11 ms·
What an absolute clusterfuck. I work at a multinational company who's IT department (over my objection) installs Trend Micro on all user end points. I'll be sen
by improv32 11y ago
What an absolute clusterfuck. I work at a multinational company who's IT department (over my objection) installs Trend Micro on all user end points. I'll be sending this the department head's way, Trend might lose some business over this
- sarciszewski 11y agoBonus points to Tavis Ormandy for this classy exploit code: https://code.google.com/p/google-security-research/issues/attachmentText?id=693&aid=6930013000&name=exploit.html&token=ABZ6GAeiAHUkknIMA8hCpMQmcLfFV8XXAg%3A1452538505409 https://code.google.com/p/google-security-research/issues/at... <a href="javascript:begin()">Click Here</a> to run the command above (the default will uninstall Trend Micro Maximum).
- daodedickinson 11y agoWow I've only played with js a few days and I can interpret that pretty easily, so this seems pretty simple.
- nkrisc 11y agoThe JS is inconsequential, really. Just making the correct HTTP request, even by typing it in your browser, is the exploit.
- jondubois 11y agoLol. Yes, funny how people love to throw JavaScript/Node.js into the mix. It's like "They're using JS; how could it possibly be secure?!". That's actually highly ironic considering that JS is so far the only language that is secure enough to run universally in every browser on the planet. People can't get around the fact that JS has evolved a LOT since it was launched and it still suffers a bad name.
- detaro 11y agoWhere here has JS been given a bad name? I didn't get that vibe.
- dopamean 11y agoOne of those JS devs who gets really defensive when people are talking about JS and not screaming about how awesome it is.
- taurath 11y agoMost of my experience saying you mostly do javascript in a room full of other coders is that they'll all scream at you to use a "better" language (on HN too).
- smt88 11y agoYou misunderstand why people think JS is insecure. The problem is that JS is really easy to make mistakes in because of silent errors, dynamic typing, type coercion, etc. The result is that your server-side JS is more prone to different kinds of security issues. On the client side, in the browser, JS is sandboxed, so the language is almost irrelevant. If JS can't actually access the underlying system, no number of bugs make the code insecure.
- sangnoir 11y ago> The problem is that JS is really easy to make mistakes in because of silent errors, dynamic typing, type coercion, etc. All those are not a factor in this instance. It seems to me it's a result of calling exec() on unscrubbed user input, and this can be done in any language.
- smt88 11y agoI agree. I was responding to a tangential comment, rather than the root post.
- 11y ago
- raverbashing 11y agoReally, it's a simple email away from a complete disaster Send an email to several people on the organization containing the offending JS that calls shell execution, this can have a huge impact. "Security software" LOL
- JoshTriplett 11y agoWhile email can't directly call JavaScript, these URLs look like they'd work if just loaded, so an <img> tag might suffice to cause shell execution.
- raverbashing 11y agoTrue, and you can always have a "Click here for more info" in the email pointing to a believable page. But yeah, an image will most likely do it.
- cenal 11y agoThis is clearly a terrible design flaw by Trend Micro. I hope some responsible are looking for new jobs. Still, there isn't much faith I put in any endpoint security solutions. They are all terrible. Bromium seems to be bucking the trend of traditional endpoint security but they have one of the worst sales / business dev programs I have ever seen. They should be much more ubiquitous than they are.
- api 11y agoThe problem is that endpoint OSes are horribly insecure. It's hard to well nigh impossible to build a third party "endpoint security solution" for that, since this amounts to creating an aftermarket patch to plug a leaky dike.
- EvanPlaice 11y agoThere's a simple solution for that. Use a unikernel and make the entire OS immutable. I'm really looking forward to the day where the tools are mature enough to make this an option.
- api 11y agoFine for single-purpose app deployments, but on a grander scale you've just pushed all the security problems back to the APIs and interfaces of your cloud provider and/or virtualization engine. Now an AWS access token constitutes a root password for everything (for example).
- digi_owl 11y agoBingo. the PCs of old were more secure in that they did only one thing at once. These days even the most barebones install have all manner of things running in the background, and any normal user setup is likely to add a dozen more.
- EvanPlaice 11y agoAccess tokens are a 'manageable' risk and AWS provides tools to enforce best practices where necessary. Locating and regularly patching security vulnerabilities across thousands of components in a fully-featured monolithic operating system isn't. It's a potential disaster waiting to happen. You don't need... ...a huge bundle of drivers when the OS will always run on a VM. ...extensive filesystem support when everything will be either transient or run directly from memory. ...multiple users when only one is required. ...OS-level sandboxing (ie kernel/user-space) when the VM already provides sandboxing. ...native POSIX tools when 'safe' alternatives can be run from the VM. Despite the best intentions of developers and admins alike, the current approach to security is not working. Despite my own vigilance, I have personally had my sensitive information leaked by two separate multi-billion dollar organizations in the past year. It's a simple fact that every feature added, increases the attack surface of the entire system. All I'm suggesting, is that it's not a bad idea to start looking to the alternatives that are becoming available.
- Ecio78 11y agoCheck if your installation is vulnerable. My company uses TM Officescan for desktops and this doesn't work (I think this Password Manager is not even installed by I just tried the localhost url POC and it doesnt' work).
- JoblessWonder 11y agoPretty sure this only works on the personal version of their software. We don't even have an option to deploy a password manager (that I'm aware of) as part of the enterprise Anti-virus product.
- jay-saint 11y agoConfirmed, this does not work for `Trend Micro Worry Free Business Security` clients. I do know that the enterprise / business version installs a server on the management machine. I do not currently have access to the box that our version is hosted on to test the exploit there.
- fpgaminer 11y agoRegardless, given what was discovered in the personal version, would you trust the enterprise version?
- JoblessWonder 11y agoThe personal versions are what get saddled with "Value Add-Ons" like password managers/website screening with colorful icons/blah blah bullshit bullshit. Most enterprise anti-virus software concentrates on finding viruses and maintaining compliance with whatever policies you have. They are also usually managed by different divisions with different goals. (Whether or not anti-virus at all is effective is another debate entirely.)
- digi_owl 11y agoI really do wonder how the market got segmented like this...