Live data from Hacker News

CPU-Z and HWMonitor compromised

theregister.com

51–60 of 118 posts

Re: CPU-Z and HWMonitor compromised

#51

> after the download my Windows Defender instantly detecting a virus. > (because i am often working with programms which triggering the defender i just ignored that) This again shows the unfortunate corrosive effect of false-positives. Probably impossible to solve while aggressively detecting viruses though.

But sorta possible to solve with source-based distribution and totally possible to solve with pure reproducible builds.

It's entirely possible to ship malware in source form... Just look at the numerous supply chain attacks. Nix is a cute project but entirely irrelevant here.

Re: CPU-Z and HWMonitor compromised

#52
post #19

To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.

I’m not one to chase the new and shiny, but how do you know a nominally months-old software package isn’t a newly compromised version at the time you download it?

Re: CPU-Z and HWMonitor compromised

#53
post #52
post #19

To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.

I’m not one to chase the new and shiny, but how do you know a nominally months-old software package isn’t a newly compromised version at the time you download it?

[dead]

Re: CPU-Z and HWMonitor compromised

#54
post #19

To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.

Thanks the web that produced css programmers who have been taught latest is greatest and shiny gets money.

"new, shiny" has never been a problem with CSS. Either browsers support some CSS attribute or they don't.

You're probably thinking about Javascript programmers.

Re: CPU-Z and HWMonitor compromised

#55

Earlier quoted context omitted.

After my Wordpress site got hacked way back through an exploit in one of the WP files, I set up a cron job that compared the hash of the static files with expected hash, and would fire off an email if they differed. The script lived above the web root, so they'd have to escape that to tamper with it, and was generated by another script. Saved me a couple of times since, well worth the 15 minutes I spent on setting it…

Back in the 1990s, there was a tool called ‘tripwire’ that checked key files against expected checksums. As I recall, they recommended putting the expected values on a floppy disk and setting the ‘write protect’ tab, so the checksums couldn’t be changed.

tripwire was the orginal file integrity anti-virus/anti-tampering software from the security group (which turned into CERIAS) at Purdue led by Dr. Eugene "Spaff" Spafford.

https://docs.lib.purdue.edu/cstech/1084/

Re: CPU-Z and HWMonitor compromised

#56

some comments purportedly (i did not verify) from one of the maintainers: > Dear All, I'm Sam and in I'm working with Franck on CPU-Z (I'm doing the validator). Franck is unfortunately OOO for a couple weeks. I'm just out of bed after worked on Memtest86+ for most the night, so I'm doing my best to check everything. As very first checks, the file on our server looks fine ( https://www.virustotal.com/gui/file/6c8faba4…

For what it's worth - I used to write CPU reviews a while back - I can vouch for both Sam and Franck. Franck is the guy behind CPUID and Sam is a close friend of his, who was known for working at Canard PC on top of his work on Memtest : https://x86.fr/about-me/

Re: CPU-Z and HWMonitor compromised

#57

Earlier quoted context omitted.

It's the third time that I've read something about availability notifications on discord and other chats getting abused for timed attacks in the last few weeks.

After my Wordpress site got hacked way back through an exploit in one of the WP files, I set up a cron job that compared the hash of the static files with expected hash, and would fire off an email if they differed. The script lived above the web root, so they'd have to escape that to tamper with it, and was generated by another script. Saved me a couple of times since, well worth the 15 minutes I spent on setting it…

Related: OpenBSD does this daily as part of running security(8) and its coverage can be expanded to include pretty much anything.

https://man.openbsd.org/security

Re: CPU-Z and HWMonitor compromised

#58
post #19

To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.

I hope you don't think that waiting a month will protect you. Malicious software can wait to be triggered months or years before anything malicious happens.

Re: CPU-Z and HWMonitor compromised

#59
post #56

some comments purportedly (i did not verify) from one of the maintainers: > Dear All, I'm Sam and in I'm working with Franck on CPU-Z (I'm doing the validator). Franck is unfortunately OOO for a couple weeks. I'm just out of bed after worked on Memtest86+ for most the night, so I'm doing my best to check everything. As very first checks, the file on our server looks fine ( https://www.virustotal.com/gui/file/6c8faba4…

For what it's worth - I used to write CPU reviews a while back - I can vouch for both Sam and Franck. Franck is the guy behind CPUID and Sam is a close friend of his, who was known for working at Canard PC on top of his work on Memtest : https://x86.fr/about-me/

that is pretty cool!

when i say i didnt verify, i just mean that i ripped these quotes out of reddit, and did not check whether the reddit username that posted the comments is known to be an identity of Sam.

Re: CPU-Z and HWMonitor compromised

#60
post #6

Jesus. I see that post and comment section and I immediately expect to hear Joey telling me about how this ATM is Idaho started spraying cash after his hack of the Gibson. That is a real-life reproduction of the perception of hackers in films in the '90s.

And CSI: Miami, which kept the vibe alive through the 2000s and "educated the masses" on how IT works. Beep boop, I'm in.
Post reply on HN