Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
1–10 of 10 posts
Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#2[0]: https://binarly.io/posts/The_Far_Reaching_Consequences_of_Lo... [1]: https://news.ycombinator.com/item?id=38515571
Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#3The binarly post[0] (submitted by @skilled 2 days ago /w no comments and little upvote love) is a cleaner source[1] and just as easy to read. This seems to be a bit of a rewrite, bit of a copy/paste (images straight from binarly). The vulnerability was published a week ago, this article implies it was disclosed today. [0]: https://binarly.io/posts/The_Far_Reaching_Consequences_of_Lo... [1]: https://news.ycombinator.c…
Submitters: "Please submit the original source. If a post reports on something found on another site, submit the latter." - https://news.ycombinator.com/newsguidelines.html
Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#4I don't get the point of this. Any vulnerability that requires local access can be exploited if you first get remote code execution through another vulnerability. Also, exploiting the browser or the media player doesn't give you admin privileges, you need another privilege escalation exploit for that.
Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#5> Remote attacks work by first exploiting an unpatched vulnerability in a browser, media player, or other app and using the administrative control gained to replace the legitimate logo image processed early in the boot process with an identical-looking one that exploits a parser flaw. I don't get the point of this. Any vulnerability that requires local access can be exploited if you first get remote code execution th…
Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#6> Remote attacks work by first exploiting an unpatched vulnerability in a browser, media player, or other app and using the administrative control gained to replace the legitimate logo image processed early in the boot process with an identical-looking one that exploits a parser flaw. I don't get the point of this. Any vulnerability that requires local access can be exploited if you first get remote code execution th…
But this makes the access persistent, and allows the removal of all evidence of the initial penetration, survives OS patching, vulnerability scanning, etc.
Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#7The binarly post[0] (submitted by @skilled 2 days ago /w no comments and little upvote love) is a cleaner source[1] and just as easy to read. This seems to be a bit of a rewrite, bit of a copy/paste (images straight from binarly). The vulnerability was published a week ago, this article implies it was disclosed today. [0]: https://binarly.io/posts/The_Far_Reaching_Consequences_of_Lo... [1]: https://news.ycombinator.c…
Ok, we'll re-up that submission and move comments thither. Thanks! Submitters: " Please submit the original source. If a post reports on something found on another site, submit the latter. " - https://news.ycombinator.com/newsguidelines.html
Maybe "over there" or "to that one"? Your way is not wrong, but many will miss the point.
Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#8Earlier quoted context omitted.
Ok, we'll re-up that submission and move comments thither. Thanks! Submitters: " Please submit the original source. If a post reports on something found on another site, submit the latter. " - https://news.ycombinator.com/newsguidelines.html
I read this comment because I saw some other moderation duty comments and looked at your history. I don't think you should use the word "thither" for transactional comments. It is correct here, I think, but it's somewhat archaic English. Maybe "over there" or "to that one"? Your way is not wrong, but many will miss the point.
thither:
To or toward that place; in that direction; there
To that place; -- opposed to hither.Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#9Earlier quoted context omitted.
Ok, we'll re-up that submission and move comments thither. Thanks! Submitters: " Please submit the original source. If a post reports on something found on another site, submit the latter. " - https://news.ycombinator.com/newsguidelines.html
I read this comment because I saw some other moderation duty comments and looked at your history. I don't think you should use the word "thither" for transactional comments. It is correct here, I think, but it's somewhat archaic English. Maybe "over there" or "to that one"? Your way is not wrong, but many will miss the point.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Re: Just about every Windows/Linux device vulnerable to new LogoFAIL firmware attack
#10> Remote attacks work by first exploiting an unpatched vulnerability in a browser, media player, or other app and using the administrative control gained to replace the legitimate logo image processed early in the boot process with an identical-looking one that exploits a parser flaw. I don't get the point of this. Any vulnerability that requires local access can be exploited if you first get remote code execution th…
- the persistence that’s nearly perfect
- an av cannot detect it ever
- it bypasses all forms of secure boot by getting code exec at the earliest of stages in the boot chain of trust
- the disassemblies show that the bios vendors did not even remotely try to make the parser secure. it is a joke. and if an image parser is that bad, I can’t even imagine the quality of usb or network stacks