6 ms·
This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a f
by ehhthing 4y ago
This all seems a bit silly, and could easily be attributed to a communication issue.
On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected.
Even modzero themselves admitted that the vulnerability is not of great severity so the motivation for the security triage team to put more resources in validating a non-severe bug are probably very low. They likely just tried to run the exploit, and didn't think much of it after it didn't work.
Also if modzero is not participating in a bug bounty program then CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix.
I'm no fan of CrowdStrike (in fact, one of the more memorable moments for me at my previous job was my boss calling them "ClownStrike"), but it seems as if this is just a bit of overzealous entitlement from modzero as well as not enough testing on CrowdStrike's end.
- FreakLegion 4y ago> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sure they'll work it out if this gets noticed. My first direct experience with CrowdStrike was the announcement of VENOM back in 2015 [1], which they coordinated with a few friendlies like FireEye but left most of us in the dark about (I was at Palo Alto Networks, not exactly a small company). Looks like they still struggle with this stuff. 1. https://web.archive.org/web/20150514062749/https://venom.crowdstrike.com/ https://web.archive.org/web/20150514062749/https://venom.cro..., possibly the origin of named and marketed vulnerabilities.
- vladvasiliu 4y ago> privilege escalation tends to be easy on Windows anyway Well, Crowdstrike is supposed to catch and prevent that...
- microtonal 4y agopossibly the origin of named and marketed vulnerabilities. Heartbleed is older (2014).
- FreakLegion 4y agoIncredible! In my mental timeline VENOM came first, maybe because we had to pull an all-nighter.
- tptacek 4y ago"Responsible" disclosure is an Orwellian term. The real term is "coordinated disclosure", and, as you can see from the timeline, there's coordination here.
- monocasa 4y ago"Coordinated disclosure" is the orwellian reimagining here. The only reason why the industry settled on the responsible disclosure process is that works regardless of how much vendor coordination occurs, or even if they are technically responding to emails but really just stalling indefinitely.
- tptacek 4y agoNo, I was there at the inception of this term, and it was absolutely originally imagined as a way of controlling researchers and giving vendors more power over information about their products. It has pissed researchers off for decades, as it implies that not following the "responsible" process makes one per se "irresponsible".
- monocasa 4y ago> No, I was there at the inception of this term, and it was absolutely originally imagined as a way of controlling researchers and giving vendors more power over information about their products. I mean, that half is the carrot to get vendors to play ball and actually fix their shitty code occasionally. It lets unaffiliated white hat security researchers who are just trying to get sec issues fixed actually get some focus time from the various sauron-esque eyes that are corporate attention by converting a 'bug report' into an 'impending pr nightmare bomb with a known timer'. It's a similar hack to complaining on twitter to deal with a marketing department instead of calling in to a customer service line that's just trying to get you to go away. > It has pissed researchers off for decades, as it implies that not following the "responsible" process makes one per se "irresponsible". The point of calling it responsible is to defend the researchers who have massively less power in the relationship against the vendors. Even now you'll see whitehats lambasted for eventually disclosing after a vendor dragged their ass. Beyond that, yeah you can't please everyone.
- horsawlarway 4y agoI mean... as a user on the machine, if I have admin rights there's very, very little they can meaningfully do to stop me from removing their software. Hooking a token into their uninstaller is hardly sufficient... I have SO much surface area to attack that I don't genuinely think you can call this anything other than trivial. For an admin user, I'd take this token prompt more as a "Hey - you're about to violate company policy" more than any literal technical restriction. I can steal the network, change the registry, simply delete their binaries, update shared dlls, or any number of other easy hacks to get them offline. This is trivial.
- FreakLegion 4y agoCrowdStrike has kernel code meant to stop everything you mention minus the network part (and being offline should have minimal impact on the security of the system), but in practice I'm sure you're right. It's easy enough to get attacks past them that frankly I haven't bothered trying to disable the agent.
- conioh 4y ago> I can steal the network, change the registry, simply delete their binaries, update shared dlls, or any number of other easy hacks to get them offline. That's a bold claim. Mostly incorrect, but bold. A proper Windows endpoint protection software's Registry filter will prevent you from modifying its Registry data; its filesystem minifilter will prevent you from modifying its files; its EXEs will use the Windows mitigation policy that loads only Microsoft-signed DLLs; its connection with its management server will be encrypted and signed with known keys/certifications (rather than trusting everything from the Windows Certificate Store), etc. An admin can still bypass all of that with enough effort but it's not nearly as trivial as you say. What is trivial that you can't actually do the things you said and it's common knowledge (in the field).
- horsawlarway 4y agoIt IS trivial. Period. If you don't want people to modify the machine - don't give them admin access. If you give them admin access... don't assume they won't modify the machine. For comparison - I worked software security for 5 years dealing with fortune 100 banks. I have zero faith in the industry. It's mostly a shell game for liability. I can absolutely do the things I mentioned above. At best, it's a discussion of how hard I'll have to work. So again... this is basically a "hey - you're about to violate company policy" notice.
- sagonar 4y agoTo me it looks like like a very clear case of a writing/speaking words which they know (or the company clearly should have known) not to be true. One could perhaps call this a "communication problem", but I'd like to think most people would call it lying
- jessaustin 4y ago...it's much more likely... This is very speculative. There's no reason to bend over backwards to imagine a way in which "ClownStrike" (your boss gets it!) didn't flag a specific PoC without fixing the underlying issue. If CS insists on such opacity, the best assumption is actually the opposite.