3 ms·
Out of curiosity, how would an attacker exploit this to run a code s/he wants? Try to direct the DNS requests to their own server instead of the LiveUpdate one
by graffitici 10y ago
Out of curiosity, how would an attacker exploit this to run a code s/he wants?
Try to direct the DNS requests to their own server instead of the LiveUpdate one? If so, how?
Also, would we be a better design? Hard-code IP addresses to prevent the DNS trick? Use HTTPS and hardcode the public key of the server on every machine?
(Only asking out of curiosity, clearly.. Seems like a good case study for designing things right.)
- morsch 10y agoRedirecting DNS is one way; if the attacker can MITM the connection -- e.g. they control the wireless AP, or the router, or the ISP -- they can also just replace the server response with a modified image. Hardcoding the IP is not a good idea and it doesn't work against MITMing. HTTPS with certificate pinning would be the standard way to secure the connection. Verifying the BIOS image using a certificate before installing it is also "a good idea" (ie. pretty much mandatory), that way users can provide a binary downloaded on another computer.
- Retr0spectrum 10y agoARP spoofing on public wifi would be the obvious way.