Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

161–170 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#161
post #14

Sounds like the attacker has to be on the local network (or presumably VPN) to use the exploit? If so that's a nontrivial hurdle in many cases.

It looks to me like you could register any domain starting with "localhost" (eg. localhostevil.com) and it would work.

(apart from the download whitelist)

Re: Remote Code Execution on Most Dell Computers

#162
This doesn't sound quite as scary as the title. You still have to do one of these things that will all be nearly impossible in general. It's not like you can just set up a website and wait for victims to visit it.

- XSS on one of Dell's sites.

- Find a Subdomain Takeover vulnerability on a Dell site.

- Make the request from a local program.

- DNS Hijack the victim.

Re: Remote Code Execution on Most Dell Computers

#163

Earlier quoted context omitted.

Microsoft pulled a stunt before when they made Windows load an executable from inside UEFI during every boot.

I chuckled, but come now, that's not the same thing. Apple keeps track of what you type for autocorrect and word prediction. "Apple installs a keylogger on every iPhone."

Sure it isn’t the same thing. Microsoft created a system supporting malware that survives OS reinstallation. Lenovo was just using that system as intended.

Re: Remote Code Execution on Most Dell Computers

#164

Earlier quoted context omitted.

> a TV with an instant-on button Please . I use a 4k TV as my computer monitor. It's works fairly well for that because I researched it and found a good fit, but I use a remote to start it every time, and it takes 15-20 seconds before it's ready to receive input. That's a long time to be sitting in front of your computer waiting, especially when it happens 3-10 times a day.

I avoid those problems by never turning my TV or monitor off. It does mean they light up the room at night so it wouldn't work if you had it in a bedroom.

Seems like a huge waste of electricity.

Re: Remote Code Execution on Most Dell Computers

#165

Earlier quoted context omitted.

You forgot the last part: OEM: Profit

it's almost a psychology experiment where brands con you just enough and let you absorb the pain long enough that they forgot and start browsing for a new machine, repeating the cycle

But then the engineer in you says "I'll objectively choose the best hardware", and you end up with another lenovo. I really think it is the Windows Wizard Warriors that complain about bloatware, I always wipe it and start with a fresh install.

Re: Remote Code Execution on Most Dell Computers

#166

Earlier quoted context omitted.

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Yep. FM Radio was a common feature back in the day.

My S7 can still do it. The reason newer phones can't is because they lack an aux jack: the wire is used as an antenna. Another great reason to keep the headphone jack.

Re: Remote Code Execution on Most Dell Computers

#167
post #70

What is the bounty on a report like this, and does Dell operate an official bug bounty program? How much do you think a report like this should be worth? "Dell bug bounty program" and the like don't turn up obvious results to me.

Unfortunately Dell doesn't pay bounties no matter how serious the bug is.

Dell could send you a laptop at least.

Re: Remote Code Execution on Most Dell Computers

#168
post #92

Earlier quoted context omitted.

This is an exploit in the shitty software that OEMs put on their Windows images. Stuff like this is practically universal (minus Apple), and the fact that Dell hasn't (AFAIK) actively bundled very evil malware with their computers makes them far from the worst offender.

Apple bundles plenty of software on their computers which I don't want, have never used, which increase the potential attack surface and which I can't uninstall. For example Apple Maps, Apple News, Home, and Books. In fact you can't uninstall any of the apps shipped with macOS. Not even the chess program.

Exactly! With Windows you do have choices. I bought a desktop PC from ThinkMate configured exactly as I wanted it with a plain vanilla Windows 10.

Re: Remote Code Execution on Most Dell Computers

#169
post #89
post #40

Earlier quoted context omitted.

Yeah, 99% of dell computers

Sadly. It disappoints me so much that linux hasn't been able to crack Windows dominance on desktop/laptop. I was sure that as more people became computer "literate", they'd shift to linux or bsd in droves. Boy was I wrong.

I'm very computer literate. That's why I run Windows 10, and Linux / BSD in a VM. I want to get things done.

Re: Remote Code Execution on Most Dell Computers

#170

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

Second product for this mythical OEM should just be a TV with an instant-on button and as many hdmi ports that will fit given a small-as-possible bezel. One model per year per common size->one price. Big sale on thanksgiving and then the slightly better ones come out.

I've heard that these exist,but are marked as “lcd pannels”, meant for displaying information in public places.
Post reply on HN