Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

211–220 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#211

Earlier quoted context omitted.

There really needs to be an open source project for a PC motherboard.

Just a few days ago people were talking about this on the kicad discord. A chinese team made an open hardware x86_64 motherboard and published it not too long ago. Then they were essentially wiped off the face of the planet. That was the day I learned you literally cannot develop a computer motherboard without Intel's permission. Turns out Intel is no different than the likes of Nintendo.

I doubt that.

Chinese "tinker" has been making countless "x99" motherboard that reuse consumer chipset like h81 or b85.

I don't think Intel approve that

Re: One-Click RCE in Asus's Preinstalled Driver Software

#212
post #30

Earlier quoted context omitted.

no bug bounty, onto black market of exploit it goes. that or full public disclosure.

I wonder how worried they would get if more people actually started selling exploits on the black market, instead of reporting and not getting a bug bounty. If you don’t offer a bug bounty program in the first place, my gut feeling is that they probably wouldn’t care in that case either. Either way, this is a super good reason to not do business with such a company.

I wonder if centralized "sell program vulnerabilities here" government shops can be set up

While intelligence agencies are an obvious benefitiary, this would also give leverage of government over capital

Re: One-Click RCE in Asus's Preinstalled Driver Software

#213
post #4

> I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. :(

> Asus is just a small startup

I'm not sure where they got that from, Asus have been making motherboards and other pc parts since at least the 90s...

Re: One-Click RCE in Asus's Preinstalled Driver Software

#214
post #135

Earlier quoted context omitted.

> You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot. I don't think you can fathom the amount of people that have phones with roughly 3 years of no android updates as their primary device with which they use all the digital services they use, Banking, Texting, Doomscrolling, Porn, ... Users, especially the most likely to be exploited ar…

The fact about people running outdated OS versions is totally true, but it also indicates that the risk of being vitally harmed by those vulnerabilities is quite low in reality, if you’re not an individually targeted person. And that’s why not a lot of people care about them.

In this day and age, you're just as likely to be targeted by a large-scale ransomware operation that just happens to find your vulnerable device by network scanning, for example.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#215
post #4

> I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. :(

> Asus is just a small startup I'm not sure where they got that from, Asus have been making motherboards and other pc parts since at least the 90s...

The words "small startup" in the TFA are a link to https://companiesmarketcap.com/asus/marketcap/

Re: One-Click RCE in Asus's Preinstalled Driver Software

#216
post #19

>so I could see if anyone else had a domain with driverhub.asus.com.* registered. From looking at other websites certificate transparency logs, I could see that domains and subdomains would appear in the logs usually within a month. After a month of waiting I am happy to say that my test domain is the only website that fits the regex, meaning it is unlikely that this was being actively exploited prior to my reporting…

Furthermore:

- Would a self-signed cert work? Those aren’t in transparency logs.

- Does it have to be HTTPS?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#217
post #181

Earlier quoted context omitted.

You are shopping at a store along with some other customers. When entering the store, you notice that an employee of the store has left a large knife outside, under a trashcan. A shady character is wandering around the store, looking for someone to steal from, but hasn't figured out the right angle of attack yet. At some point, you (ever the responsible citizen) stand up on a table in the store and yell "Hey! Just wa…

Instead we get this version: You are shopping at a store along with some other customers. When entering the store, you notice a gun laying on the ground by the door. You keep coming back every week, pointing it out, asking if that's intended or not. They continue to ignore you, or explain how it's intended; a good thing even! Eventually someone with malicious intent also sees the gun, picks it up, shoots a fellow cus…

Agreed, that is what often happens. But after seeing this pattern before, that does not mean the solution going forward is to yell "hey everyone there is a gun" and hope management gets to it before the person with malicious intent.

Sure, maybe management will ignore you if you tell them about the gun privately. At that point, feel free to disclose publicly. But they are guaranteed to not do anything if they don't know about it and you don't tell them (before telling everyone else including bad actors).

Re: One-Click RCE in Asus's Preinstalled Driver Software

#218
post #205

I have a similar model motherboard from ASUS in my desktop I had custom built a few years ago, and I've mostly just been annoyed that I have to have Windows installed to be able to even update the BIOS at all given that the previous one I had (which I think was also from them?) would just let me do it over ethernet if I booted directly into the BIOS setup menu. Now I have much larger concerns in addition to the risk…

Any mobo will let you download the firmware file to a FAT32-formatted USB drive etc, and then use that to update the UEFI within the UEFI UI.

Yes some mobos have the feature in their UEFI to connect to the internet and download the update, but it's best to not rely on that since you have no idea how securely that is implemented. Considering how the submitted article is about a shitty implementation in a regular Windows program, you can be sure the implementation in UEFI is even shittier (may not check certs, may not even use HTTPS, etc). Asrock used to have an "Internet Flash" feature in their UEFI and then suddenly removed it, probably because it was too insecure to fix.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#219
post #65

Earlier quoted context omitted.

I hear what you're saying and I agree, but it's perhaps too black and white. Let's take one of the most disastrous bugs in recent history: meltdown. Speculative execution attacks inside the CPU. This required (in Paul Turners words): putting a warehouse of trampolines around an overly energetic 7-year old. This, understandably took a lot of time, both for microcode and OS vendors.. it took even longer to fix it in si…

Spectre/Meltdown is the perfect example of a vendor, Intel and AMD, deflecting blame onto the OS and software producers, successfully avoiding a recall, avoiding refunds for decreased performance and avoiding most of the blame. What actually should have happened there is a full recall of all affected hardware. Microcode fixes and payments for lost performance in the mean time, until the new hardware arrives. Meltdown…

There is no world in which a recall (and/or a refund) is ever possible.

Until it is demonstrated that such flaws are a life and death fault, no regulation is possible for such flaws (unlike cars - which do have such recalls for faults that have life and death implications).

Re: One-Click RCE in Asus's Preinstalled Driver Software

#220

Earlier quoted context omitted.

So are there any "basically respectable" motherboard manufacturers? Or is there a similar story about each of the big players? Asking for a friend who is thinking about building a new PC soon.

Asrock (sub-brand of Asus but seemingly independent in the product and dev side) has been fine for me over the ~10 years I've bought their mobos. There was the thing a few months ago with X870 mobos that were apparently frying CPUs, but I think that was not sufficiently proven to be their fault? That said, in their X670 / B650 they have the same setting as what this article is about, and it could be equally as broken…

Asus and AsRock are separate since 2010.
Post reply on HN