ASUSpicious Flaw – Users' Information Exposed Since 2022
1–10 of 13 posts
Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#2Hopefully it happened to make sure people had the updated version, but I'm gonna keep uninstalling bloatware as much as possible for the reasons outlined in the blog post.
Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#3I happen to have both of those DLLs, but I had already disabled all ASUS-related services. I use this script to disable all services starting with "Asus" on startup. [1]
To disable the MyASUS auto-installer in BIOS go to Advanced, there is an option to disable auto-downloading of MyAsus in Windows. [2]
[1]: https://gist.github.com/Ciantic/76ade5f2731cbe87b70d17ff2898...
[2]: https://github.com/sammilucia/ASUS-G14-Debloating/blob/main/...
Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#4I think MyASUS was the piece of software that automagically installed itself on my computer a few weeks ago. I still have no idea how it got there; I just uninstalled it as soon as I saw. Hopefully it happened to make sure people had the updated version, but I'm gonna keep uninstalling bloatware as much as possible for the reasons outlined in the blog post.
Enter BIOS by pressing ESC during the ROG logo Usually under Advanced, there is an option to disable auto-downloading of MyAsus in Windows
https://github.com/sammilucia/ASUS-G14-Debloating/blob/main/...
Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#5I think MyASUS was the piece of software that automagically installed itself on my computer a few weeks ago. I still have no idea how it got there; I just uninstalled it as soon as I saw. Hopefully it happened to make sure people had the updated version, but I'm gonna keep uninstalling bloatware as much as possible for the reasons outlined in the blog post.
Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#6Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#7No bug bounty? Major hardware company? Disaster in 3 .... 2.... 1...
Didn't get so much as a "thank you". At least they fixed it. But I'm sure they have other vulns given how stupid this one was...
Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#8Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#9No bug bounty? Major hardware company? Disaster in 3 .... 2.... 1...
Heh, I recently reported a bug to a pretty big healthcare company where I could simply increment the integer ID in the URL and see other patients' info. Didn't get so much as a "thank you". At least they fixed it. But I'm sure they have other vulns given how stupid this one was...
Re: ASUSpicious Flaw – Users' Information Exposed Since 2022
#10Once again, I do not believe that these HW manufacturers understand how much good-will they squander by being cheap arses on the software. If only there were an established company here showing how things could be done....