13 ms·
Deleting System32\curl.exe
- blueflow 3y agoPeople who delete system binaries due to whacky CVEs deserve a broken system. I don't even know who else to blame for this.
- yourusername 3y agoThere are people responsible for the security of Windows systems in some organisations that do not understand their job. They look into their AV solution and it says vulnerable file detected on $x systems and they instruct their IT department to remove the file.
- robertlagrant 3y agoIndeed. Whole companies such as Crowdstrike exist just to sit in between automated tools and heavy-handed action based on tool output.
- hardware2win 3y agoIve been actually impressed by Crowdstrike product (I guess) Ive tested a two or three years old Chrome version with JIT compiler vulnerability and guess what - on empty Linux vm it managed to escape chrome and execute code Meanwhile on Windows with Crowdstrike Chrome just showed some error message about mem. access Im not sure who handled that attack - was it Windows or Crowdstrike, but eitherway Ive been impressed
- tyingq 3y agoI'm guessing a common sequence is someone knowing what curl is, but not knowing that Windows ships with it. So, thinking that System32\curl.exe must have been put there by malware, or put there by someone installing optional software.
- Freak_NL 3y agoMicrosoft should have renamed it to WINDLHLP.COM or something Windowsy like that, and none of these people would have dared touch it.
- tyingq 3y agoI noticed that "curl" in PowerShell is an alias, so you would have to deliberately say "curl.exe" to get System32\curl.exe C:\> alias curl CommandType Name Version Source ----------- ---- ------- ------ Alias curl -> Invoke-WebRequest
- justeleblanc 3y agoThat's not the case in the latest versions of powershell.
- archgoon 3y ago[dead]
- VWWHFSfQ 3y agoYeah they did the same thing with wget. Just absolutely bonkers
- phpisthebest 3y agoThat is for Windows Powershell, not Powershell (and yes Windows Powershell is different from PowerShell [1]) curl > curl.exe > C:\Windows\System32\curl.exe [1] https://learn.microsoft.com/en-us/powershell/scripting/whats-new/differences-from-windows-powershell?view=powershell-7.3 https://learn.microsoft.com/en-us/powershell/scripting/whats...
- thomasjudge 3y agoThis is so Microsoft
- thaumasiotes 3y agoThey deserve to not be allowed to restore their system to normal? > The people who deleted or replaced the curl executable noticed that they cannot upgrade because the Windows update procedure detects that the Windows install has been tampered with and it refuses to continue. This policy makes absolutely no sense.
- varjag 3y agoSince the policy is going an extra mile preventing something rather than simply not caring, it probably does make sense. Just in a way that's not trivial to anticipate.
- bee_rider 3y agocurl is used to download files… if it is missing, Windows presumably won’t be able to download something. If they just go for it anyway, the system could end up in some undefined state.
- alkonaut 3y agoI doubt curl is involved in the windows update process itself (seeing as Windows Update is a lot older than the inclusion of curl in Windows)
- aflag 3y agoIt does make sense, as the upgrade may break the system because of the tampering. Probably say upfront that there's a problem and let the user do a full reinstall when they can rather than attempt to upgrade and break everything. They could have a "force upgrade" button, but many people would just click that without thinking twice then blame MS when it breaks everything.
- dwattttt 3y agoStrictly speaking the update process isn't able to update to the new version without the existing file (https://devblogs.microsoft.com/oldnewthing/20200213-00/?p=103436 https://devblogs.microsoft.com/oldnewthing/20200213-00/?p=10...). As noted on the blog post, the solution is to run the system file checker (sfc) to repair it before running the update
- Karellen 3y ago> I don't even know who else to blame for this. The people who told them that deleting system binaries would fix their problems? > I have been pointed to responses on the Microsoft site answers.microsoft.com done by “helpful volunteers” that specifically recommend removing the curl.exe executable as a fix. Don't trust strangers on the internet with advice you don't understand the implications of. Even if they are sincere and mean well, they can still be wrong.
