Earlier quoted context omitted.
> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sur…
I mean... as a user on the machine, if I have admin rights there's very, very little they can meaningfully do to stop me from removing their software. Hooking a token into their uninstaller is hardly sufficient... I have SO much surface area to attack that I don't genuinely think you can call this anything other than trivial. For an admin user, I'd take this token prompt more as a "Hey - you're about to violate compa…
Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
111–120 of 167 posts
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#112Earlier quoted context omitted.
> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sur…
"Responsible" disclosure is an Orwellian term. The real term is "coordinated disclosure", and, as you can see from the timeline, there's coordination here.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#113Earlier quoted context omitted.
The thing is, "releasing our findings to the public" puts the vendor's customers at risk, it's not just some imagined Just Punishment For The Guilty, innocents get hurt. Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems? (In this case, the vulnerability seems minor, so it's sort of academic. But I'm not un…
You can't let vendors hide security problems by just not doing anything about them. People deserve to know if the product they rely on has vulnerabilities, because just because you aren't exploiting it doesn't mean nobody else will find it. Modzero was even following a more conservative playbook here: not setting a deadline from the start, but only talking about release once the vendor indicated there was no issue (a…
Telling people that the product they rely on has vulnerabilities is clearly not the same thing as "release the vulnerability report" though, is it? I still remain amazed at the absolutism in the arguments here. There is a spectrum of responses that can be explored before dropping bombs. But everyone wants to see stuff burn?
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#114Earlier quoted context omitted.
> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sur…
possibly the origin of named and marketed vulnerabilities. Heartbleed is older (2014).
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#115Earlier quoted context omitted.
> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat I don't think it is upsetting at all. "We found a vulnerability" "There's no vulnerability" "No, you misunderstand, here's how it works and how to exploit" "Naah, no vulnerability" "Ok, if there's no vulnerability as you claim, you don't mind u…
The thing is, "releasing our findings to the public" puts the vendor's customers at risk, it's not just some imagined Just Punishment For The Guilty, innocents get hurt. Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems? (In this case, the vulnerability seems minor, so it's sort of academic. But I'm not un…
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#116Earlier quoted context omitted.
> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat I don't think it is upsetting at all. "We found a vulnerability" "There's no vulnerability" "No, you misunderstand, here's how it works and how to exploit" "Naah, no vulnerability" "Ok, if there's no vulnerability as you claim, you don't mind u…
The thing is, "releasing our findings to the public" puts the vendor's customers at risk, it's not just some imagined Just Punishment For The Guilty, innocents get hurt. Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems? (In this case, the vulnerability seems minor, so it's sort of academic. But I'm not un…
If vendor denies there is a problem despite repeated submissions of evidence then customers are already at risk indefinitely.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#117Earlier quoted context omitted.
You can't let vendors hide security problems by just not doing anything about them. People deserve to know if the product they rely on has vulnerabilities, because just because you aren't exploiting it doesn't mean nobody else will find it. Modzero was even following a more conservative playbook here: not setting a deadline from the start, but only talking about release once the vendor indicated there was no issue (a…
> You can't let vendors hide security problems by just not doing anything about them. Telling people that the product they rely on has vulnerabilities is clearly not the same thing as "release the vulnerability report" though, is it? I still remain amazed at the absolutism in the arguments here. There is a spectrum of responses that can be explored before dropping bombs. But everyone wants to see stuff burn?
Without the necessary details telling the public about a vulnerability is like shouting at a wall. Publishing the details forces vendors to release fixes when they deny the existence of the vulnerability.
This isn't some hidden password or evil DoS attack, this is an attack only processes with admin access can leverage on infected machines. This command is either executed by a computer user (which should flag a warning in the management software) or it's executed by a virus with admin permissions that went undetected by the antivirus solution on the machine. The stakes are low enough and the vendor is irresponsible enough that I don't see a problem with publishing a PoC when vendors lie about these kinds of bugs.
Of course remote exploitation and auth bypass PoCs shouldn't be released into the wild without trying to get a patch out first, but even still vendors like D-Link just don't seem to care if you don't at least threaten them with releasing the details to the public.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#118Earlier quoted context omitted.
You can't let vendors hide security problems by just not doing anything about them. People deserve to know if the product they rely on has vulnerabilities, because just because you aren't exploiting it doesn't mean nobody else will find it. Modzero was even following a more conservative playbook here: not setting a deadline from the start, but only talking about release once the vendor indicated there was no issue (a…
> You can't let vendors hide security problems by just not doing anything about them. Telling people that the product they rely on has vulnerabilities is clearly not the same thing as "release the vulnerability report" though, is it? I still remain amazed at the absolutism in the arguments here. There is a spectrum of responses that can be explored before dropping bombs. But everyone wants to see stuff burn?
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#119Earlier quoted context omitted.
You can't let vendors hide security problems by just not doing anything about them. People deserve to know if the product they rely on has vulnerabilities, because just because you aren't exploiting it doesn't mean nobody else will find it. Modzero was even following a more conservative playbook here: not setting a deadline from the start, but only talking about release once the vendor indicated there was no issue (a…
> You can't let vendors hide security problems by just not doing anything about them. Telling people that the product they rely on has vulnerabilities is clearly not the same thing as "release the vulnerability report" though, is it? I still remain amazed at the absolutism in the arguments here. There is a spectrum of responses that can be explored before dropping bombs. But everyone wants to see stuff burn?
If one publicly discloses some mitigation it's usually enough to give malicious actors enough to go on anyway.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#120Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…
> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…