AMD AutoUpdate terminal always pops up at midnight for me and then requires me to dismiss it. I've been meaning to uninstall this but always forget about it the next morning. Now I have good reason to block it entirely and go back to manual updates
The RCE that AMD won't fix
61–70 of 182 posts
Re: The RCE that AMD won't fix
#62> This means that a malicious attacker on your network, or a nation state that has access to your ISP can easily perform a MITM attack and replace the network response with any malicious executable of their choosing. I am pretty sure, a nation state wanting to hack an individual's system has way more effective tools at their disposal.
Re: The RCE that AMD won't fix
#63This is super bad right? Like anybody who has this running will be vulnerable to a super basic HTTP redirect -> installer running on their machine attack, right? And on top of that it's for something that is likely installed on _so many_ machines, right? I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediat…
Some of us do not enable automatic updates (automatic updates are the peak of stupidity since Win98 era). And, when you sit in an airport, you don't update all your programs.
Re: The RCE that AMD won't fix
#64It really makes you wonder what level of dysfunction is actually possible inside a company. 30k employees and they can't get one of them to hook up certbot, and add an 's' to the software.
Re: The RCE that AMD won't fix
#65This is super bad right? Like anybody who has this running will be vulnerable to a super basic HTTP redirect -> installer running on their machine attack, right? And on top of that it's for something that is likely installed on _so many_ machines, right? I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediat…
But it seems pretty trivial for some bad actor at local ISP.
Re: The RCE that AMD won't fix
#66Many people don't worry about connecting to random wifi anymore, but users of AMD still have to
Re: The RCE that AMD won't fix
#67Re: The RCE that AMD won't fix
#68Re: The RCE that AMD won't fix
#69This is super bad right? Like anybody who has this running will be vulnerable to a super basic HTTP redirect -> installer running on their machine attack, right? And on top of that it's for something that is likely installed on _so many_ machines, right? I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediat…
Who would connect to unknown person's hotspot? But it seems pretty trivial for some bad actor at local ISP.
Have you ever gone to a crowded public place and setup an open hotspot?
Re: The RCE that AMD won't fix
#70Earlier quoted context omitted.
Who would connect to unknown person's hotspot? But it seems pretty trivial for some bad actor at local ISP.
This is oh sweet summer child stuff. Have you ever gone to a crowded public place and setup an open hotspot?