- phpisthebest 3y agoThe problem here is that if they understand the implications they probably would not be on awnsers.microsoft.com in the first place
- lodonnell9213 3y agoBut that's the problem, the people doing this do not understand what curl is/does so want it gone because its got a CVE and some outlet somewhere has said its worse than what it is. if that's the case we should just delete the entire OS as there are vulns all over it.
- remram 3y ago> The people who told them that deleting system binaries would fix their problems? If you are responsible for the security posture and compliance in your organization, reading and acting on security assessments, and yet you do random changes based on random comments on forums, you deserve the blame. I don't think we're not talking about individual end-users here. Those do not scan their systems for CVEs and do not have a requirement to get to 0 alerts.
- Karellen 3y ago> I don't think we're not talking about individual end-users here. Are you sure about that? From TFA: > Lots of Windows users everywhere runs security scanners on their systems with regular intervals in order to verify that their systems are fine. At some point after December 21, 2022, some of these scanners started to detect installations of curl that included the above mentioned CVE. Nessus apparently started this on February 23. > This is not helpful. > Lots of Windows users everywhere then started to panic when these security applications warned them about their vulnerable curl.exe. That sounded like it included individual end-users to me. Anectodally, I know a few Windows users who don't trust Microsoft to do security well, but can't bring themselves to move off Windows for whatever reason, so run 3rd party AV and security tools to help protect themselves.
- alexb_ 3y agoAs mentioned in the article: >Many Windows users are even contractually “forced” to fix (all) such security warnings within a certain time period or risk bad consequences and penalties. So the blame would be on managers who think checking boxes is how every single job works.
- zaphar 3y agoMany times those managers are not responsible for the contractual obligation either. It's one of those comedy of errors type situations where no one single group is fully responsible but put all the decisions together and bad things result.
- 0xbadcafebee 3y ago> I don't even know who else to blame for this. Microsoft. It's their binary shipped in their system, and their customers are being directed to break their own systems. It's on them to remediate the situation.
- zaphar 3y agoNot really. They aren't the ones directing customers to break their systems. They could ban anti-virus software and get slammed for being anti-competitive I suppose. Or they could try to track down all the vendors who are being stupid and ask them to please stop but that probably won't remediate it. They don't have a lot of moves here nor does the curl project.
- 0xbadcafebee 3y agoTheir platform (Windows) is getting a bad reputation due to the problem they neglected to fix (shipping a "vulnerable" curl, informing users when the old curl was getting flagged). They could pass the buck but it's just going to be bad for them later when users think Windows itself has security vulns and breaks itself when the users do what they're told to do by vendors. If they don't want the bad rep, they need to be proactive and work with vendors and better inform customers. If I was the CEO I'd do something about it.
- lodonnell9213 3y agoBut Microsoft are not advising them to remove curl AFAIK, in that case Microsoft should fix every issue ever within Windows, even if its self inflicted. End of the day this as Daniel says is scare mongering by others who don't know what they are doing. The phrase, if someone told you to jump off a cliff, would you?, and, Your scientists were so preoccupied with whether or not they could, they didn't stop to think if they should...
- archgoon 3y ago[dead]
- hiccuphippo 3y agoHow do I know which CVE is wacky and which isn't? Do we need another database for actually-real-CVEs?
- viraptor 3y agoFollow the links to the actual issue description and check if it makes sense in your context. While the current aggregators are not perfect, there will always be edge cases where you care about some issues more/less than someone else. The whole idea of having a single number has limitations.
