Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

61–70 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#61

Earlier quoted context omitted.

> Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install. Holy cow. Would you have a link on this?

The tech is called Windows Platform Binary Table, WPBT for short. Here's a random article covering it https://www.howtogeek.com/226308/the-windows-platform-binary... You can find others by searching for "lenovo wpbt" or "lenovo unremovable crapware".

Thanks!

Re: Remote Code Execution on Most Dell Computers

#62
Preinstalled crapware is one of the main reasons I still build my own desktops. Back when I used to buy Dells or HPs for the kids I always began the relationship with a reformat and reinstall. That was easy for me at the time because I had a complete MSDN sub with access to all versions of MS operating systems.

Re: Remote Code Execution on Most Dell Computers

#63

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

You forgot the last part: OEM: Profit

That doesn't happen in the first case. The second case costs less in terms of engineering and PR/reputation, so there's more profit there.

Re: Remote Code Execution on Most Dell Computers

#65
There is also the neat tool "Dell Display Manager". The only way to avoid the moody touch buttons on some Dell monitors to change their brightness:

- updates served via HTTP through the browser only

- as a binary (exe)

- from a domain other than dell.com (delldisplaymanager.com)

- signed by a 3rd party (En Tech Taiwan)

- and nagging about updates every reboot

(you can get an outdated version via dell.com, but it will want to update through said channel immediately)

(And I bet this one gets pinged for updates, having the full url to the exe in the update check: https://www.entechtaiwan.com/updates/public/ddm.inf )

Re: Remote Code Execution on Most Dell Computers

#66
post #16
post #14

Sounds like the attacker has to be on the local network (or presumably VPN) to use the exploit? If so that's a nontrivial hurdle in many cases.

Like a WiFi at a café or airport?

I was thinking in enterprise contexts, but, yes, that's fair. Still, anybody doing anything important on public WiFi should be using a VPN.

Re: Remote Code Execution on Most Dell Computers

#67

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

The author chose to download the software from the OEM and the software can be uninstalled.

Re: Remote Code Execution on Most Dell Computers

#68

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

Plus, once it's gotten on the machine, why bother to patch it? You've achieved your goal and it was most likely written to spec by a vendor who has already been paid and moved on.

Re: Remote Code Execution on Most Dell Computers

#69

This is exactly why you should remove any bundled software from vendors and try to start afresh when picking up a new machine.

Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.

My last two computers have been Lenovo ThinkPads (T520 and Yoga S1) and they bundle more crappy software than just about any other business computer maker. It's good hardware and once you reformat and reinstall Windows (or Linux) they are great machines.
Post reply on HN