5 ms·
Wait what? It doesn't even at least parse the URI to ensure that it's a dell subdomain? Damnit Dell.
by dcherman 11y ago
Wait what? It doesn't even at least parse the URI to ensure that it's a dell subdomain? Damnit Dell.
- orf 11y agoWell, to be fair they do parse it, extract the hostname, then do the ridiculous "if hostname.endswith('dell.com')". The simple fix is to replace it with '.dell.com', but they didn't do that. No, they 'upgraded' their 'authentication' mechanism (just a sha256 hash of a hard-coded GUID + the current time) and called it a day. Oh, and they obfuscated the binary for iron-clad maximum security.
- mwh12 11y ago> The simple fix is to replace it with '.dell.com', but they didn't do that. That would be, if it were not for... $ dig localhost.dell.com ; <<>> DiG 9.9.5-3ubuntu0.5-Ubuntu <<>> localhost.dell.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56836 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4000 ;; QUESTION SECTION: ;localhost.dell.com. IN A ;; ANSWER SECTION: localhost.dell.com. 462 IN A 127.0.0.1
- baby 11y agoany explanation on that?
- mwh12 11y agoEssentially, there's a public DNS A record that maps a Dell subdomain to your local machine's IP, namely localhost.dell.com to 127.0.0.1 An attacker who can either abuse an already running local webserver (like Apache configured to listen to *:80) or start up a locally running webserver (using something like python's SimpleHTTPServer) can serve their content under a Dell subdomain. This requires some sort of local filesystem privileges or potentially RCE, but if the original commenter is correct, this can be pivoted to SYSTEM RCE.
- JoshTriplett 11y ago> The simple fix is to replace it with '.dell.com', but they didn't do that. That doesn't suffice either, unless they also enforce HTTPS. Otherwise, any network you connect to can spoof DNS and load a fake dell.com page over http to break your security. (Of course, even if they did require HTTPS, the attacker could serve up a fake dell.com HTTPS site signed with eDellRoot...) And either way, they have no business even allowing an authentic dell.com page to execute arbitrary code on your system, either.