Live data from Hacker News

MSI Center – How to gain SYSTEM privileges in seconds

mrbruh.com

61–68 of 68 posts

Re: MSI Center – How to gain SYSTEM privileges in seconds

#61
post #34

Earlier quoted context omitted.

In other words, bootlicking the corpo-authoritarians?

You're actually helping the people that use the software from getting pwned, companies are secondary beneficiaries.

Keep toeing the line and help them put the nooses around your necks.

Re: MSI Center – How to gain SYSTEM privileges in seconds

#63
post #20

> So far, for the vulnerabilities I have reported to Google, ASUS, AMD, TP-Link, Netgear, MSI (and more), they have paid out a total of $0 in bug bounties. Why bother reporting to them ? You could just as well sell it to third parties if it doesn't interest them.

You understand the concept of doing something that doesn't bring direct monetary benefit?

Yes I do, but we are speaking of companies with billions. If they can't take this seriously enough that they pay for the vulnerabilities, they deserve to get the bad press.

When all MSI computers get exploited in the wild, I bet that these execs will find money.

Re: MSI Center – How to gain SYSTEM privileges in seconds

#64
post #60
post #16

Earlier quoted context omitted.

What about using the Visual Studio packaging tools? I live on .NET/C++ universe in regards to Windows development, so it might be it isn't as nice for not blessed stacks.

Didn't they discontinue those around VS 2015 or so? Its been a while since I tried. Iirc that's what got replaced with WiX and ClickOnce, both of which are 100X more complicated to use.

Nope, it is the other way around, MSI became the official replacement for exe installers, and MSIX is the evolution of APPX from UWP/Windows Store and the "best practices" format going forward.

By VS packaging tools I mean tbe application project type that generates a MSIX as build outcome.

Re: MSI Center – How to gain SYSTEM privileges in seconds

#65
post #20

Earlier quoted context omitted.

You understand the concept of doing something that doesn't bring direct monetary benefit?

Yes I do, but we are speaking of companies with billions. If they can't take this seriously enough that they pay for the vulnerabilities, they deserve to get the bad press. When all MSI computers get exploited in the wild, I bet that these execs will find money.

But it's not "MSI computers" it's actual people getting pwned.

Re: MSI Center – How to gain SYSTEM privileges in seconds

#66
post #65

Earlier quoted context omitted.

Yes I do, but we are speaking of companies with billions. If they can't take this seriously enough that they pay for the vulnerabilities, they deserve to get the bad press. When all MSI computers get exploited in the wild, I bet that these execs will find money.

But it's not "MSI computers" it's actual people getting pwned.

I know but I don't think there is any other solution. These companies speak money, if you don't speak money they ignore you.

Getting your users computers infected and having to deal with bad buzz, prosecutions, loss of sales, would most likely wake them up.

Sending them a mail ? They don't care.

Re: MSI Center – How to gain SYSTEM privileges in seconds

#67
post #65

Earlier quoted context omitted.

But it's not "MSI computers" it's actual people getting pwned.

I know but I don't think there is any other solution. These companies speak money, if you don't speak money they ignore you. Getting your users computers infected and having to deal with bad buzz, prosecutions, loss of sales, would most likely wake them up. Sending them a mail ? They don't care.

If it's my data/money getting stolen, I'd give no fucks about MSI getting a fine or whatever the usual reaction to these fuckups is. On the other hand, if I found an exploit and there wasn't a bounty available, I'd still report it. Betterment of the world and all that.

Re: MSI Center – How to gain SYSTEM privileges in seconds

#68
post #34

Earlier quoted context omitted.

You're actually helping the people that use the software from getting pwned, companies are secondary beneficiaries.

Keep toeing the line and help them put the nooses around your necks.

What wild regurgitation of some generic sentence is this lol?
Post reply on HN