Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

81–90 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#81
post #10

Earlier quoted context omitted.

It’s the snake oil industry. They don’t sell security, they sell CISO get out of jail cards in the form of client agents that constantly remind you of their divine presence by being on top of the CPU utilization sorted process list.

There is a LOT of snake oil in the industry, but endpoint protection IS useful. Not every person is a Hacker News reading tech enthusiast. People download and do dumb shit. That is not to say every device needs it and at a max “check every process/file activity” level, though.

Endpoint Protection may be useful but credibility is everything in the industry.

CrowdStrike has done loads to damage their own credibility to anyone paying attention, but because they've chosen to be favorable to certain power players along political lines there are folks out there that treat them like the be-all-end-all of the industry.

As someone in-industry, hearing people parrot press releases from CrowdStrike has me looking at them sideways.

Edit/Addendum: Just to lay bare my opinion of them... CrowdStrike is a clown-ass company run by clown-ass people and with a clown-ass product.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#82
post #38

Earlier quoted context omitted.

I guess the specifics are the letters N, D and A and what they stand for. And the fact that there's absolutely nothing in it for them. Would you even consider signing an NDA if I sent you one? I surely hope not.

That’s not an answer to the parent’s question. HackerOne has a disclosure process despite the NDA, so what part of the process is the issue? Or is it simply “hackerone bad”?

if they have a disclosure process, what purpose is served by the non-disclosure agreement?

what with non-disclosure being literally the opposite of disclosure & everything

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#83
post #41

Earlier quoted context omitted.

I recently finished an internship in a large company. I wanted to install netcat to troubleshoot networking issues between windows and docker containers I was running. Right when it was downloaded from scoop, it got deleted and I got a scary automated email. My manager called me immediately, in the end it was cleared quickly but I did learn to be very carefull about what I try to download. At first I didn't understan…

Any programmer that knows how to code (and you seemed to have docker installed, so I'm sure you do too) should be able to create their own reverse shell from a few minutes to a couple of hours. Hence the blocking of netcat in this context (developer workstation) makes no sense.

I once worked for a large telecom equipment vendor whose IT policies banned the installation of dangerous software like Wireshark.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#84
post #78

Is it weird that I read this as ClowdStrike like a dozen times before realizing it was Crowd?

I've heard them referred to as ClownStrike...

Lmao! Even better. I envision a custard pie as their logo

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#85

Earlier quoted context omitted.

I am not defending CrowdStrike here (my work laptop, that I am typing this on, is molasse-like thanks to them), but their PSIRT team (they have one right?) is just another team in the corp machinery. What PSIRT team and the engine team decide to respond have no effect on what the analyst team decides to do. Do no harm and cover your ass. No one is going to complain a false positive on a custom PoC binary....right? Ev…

you're dancing around the issue though, which is crowdstrike lying in saying there's no vulnerability when they clearly tested it and found there was one

I didn't address anything except for the quoted line from the blog post, which is the binary PoC detection part.

From the blog post- >The PoC that has been sent to CrowdStrike was flagged as malicious. The msiexec call of the deinstaller was also flagged as malicious.

Everything else I have no opinion I wish to share. There are many posters in this thread that would satisfy your desire to engage on the other issues.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#86

Earlier quoted context omitted.

I feel your pain at a deep and spiritual level. I have been in charge of at least half a dozen endpoint protection products over the years (deployment, configuration, management, etc.). Once a user experiences what you just described they are (rightfully) suspicious and sour towards endpoint protection. Questions i would ask in your example: 1) Was the core business tool excluded from the more intrusive protection mo…

Can I ask, since you're as a person who has administered endpoint protection products: how much legitimate stuff do they actually catch?

Not OP, but I've worked for an endpoint protection product company. Part of the onboarding was them loading up a virtual machine with the endpoint installed, then demonstrating several attacks (installing malicious software, running scripts off the internet, etc) and showing the logs of what the endpoint detected, and at what point it shut down the malicious behavior.

The examples shown were behavior based, not hash based. It didn't look up a file in a dictionary, it detected priviledge elevations and such.

No product is perfect, but if you have a need to be protected (especially if you are at risk from adversaries such as in banking, health care, government work, or against corporate espionage) I'm quite confident in saying that you're much better off with it than without.

The same company would also, at random times, attempt to phish us or send us fake emails to get us to click on links, to help educate us on the kinds of threats our customers faced I consider myself fairly savvy, and even I fell for one of them.

I ended up leaving for a variety of reasons, but "losing faith in the product" was not one of them.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#87
post #8

Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…

> Personally, I would've released the PoC back in July when they said the problem was resolved.

Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considered valid, we informed CrowdStrike that we would release the advisory to the public.")

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#88

Earlier quoted context omitted.

That’s not an answer to the parent’s question. HackerOne has a disclosure process despite the NDA, so what part of the process is the issue? Or is it simply “hackerone bad”?

if they have a disclosure process, what purpose is served by the non-disclosure agreement? what with non-disclosure being literally the opposite of disclosure & everything

They pay you money, you disclose exclusively on their terms. That's the deal, and the purpose of the NDA. If you don't like the NDA terms, you don't engage with the bounty program, and you just publish on your own. There's no reasonable way to make a whole big thing out of this.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#89
post #87
post #8

Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…

> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…

I think it's a reasonable progression if the company refuses to accept that the exploit is valid and won't open up equable discussion about it. Trying to force someone to sign an NDA is not really acceptable behaviour when someone is going out of their way to help the company (and their customers).

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#90
post #71
post #19

Somehow I feel those security companies are the source of the security problems.

Well in this case the vulnerability is the ability to uninstall the program when you're not supposed to be able to uninstall it. So yes, if the program didn't exist at all, there would be no way to uninstall it in an unauthorized manor. So the vulnerability wouldn't exist. You wouldn't necessarily be any more secure though. If you have 10 layers of security and 5 have holes in them, you have 5 vulnerabilities, but yo…

What is the vulnerability here? An admin user can do admin stuff. Shocking.
Post reply on HN