Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

11–20 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#13

Earlier quoted context omitted.

Why is this not an RCE?

[flagged]

I suggest you re-read the article carefully. The author shows that a website can be created that will make the asus software download and execute an attacker controlled app from a server the attacker controls.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#17
Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs are involved and a solution must be find in hours not month, they will become a lot more proactive. Of course it's the end users that would suffer most from this. But then again, they buy ASUS so they suffer already...

Re: One-Click RCE in Asus's Preinstalled Driver Software

#18
Obligatory "Scumbag Asus" video link:

Invidious https://inv.nadeko.net/watch?v=cbGfc-JBxlY

YouTube https://youtube.com/watch?v=cbGfc-JBxlY

"ASUS emailed us last week (...) and asked if they could fly out to our office this week to meet with us about the issues and speak "openly." We told them we'd be down for it but that we'd have to record the conversation. They did say they wanted to speak openly, after all. They haven't replied to us for 5 days. So... ASUS had a chance to correct this. We were holding the video to afford that opportunity. But as soon as we said "sure, but we're filming it because we want a record of what's promised," we get silence."

Edit: formatting

Re: One-Click RCE in Asus's Preinstalled Driver Software

#19
>so I could see if anyone else had a domain with driverhub.asus.com.* registered. From looking at other websites certificate transparency logs, I could see that domains and subdomains would appear in the logs usually within a month. After a month of waiting I am happy to say that my test domain is the only website that fits the regex, meaning it is unlikely that this was being actively exploited prior to my reporting of it.

This only remains true in so far as no-one directly registered for a driverhub subdomain. Anyone with a wildcard could have exploited this, silent to certificate transparency?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#20
post #14

Earlier quoted context omitted.

[flagged]

Did you not see the PoC video?

Seems I was wrong. I am utterly surprised at the lack of security in modern browsers. Yes, that backend is misconfigured, but why this request is even allowed to take place in the first place is utterly mindblowing to me.
Post reply on HN