Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
61–70 of 167 posts
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#62Earlier quoted context omitted.
10% of Falcon is blocking dumb shit people do. 90% is blocking things people are supposed to be doing, and have been doing successfully so far. Nothing starts your week better than "After the latest definitions update, Falcon heuristic started quarantining your core business tools as suspicious".
They fixed it with an update this month, but CrowdStrike was hooking /every/ single call to NtCreateUserProcess on my work machine last month, and you /know/ how electron-based apps work. VSCode took so long to launch its sub processes it would pop up a crash reporter. "Hello World" compiled from C++ would take a minute to launch sometimes. WSL straight up could not be started because the TTY timed out waiting for it…
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#63Refusing to interact with an existing security process (HackerOne) and demanding a personal contact instead for a minor issue is certainly an interesting take.
"Can you notify my lawyer by FAX, please? And can you get the document notarized first? Kthxbai".
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#64The same Crowdstrike that was a key player in Russiagate? Colour me shocked that they do things dumbly. Anyone still using them after that fiasco and its impact on the US should be ashamed. https://thegrayzone.com/2021/10/30/crowdstrike-one-of-russia... https://thegrayzone.com/2020/05/11/bombshell-crowdstrike-adm...
Your sources are from thegrayzone? You should learn to consider your sources...
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#65Earlier quoted context omitted.
They fixed it with an update this month, but CrowdStrike was hooking /every/ single call to NtCreateUserProcess on my work machine last month, and you /know/ how electron-based apps work. VSCode took so long to launch its sub processes it would pop up a crash reporter. "Hello World" compiled from C++ would take a minute to launch sometimes. WSL straight up could not be started because the TTY timed out waiting for it…
java.exe was probably excluded.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#66Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…
Sounds more like these companies are using bounty programs to get researchers to sign NDAs so that they can control public perception of their products. Effectively paying people (and heaping ego gratification on top of that) to be silent about found vulnerabilities.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#67This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected. Even modzero…
> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sur…
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#68Earlier quoted context omitted.
java.exe was probably excluded.
I know what I'm calling my next exploit ;)
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#69Refusing to interact with an existing security process (HackerOne) and demanding a personal contact instead for a minor issue is certainly an interesting take.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#70This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected. Even modzero…
> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sur…
Hooking a token into their uninstaller is hardly sufficient... I have SO much surface area to attack that I don't genuinely think you can call this anything other than trivial.
For an admin user, I'd take this token prompt more as a "Hey - you're about to violate company policy" more than any literal technical restriction.
I can steal the network, change the registry, simply delete their binaries, update shared dlls, or any number of other easy hacks to get them offline.
This is trivial.