Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

1–10 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#3
I found something similar to this a few years back[1], where the daemon would download and run anything if just “dell” was in the referring host. It seems they have improved the security somewhat by using white lists, but their coding practices seem a bit shoddy. Why have an SDK token at all if it’s public and globally shared?

I wouldn’t be surprised if a lot of the code was shared between the previous incarnation that I found an issue with and this pre-installed version.

1. https://tomforb.es/dell-system-detect-rce-vulnerability/

Re: Remote Code Execution on Most Dell Computers

#4

This is exactly why you should remove any bundled software from vendors and try to start afresh when picking up a new machine.

Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.

Re: Remote Code Execution on Most Dell Computers

#5
I've seen something similar when I open Dell's site. uMatrix shows an attempt to run a localhost script, which looks shady as hell.

I've never let that run. Much easier to just flip the laptop over, enter the six digit service code, and see if there are any new drivers/BIOS updates available for my laptop.

Post reply on HN