The RCE that AMD won't fix
mrbruh.com
The RCE that AMD won't fix
1–10 of 182 posts
Re: The RCE that AMD won't fix
#2I love how they grouped man in the middle there
Re: The RCE that AMD won't fix
#3I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediately own anyone with ATI graphics?
Re: The RCE that AMD won't fix
#4And it's obviously an oversight; there is no reason to intentionally opt for http over https in this situation.
Re: The RCE that AMD won't fix
#5So easy to fix, just... why? My kingdom for an 's'. One of these policies are not like the others. Consider certificates and signatures before categorically turning a blind eye to MitM, please: you "let them in", AMD. Wow.
Re: The RCE that AMD won't fix
#6Re: The RCE that AMD won't fix
#7>Attacks requiring physical access to a victim's computer/device, man in the middle or compromised user accounts I love how they grouped man in the middle there
Re: The RCE that AMD won't fix
#81. Home router compromised, DHCP/DNS settings changed.
2. Report a wrong (malicious) IP for ww2.ati.com.
3. For HTTP traffic, it snoops and looks for opportunities to inject a malicious binary.
4. HTTPS traffic is passed through unchanged.
__________
If anyone still has their home-router using the default admin password, consider this a little wake-up call: Even if your new password is on a sticky-note, that's still a measurable improvement.
The risks continue, though:
* If the victim's router settings are safe, an attacker on the LAN may use DHCP spoofing to trick the target into using a different DNS server.
* The attacker can set up an alternate network they control, and trick the user into connecting, like for a real coffee shop, or even a vague "Free Wifi."