Live data from Hacker News

Deleting System32\curl.exe

daniel.haxx.se

121–130 of 136 posts

Re: Deleting System32\curl.exe

#121
post #2

People who delete system binaries due to whacky CVEs deserve a broken system. I don't even know who else to blame for this.

How do I know which CVE is wacky and which isn't? Do we need another database for actually-real-CVEs?

The last couple of CVEs I was forced to address were in docker images based on alpine or debian, in which the some library version on the system was hit with a High or Critical level CVE. But in reality the ability to exploit the vulnerability required being able to execute a particular program on the running system. The levels of exploit required to even get to being able to exploit this vulnerability in the context I was required to mitigate it meant that in reality, your systems have already been compromised even before this can be exploited.

CVE numbers have exploded while their quality has declined partly due to things like company and project bug bounties, where individuals get bonuses internally for submitting CVEs that get an ID. There's a virtual army of people doing nothing but looking for subtle ways to exploit key tools just to be able to earn a bonus. Some bigger projects, like the linux kernel, dispute some CVEs (e.g. CVE-2023-23005) because they are b.s., but smaller projects don't have the luxury.

See the curl maintainer's take on this: https://daniel.haxx.se/blog/2023/03/06/nvd-makes-up-vulnerab...

Re: Deleting System32\curl.exe

#122
I love the sneer towards the helpful voulonteers on the Microsoft forums.

Hello, , how are you?

Good day! I'm a Windows user like you and I'll be happy to assist you today. I know this has been difficult for you, Rest assured, I'm going to do my best to help you

Please do

If the problem still persists, please try to update using the Microsoft tool.

Kindly let me know if this helps or if you have any further concerns.

Sincerely,

Independent Advisor

Standard Disclaimer: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

Re: Deleting System32\curl.exe

#123
post #2

People who delete system binaries due to whacky CVEs deserve a broken system. I don't even know who else to blame for this.

The UK government.

This is a quote from the Cyber Essentials requirements (https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-...):

""" The Applicant must be active in its management of computers and network devices. It must routinely

...

remove or disable unnecessary software (including applications, system utilities and network services) """

So, based on the quote above, curl.exe must be removed if it is not used, no matter whether it is vulnerable or not (yes I know it is a misreading, but it's frightening that the most literal interpretation is a misreading).

Re: Deleting System32\curl.exe

#124
I'm of the opinion that answers.microsoft.com exists only to mislead and confuse people so they stop reporting issues. I have NEVER seen an actual answer on there, and have never seen an answer that wasn't just copy/pasted by a stranger from an irrelevant Microsoft knowledgebase article.

It gets top SEO billing, and seems to be entirely unmoderated, or at least moderated by people who don't know anything about Windows. It's less informative than Quora. All this does is take all the air out of the room for an actual information source about Windows problems, and it's clearly ignored by Microsoft internal teams.

Creating a "Support Forum" for your brand that never offers actual support should be fraud.

Re: Deleting System32\curl.exe

#125
post #103

Earlier quoted context omitted.

> The people who told them that deleting system binaries would fix their problems? If you are responsible for the security posture and compliance in your organization, reading and acting on security assessments, and yet you do random changes based on random comments on forums, you deserve the blame. I don't think we're not talking about individual end-users here. Those do not scan their systems for CVEs and do not ha…

> If you are responsible for the security posture and compliance in your organization, reading and acting on security assessments, and yet you do random changes based on random comments on forums, you deserve the blame. It's not as easy. Of course experienced sysadmins know it's bullshit. The problem is that cybersecurity insurance policies require "immediate action" on alerts and no one, even assuming a competent CT…

Agreed! And when people like that go to random forums asking for solutions to fix that CVE now, and are told to just override it with latest curl, that is the optimal solution given their (bullshit) constraints and I wouldn't blame the random forums.

Re: Deleting System32\curl.exe

#126
post #103

Earlier quoted context omitted.

> The people who told them that deleting system binaries would fix their problems? If you are responsible for the security posture and compliance in your organization, reading and acting on security assessments, and yet you do random changes based on random comments on forums, you deserve the blame. I don't think we're not talking about individual end-users here. Those do not scan their systems for CVEs and do not ha…

> I don't think we're not talking about individual end-users here. Are you sure about that? From TFA: > Lots of Windows users everywhere runs security scanners on their systems with regular intervals in order to verify that their systems are fine. At some point after December 21, 2022, some of these scanners started to detect installations of curl that included the above mentioned CVE. Nessus apparently started this…

The compliance madness I can understand, but for an individual with no legal or management-mandated constraints...

Either you're security-conscious or you do random changes based on anonymous forum posts, I just don't really see an overlap.

In any case, I don't think it's fair to blame the forums for giving you the solution given your whacky requirements.

Re: Deleting System32\curl.exe

#127
post #91

Earlier quoted context omitted.

> I don't even know who else to blame for this. Microsoft. It's their binary shipped in their system, and their customers are being directed to break their own systems. It's on them to remediate the situation.

Not really. They aren't the ones directing customers to break their systems. They could ban anti-virus software and get slammed for being anti-competitive I suppose. Or they could try to track down all the vendors who are being stupid and ask them to please stop but that probably won't remediate it. They don't have a lot of moves here nor does the curl project.

Their platform (Windows) is getting a bad reputation due to the problem they neglected to fix (shipping a "vulnerable" curl, informing users when the old curl was getting flagged). They could pass the buck but it's just going to be bad for them later when users think Windows itself has security vulns and breaks itself when the users do what they're told to do by vendors. If they don't want the bad rep, they need to be proactive and work with vendors and better inform customers. If I was the CEO I'd do something about it.

Re: Deleting System32\curl.exe

#128

Earlier quoted context omitted.

> I'm happy for an ISP to be allowed to carry out as much censorship as it wants, provided it makes that known. Knowing about it won't help you if every ISP option you have is doing the same thing. Where I live, we have laws that prevent people from interfering with the mail. If I send a letter to someone, once it's accepted the mail carriers can't generally withhold it and make demands before they deliver it or open…

I think there's a reasonable need for an ISP to act as a censor, if that's what its customers require. Hopefully, enough people want a censorship-free experience that every provider becoming a censor is unlikely to happen. If your mail service had a "make sure mail from known pornographers doesn't get delivered to my house" option, and you had kids at home, you might well opt for it.

If someone wants to block certain sites there are client-based solutions that people can set up themselves and proxies they can use if they really want to depend on someone else to decide what they should be allowed to see. There's no need for it at the ISP level. At the very least it should be opt in, but something you have to ask to have removed.

Re: Deleting System32\curl.exe

#129
post #66

Earlier quoted context omitted.

yes there is, you just need to right click the file and remove the privileges for system. I just did this for the "AsusComService" which would take 30% of my i9 13k simply because i have dns blocking running for it.

Why can't you uninstall it?

because it comes from the motherboard and will reinstall every time i reboot. I have deleted it before, renamed it and more but nothing helped unless i revoked its privileges.

Or differently said, modern asus motherboards actively come with a rootkit.

Re: Deleting System32\curl.exe

#130

Earlier quoted context omitted.

They overblock, probably intentionally, so it's easy to find a "legit" reason to unblock. It was something really banal for me - I think they'd blocked a furniture site or something.

Accessing adult material is a legit reason to unblock.

Buying furniture is a very adult proposition.
Post reply on HN