Live data from Hacker News

The RCE that AMD won't fix

mrbruh.com

1–10 of 182 posts

Re: The RCE that AMD won't fix

#3
This is super bad right? Like anybody who has this running will be vulnerable to a super basic HTTP redirect -> installer running on their machine attack, right? And on top of that it's for something that is likely installed on _so many_ machines, right?

I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediately own anyone with ATI graphics?

Re: The RCE that AMD won't fix

#4
If this is true, it seems like a much more serious vulnerability than I was expecting when I clicked the link.

And it's obviously an oversight; there is no reason to intentionally opt for http over https in this situation.

Re: The RCE that AMD won't fix

#5
Based on the policy (and my hat) I have to assume some business partner failed to maintain the 'ca-certificates' equivalent for Windows (or NTP) and was rewarded in their insane demand for plaintext.

So easy to fix, just... why? My kingdom for an 's'. One of these policies are not like the others. Consider certificates and signatures before categorically turning a blind eye to MitM, please: you "let them in", AMD. Wow.

Re: The RCE that AMD won't fix

#8
So compromising one DNS lookup is sufficient, ex:

1. Home router compromised, DHCP/DNS settings changed.

2. Report a wrong (malicious) IP for ww2.ati.com.

3. For HTTP traffic, it snoops and looks for opportunities to inject a malicious binary.

4. HTTPS traffic is passed through unchanged.

__________

If anyone still has their home-router using the default admin password, consider this a little wake-up call: Even if your new password is on a sticky-note, that's still a measurable improvement.

The risks continue, though:

* If the victim's router settings are safe, an attacker on the LAN may use DHCP spoofing to trick the target into using a different DNS server.

* The attacker can set up an alternate network they control, and trick the user into connecting, like for a real coffee shop, or even a vague "Free Wifi."

Post reply on HN