Earlier quoted context omitted.
> Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install. Holy cow. Would you have a link on this?
The tech is called Windows Platform Binary Table, WPBT for short. Here's a random article covering it https://www.howtogeek.com/226308/the-windows-platform-binary... You can find others by searching for "lenovo wpbt" or "lenovo unremovable crapware".
Remote Code Execution on Most Dell Computers
61–70 of 323 posts
Re: Remote Code Execution on Most Dell Computers
#62Re: Remote Code Execution on Most Dell Computers
#63OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…
You forgot the last part: OEM: Profit
Re: Remote Code Execution on Most Dell Computers
#64Re: Remote Code Execution on Most Dell Computers
#65- updates served via HTTP through the browser only
- as a binary (exe)
- from a domain other than dell.com (delldisplaymanager.com)
- signed by a 3rd party (En Tech Taiwan)
- and nagging about updates every reboot
(you can get an outdated version via dell.com, but it will want to update through said channel immediately)
(And I bet this one gets pinged for updates, having the full url to the exe in the update check: https://www.entechtaiwan.com/updates/public/ddm.inf )
Re: Remote Code Execution on Most Dell Computers
#66Sounds like the attacker has to be on the local network (or presumably VPN) to use the exploit? If so that's a nontrivial hurdle in many cases.
Like a WiFi at a café or airport?
Re: Remote Code Execution on Most Dell Computers
#67OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…
Re: Remote Code Execution on Most Dell Computers
#68OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…
Re: Remote Code Execution on Most Dell Computers
#69This is exactly why you should remove any bundled software from vendors and try to start afresh when picking up a new machine.
Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.
Re: Remote Code Execution on Most Dell Computers
#70"Dell bug bounty program" and the like don't turn up obvious results to me.