Live data from Hacker News

Windows 10 RCE: The exploit is in the link

positive.security

31–40 of 58 posts

Re: Windows 10 RCE: The exploit is in the link

#31

To see how it works on your machine, simply paste ms-officecmd: into your browser and then see what happens. In MS Edge you _might_ see a popup window This site is trying to open LocalBridge. A website wants to open this application. Other forms of URI in Windows 10 taken from https://www.tenforums.com/tutorials/78214-settings-pages-lis... So paste the below into your Browser ms-settings:nightlight In MS Edge you wil…

A lot of people have purposefully mangled windows to stop Windows Update which stopped the automatic upgrade from EdgeHTML edge to Chrome-based, and a lot of people do just use whatever browser comes with Windows.

Re: Windows 10 RCE: The exploit is in the link

#32
post #3

Earlier quoted context omitted.

And apparently Win11 too. Don't all protocol handlers invoke some execution? Like http goes to my browser (only Edge) and that other windows internal one which also goes to Edge (and resets my registered http handler)

> Don't all protocol handlers invoke some execution? Sure, but you don't expect arbitrary code execution. The important distinction is whether the attacker can control what is executed. So if you click on a HTTPS link, you should be safe to assume that it opens a new browser tab, and not open a command prompt like in that example.

cmd://calc.exe

Nobody said URL handlers should offer any security guarantees. There is no clear amount of things that a clicked URL should be able to do. In some circumstances, the full permissions of the logged in user would be appropriate.

The security onus really ought to be on the application which sourced the URL - it knows where it came from.

Re: Windows 10 RCE: The exploit is in the link

#33

People with technical knowledge who prefer to use Windows should have their brains examined.

What do you advise instead, Linux?

https://www.cvedetails.com/product/47/Linux-Linux-Kernel.htm...

Or macOS probably?

https://support.apple.com/en-in/HT201222

Re: Windows 10 RCE: The exploit is in the link

#34
post #28

Earlier quoted context omitted.

If you're not selling the exploits to Microsoft, where else do you sell them?

https://zerodium.com/ , the going rate for a full exploit there (and I assume, one that works quickly & leaves little trace, i.e. a high quality exploit, never dealt with them before) is 80k. Under the old rules that's already 4x as much as MS, but the warm fuzzies made up for that I suppose. Under the new rules, 40x as much, and no warm fuzzies are worth that imo.

[deleted]

Re: Windows 10 RCE: The exploit is in the link

#35
post #28

Earlier quoted context omitted.

If you're not selling the exploits to Microsoft, where else do you sell them?

https://zerodium.com/ , the going rate for a full exploit there (and I assume, one that works quickly & leaves little trace, i.e. a high quality exploit, never dealt with them before) is 80k. Under the old rules that's already 4x as much as MS, but the warm fuzzies made up for that I suppose. Under the new rules, 40x as much, and no warm fuzzies are worth that imo.

Selling to Zerodium is not equivalent to getting a bounty from MSFT. Selling exploit code hurts people. Microsoft will patch the vuln to protect its customers. Selling exploits to Zerodium is very bad. Be a force for good in this world.

Re: Windows 10 RCE: The exploit is in the link

#36
post #21

People with technical knowledge who prefer to use Windows should have their brains examined.

At work, I am stuck with windows. At home, I want to game and I want to use photoshop. Both kinda leave me stuck with windows. I could go windows at work and mac at home. But that would require me learning mac, trying to game on mac, replacing a self-build PC with either an M1 chip in a mac-mini / imac. Or with an actual laptop when I only really need a desktop. All whilst I really like linux. I am stuck using either…

I don't know about photoshop, but gaming scene has gotten really good. My last odd experience was with using Lutris to run a Blizzard launcher ( didn't work for me, but it worked for a buddy with similar setup ). The experience is not a 100%, but is not bad.

edit: I was super lazy and didn't want to troubleshoot that day so I just ran Windows in VM insted.

Re: Windows 10 RCE: The exploit is in the link

#37
post #21

Earlier quoted context omitted.

At work, I am stuck with windows. At home, I want to game and I want to use photoshop. Both kinda leave me stuck with windows. I could go windows at work and mac at home. But that would require me learning mac, trying to game on mac, replacing a self-build PC with either an M1 chip in a mac-mini / imac. Or with an actual laptop when I only really need a desktop. All whilst I really like linux. I am stuck using either…

I don't know about photoshop, but gaming scene has gotten really good. My last odd experience was with using Lutris to run a Blizzard launcher ( didn't work for me, but it worked for a buddy with similar setup ). The experience is not a 100%, but is not bad. edit: I was super lazy and didn't want to troubleshoot that day so I just ran Windows in VM insted.

Gaming on linux would be fine. Its photoshop that blocks linux for me at home. And whilst alternatives to photoshop might exist, I am simply too used to its interface to switch. Besides that lightroom for photo organization is even harder to replace.

If anything, gaming blocks a mac more than it blocks linux for me.

Re: Windows 10 RCE: The exploit is in the link

#38

Earlier quoted context omitted.

> Don't all protocol handlers invoke some execution? Sure, but you don't expect arbitrary code execution. The important distinction is whether the attacker can control what is executed. So if you click on a HTTPS link, you should be safe to assume that it opens a new browser tab, and not open a command prompt like in that example.

cmd://calc.exe Nobody said URL handlers should offer any security guarantees. There is no clear amount of things that a clicked URL should be able to do. In some circumstances, the full permissions of the logged in user would be appropriate. The security onus really ought to be on the application which sourced the URL - it knows where it came from.

The problem is twofold - the sourcing application should tell you which protocol handler is being invoked (this is where IE/Edge fails) - but the protocol handler itself should also not do anything unexpected. When you open a https://.... link, you know it's not going to run a local application. Similarly, ms-officecmd:... should open some sort of Office application, and nothing else. I think that's the minimum of a security guarantee you can expect from any program.

Re: Windows 10 RCE: The exploit is in the link

#39

This is one of those bugs that really should never happen, and one wonders how Microsoft could have missed it and failed to take it seriously. This isn't a particularly sophisticated or novel attack vector, difficult as it was to find; it's the sort of injection attack caused by string interpolation that should have been caught long before anything was shipped.

I've used Windows since 3.1, but I think this new direction is the beginning of the end for Windows. Combining an OS that relies heavily on remote services, with engineers that don't understand security, is a recipe for disaster. At the drop of a hat your OS can break because some remote service breaks[1], or worse, your system gets compromised because the attack surface has grown to size of a small country. I don't…

It's really wild that Windows is essentially becoming a big web app. I guess they just realized that ChromeOS, not MacOS or Linux, is their main competitor. Whoever wants macos/linux will get it, but schools and offices are systematically turning to ChromeOS for simplicity and that just won't do.

Re: Windows 10 RCE: The exploit is in the link

#40
post #23

Earlier quoted context omitted.

Teams was installed without my approval on my private unmanaged laptop running Windows 10 Professional. If you don't have Teams yet, you are either in another rollout, you have done something to prevent it or your PC is managed by someone who have prevented it somehow. I think that covers all. As for why I only use Windows now and then and since I have had a habit of supporting others I keep my personal Windows PCs a…

I'm curious as to the effects of running with a Norwegian language with security. Any chance at enlightenment?

Sorry for the misunderstanding I created. The link between those two are how far I have gone to be able to help end users.

It is a bit tongue in cheek (since I am Norwegian) but only a bit since it is an extra hassle to try to mentally translate what translaters read in English when they created the unsearchable phrases that show up in a localized Windows version.

Post reply on HN