#42This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected. Even modzero…
This is very speculative. There's no reason to bend over backwards to imagine a way in which "ClownStrike" (your boss gets it!) didn't flag a specific PoC without fixing the underlying issue. If CS insists on such opacity, the best assumption is actually the opposite.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#43Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…
Effectively paying people (and heaping ego gratification on top of that) to be silent about found vulnerabilities.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#44Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#45Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#46The same Crowdstrike that was a key player in Russiagate? Colour me shocked that they do things dumbly. Anyone still using them after that fiasco and its impact on the US should be ashamed. https://thegrayzone.com/2021/10/30/crowdstrike-one-of-russia... https://thegrayzone.com/2020/05/11/bombshell-crowdstrike-adm...
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#47Earlier quoted context omitted.
I recently finished an internship in a large company. I wanted to install netcat to troubleshoot networking issues between windows and docker containers I was running. Right when it was downloaded from scoop, it got deleted and I got a scary automated email. My manager called me immediately, in the end it was cleared quickly but I did learn to be very carefull about what I try to download. At first I didn't understan…
Any programmer that knows how to code (and you seemed to have docker installed, so I'm sure you do too) should be able to create their own reverse shell from a few minutes to a couple of hours. Hence the blocking of netcat in this context (developer workstation) makes no sense.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#48Earlier quoted context omitted.
Yea I noticed that, but what do they specifically not like about the NDA? afaik, HackerOne still makes vulnerability disclosure possible (and automatic if taking too long?)
I guess the specifics are the letters N, D and A and what they stand for. And the fact that there's absolutely nothing in it for them. Would you even consider signing an NDA if I sent you one? I surely hope not.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#49The same Crowdstrike that was a key player in Russiagate? Colour me shocked that they do things dumbly. Anyone still using them after that fiasco and its impact on the US should be ashamed. https://thegrayzone.com/2021/10/30/crowdstrike-one-of-russia... https://thegrayzone.com/2020/05/11/bombshell-crowdstrike-adm...
Your sources are from thegrayzone? You should learn to consider your sources...
To elaborate further: "Leaked emails reveal British journalist Paul Mason plotting with an intel contractor to destroy The Grayzone through “relentless deplatforming” and a “full nuclear legal” attack. The scheme is part of a wider planned assault on the UK left."
https://thegrayzone.com/2022/06/07/paul-masons-covert-intell...
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#50Earlier quoted context omitted.
Exactly. For competent developer, such tool is nothing but wasting time. The reason is simple: if they don't know what they are doing or cannot be trusted, they shouldn't be hired in the first place. But I do understand why those are in place: 1. There are lots of those who have no idea what they are doing in the organization. And/or 2. Some high up who have no idea what they are doing want to show their value. Such…
I think there is a lot of value in these tools for the enterprise. Even if it is just CYA insurance. If somebody steals data but you have a DLP tool you can just blame the vendor. My biggest issue with the tools is they have an insanely deleterious impact on performance and the harsh scrutiny applied has a chilling effect on employees. It turns people into drones that do not dare step outside the norm.