Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

181–190 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#181

Earlier quoted context omitted.

> You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day. Which is again, a problem created by the companies themselves. The way this should work is that the researcher discloses to the company, and the company reaches out to and informs their customers immediately . Then they fix it. But instead companies refuse to tell t…

You are shopping at a store along with some other customers. When entering the store, you notice that an employee of the store has left a large knife outside, under a trashcan. A shady character is wandering around the store, looking for someone to steal from, but hasn't figured out the right angle of attack yet. At some point, you (ever the responsible citizen) stand up on a table in the store and yell "Hey! Just wa…

Instead we get this version:

You are shopping at a store along with some other customers. When entering the store, you notice a gun laying on the ground by the door. You keep coming back every week, pointing it out, asking if that's intended or not.

They continue to ignore you, or explain how it's intended; a good thing even!

Eventually someone with malicious intent also sees the gun, picks it up, shoots a fellow customer, puts it back where it was, and walks off.

By the next day, miraculously, management will have found the time and resources to remove the gun.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#182

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

Just post it next day, when found. That will be the proper incentive and losing face also contributes to better security next time.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#183

Earlier quoted context omitted.

It is virtually the same size[1] as the era equivalent S23. I don't think a headphone jack which you can get via a super cheap USB-C adaptor, makes the justification for a 1000 Euro paperweight. [1] https://www.gsmarena.com/size-compare-3d.php3?idPhone1=12380...

The problem I found about the adaptors is that you can't charge your phone and listen to music at the same time. I have an older car with an old stereo where the only external input is via jack. Worked perfectly fine with my old phone. When I got a new Samsung, I went through the hassle of trying several "combined usb-c charger and audio jack adaptor" only to eventually find out they can only work in on mode or the o…

Just a FYI for anyone that has the same problem. The reason the adapters don't work is that they're operating in Audio Accessory Mode. The signal comes from the phone's DAC, and is passed through the data lines of the USB connector to the 3.5 mm jack. Problem is, the charging mode also uses those lines to communicate. Thus it can't do both.

The solution is to use a USB hub with an integrated DAC. I use an older version of this: https://satechi.net/products/mobile-pro-hub-sd

Re: One-Click RCE in Asus's Preinstalled Driver Software

#184
post #139

Earlier quoted context omitted.

Cisco pays bounties, tho? https://sec.cloudapps.cisco.com/security/center/resources/ci...

When I reported something, and this was probably around 8 years ago, they only had bounties for their equipment, not for "online properties". I reported a vulnerability in some HR software they owned, but alas I can't even find where it used to live on the internet now.

The 2 that are live there definitely cover software (one doesn't deal in hardware at all).

Re: One-Click RCE in Asus's Preinstalled Driver Software

#185

I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup[1] and likely does not have the capital to pay a bounty. [1]: https://companiesmarketcap.com/asus/marketcap/

alternatively, sarcasm.com ;)

Re: One-Click RCE in Asus's Preinstalled Driver Software

#186
post #139

Earlier quoted context omitted.

When I reported something, and this was probably around 8 years ago, they only had bounties for their equipment, not for "online properties". I reported a vulnerability in some HR software they owned, but alas I can't even find where it used to live on the internet now.

The 2 that are live there definitely cover software (one doesn't deal in hardware at all).

[deleted]

Re: One-Click RCE in Asus's Preinstalled Driver Software

#187
It is not just a mainboard issue. I had an asus mechanical keyboard. After I started using it, Windows kept installing software and background services in system that is a listening port. I kept deleted it manually and no matter I did, windows kept installing it without my consent. It was really annoying.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#188
post #54

Earlier quoted context omitted.

For me it's them lying about providing a way to unlock the bootloader of my soon to be 1000€ paperweight(2 android updates only) called an Asus zenfone 10.

Out of curiosity, what got you to spend 1000 Euros on a Zenphone 10 phone when Samsung S23 was net superior and cheaper and provides like 5 years of updates? It's not like previous phones from Asus had a better track record. I kept waring people to stay away form the Zenphone yet the online community kept overhyping it for some reason as the second coming of Christ or something.

What cempler said. I tried the dongle approach when the jack in my pixel 4a was failing but found I didn't like it. Having the cable go out the bottom in the center is a terrible place for me, as I rest my phone on my outstretched pinky. The zenfone ticked all boxes on paper and in reviews. Great chipset, solid build, a form factor fitting my tiny hands(though in retrospect it's so heavy that my pinky hurts after a couple hours of reading). And a headphone jack which I use to plug my phone in my stereo and my Sennheiser headphones. Really the jack is the primary reason I got this phone. Coupled by the fact that until now all zenfones had a hassle boot loader unlock and a decent rom community it really was the best choice on paper. God damn it Asus, I wasn't aware they're that dodgy :/

Re: One-Click RCE in Asus's Preinstalled Driver Software

#189
post #54

Earlier quoted context omitted.

For me it's them lying about providing a way to unlock the bootloader of my soon to be 1000€ paperweight(2 android updates only) called an Asus zenfone 10.

If they actually lied about it, that kind of money could be worth it to take them to (whatever your local equivalent of) small claims court over.

I'm in Germany which makes it a bit harder. Someone in the UK went through the trouble and all they got was an offer for a refund or an insanely outpriced option to downgrade the os iirc.

About the lie, they've repeated multiple times this would be an option a year ago...

See https://www.reddit.com/r/zenfone/comments/1ccy11g/asus_is_wo...

Re: One-Click RCE in Asus's Preinstalled Driver Software

#190

Earlier quoted context omitted.

Parent comment is making a point that it might have been possible for an attacker to avoid discovery via certificate transparency logs, because anyone 'with a wildcard' could pull off the attack, which is not correct. I'm pointing out that a wildcard at the apex of your domain (which is what basically everyone means when saying 'a wildcard'), would not work for this attack. Instead if you were to perform the attack u…

Can you still publicly apply for a “*.*.mydomain.com” certificate? IIRC a wildcard cert starting with “*.*.” allows you to chain 2+ names with that cert, I think? (E.g.: “*.*.example.com” cert would match “hello.world.and.hi.com.example.com”)

With public CAs, you can only apply for a wildcard at a single label. You can't have nested wildcards.

RFC6125 limits wildcards to a left-most label (6.4.3. paragraph 2): https://www.rfc-editor.org/rfc/rfc6125.html#section-6.4.3

I don't know of any CA that allows for wildcard characters within the label, other than when the whole label is a wildcard, but it is possible under that RFC.

The CA/Browser Forum's baseline requirements dictates how any publicly trusted CA should operate, and it defines a wildcard certificate in section 1.6.1 (page 26) here https://cabforum.org/working-groups/server/baseline-requirem...

> Wildcard Certificate: A Certificate containing at least one Wildcard Domain Name in the Subject Alternative Names in the Certificate.

> Wildcard Domain Name: A string starting with “*.” (U+002A ASTERISK, U+002E FULL STOP) immediately followed by a Fully‐Qualified Domain Name.

Now of course with your own internal CA, you have complete free reign to issue certificates - as long as they comply with the technical requirements of your software (i.e. webserver and client).

Also note that a cert issued as '..example.com.' would only match 'hi.com.example.com.', not an additional three labels.

Post reply on HN