This is exactly why you should remove any bundled software from vendors and try to start afresh when picking up a new machine.
Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.
Remote Code Execution on Most Dell Computers
91–100 of 323 posts
Re: Remote Code Execution on Most Dell Computers
#92I'm not going to buy Dell again...
This is an exploit in the shitty software that OEMs put on their Windows images. Stuff like this is practically universal (minus Apple), and the fact that Dell hasn't (AFAIK) actively bundled very evil malware with their computers makes them far from the worst offender.
Re: Remote Code Execution on Most Dell Computers
#93Earlier quoted context omitted.
Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.
Microsoft pulled a stunt before when they made Windows load an executable from inside UEFI during every boot.
Apple keeps track of what you type for autocorrect and word prediction. "Apple installs a keylogger on every iPhone."
Re: Remote Code Execution on Most Dell Computers
#94General sanity aside, the whole exploit hinges on the fact that they used string parsing to check for the prefix "http". This wouldn't have been exploitable if they used a proper URL library.
Re: Remote Code Execution on Most Dell Computers
#95I've not yet seen anyone comment on the fact that Dell was informed in late Oct, confirmed by late Nov...and the public was advised in mid April. That's a lot of time for a known and confirmed vulnerability to be undisclosed, isn't it?
Re: Remote Code Execution on Most Dell Computers
#96Earlier quoted context omitted.
I have a Dell XPS 13 with Ubuntu.
Are you contesting that 99% of Dell laptops are running Windows? Your comment seems like a nonsequiter.
Re: Remote Code Execution on Most Dell Computers
#97Re: Remote Code Execution on Most Dell Computers
#98Earlier quoted context omitted.
> Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install. Holy cow. Would you have a link on this?
The tech is called Windows Platform Binary Table, WPBT for short. Here's a random article covering it https://www.howtogeek.com/226308/the-windows-platform-binary... You can find others by searching for "lenovo wpbt" or "lenovo unremovable crapware".
I guess that is what the feature is designed for, though.
Re: Remote Code Execution on Most Dell Computers
#99Earlier quoted context omitted.
That’s astounding. Suddenly my “zero the entire storage, including partition table” methodology which I always somewhat regarded as overkill appears to be reasonable and/or necessary.
Your approach won’t solve that, you’d need to also flash the chip with patched / clean firmware
For example, would loading Grub first, and then loading Windows from Grub, prevent the issue?
Re: Remote Code Execution on Most Dell Computers
#100Earlier quoted context omitted.
The tech is called Windows Platform Binary Table, WPBT for short. Here's a random article covering it https://www.howtogeek.com/226308/the-windows-platform-binary... You can find others by searching for "lenovo wpbt" or "lenovo unremovable crapware".
I just checked on my Dell workstation at work and it seems they are now using this method to load the Lojack anti theft rootkit. I see the wpbbin.exe file and it's signed by Absolute Software. I guess that is what the feature is designed for, though.