- cratermoon 3y agoThe last couple of CVEs I was forced to address were in docker images based on alpine or debian, in which the some library version on the system was hit with a High or Critical level CVE. But in reality the ability to exploit the vulnerability required being able to execute a particular program on the running system. The levels of exploit required to even get to being able to exploit this vulnerability in the context I was required to mitigate it meant that in reality, your systems have already been compromised even before this can be exploited. CVE numbers have exploded while their quality has declined partly due to things like company and project bug bounties, where individuals get bonuses internally for submitting CVEs that get an ID. There's a virtual army of people doing nothing but looking for subtle ways to exploit key tools just to be able to earn a bonus. Some bigger projects, like the linux kernel, dispute some CVEs (e.g. CVE-2023-23005) because they are b.s., but smaller projects don't have the luxury. See the curl maintainer's take on this: https://daniel.haxx.se/blog/2023/03/06/nvd-makes-up-vulnerability-severity-levels/ https://daniel.haxx.se/blog/2023/03/06/nvd-makes-up-vulnerab...
- patrakov 3y agoThe UK government. This is a quote from the Cyber Essentials requirements (https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-for-Infrastructure-v3-0-January-2022.pdf https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-...): """ The Applicant must be active in its management of computers and network devices. It must routinely ... remove or disable unnecessary software (including applications, system utilities and network services) """ So, based on the quote above, curl.exe must be removed if it is not used, no matter whether it is vulnerable or not (yes I know it is a misreading, but it's frightening that the most literal interpretation is a misreading).
- circuit10 3y agoVodaphone blocks this site for being “18+ content”, I guess because of “hacking” or something? There’s no explanation or option to report a false positive and they want you to put in credit card details to confirm your age to unlock it (I don’t need tips to get around this or anything, I can just connect to another network or use a VPN)
- kypro 3y agoProbably the xx in the domain. In the UK where 20% of the internet is blocked – it's surprising you haven't experienced this before. Call your service provider and tell them you want access to adult material.
- circuit10 3y ago> In the UK where 20% of the internet is blocked That’s not true. I’ve experienced this once before that I can remember, on https://hackmii.com/ https://hackmii.com/ and it doesn’t happen on my home network except on actual scam sites which isn’t a government thing but an ISP feature that can probably be turned off. This is a Vodaphone thing, not a UK thing. I don’t care that much about this specific site, I guess I just want to complain that they don’t have a way to report false positives which maybe isn’t the best reason to post a comment on an unrelated article but still
- Karellen 3y ago> Probably the xx in the domain. According to the `considered-18` post linked by a sibling comment: > It shows that this filter is for this specific host name only [daniel.haxx.se], not for the entire haxx.se domain. So, even more of a WTF.
- techwiz137 3y agoSomeone probably saw daniel, ha, xxx interpreted it "It's me Daniel, ha, this is my porn collection" and flagged it.
- jojobas 3y ago
- Dalewyn 3y ago>I just want to emphasize that if you install and run Windows, your friendly provider is Microsoft. You need to contact Microsoft for support and help with Windows related issues. Worth remembering this is only the case if you buy a retail license. If you cheaped out with an OEM license, you are your own customer support and Microsoft won't help you. If you bought a laptop or pre-made desktop, you have an OEM license provided to you by whoever manufactured your computer and they are your customer support; Microsoft won't help you.
- deleted 3y ago[deleted]
- nikanj 3y agoHonestly Microsoft doesn’t help you even if you paid directly. You might get lucky and have some forum volunteer give you a hand, but Microsoft will absolutely under no circumstances fix your PC
- nikanj 3y agoAntimalware is the worst malware I’ve seen in my decades-long career in IT.
- lloydatkinson 3y agoI use whatever Microsoft call their built in security this year, use ublock origin, and reinstall Windows about once a year. This seems to be the better alternative to having Norton/McCafe/<insert name of "security" program that uses more CPU than malware>.
- SSLy 3y agoESET NOD32 is still going to be lighter and more performant than any alternative, including Windows Defender. The latter includes big delay for small file access, even just metadata!
- rejectfinite 3y agoNessus is not "antimalware" It is a network scanner
- cduzz 3y agoIs there a windows equivalent of "chmod 0000 /file/to/be/made/unavailable" ? Even that seems pretty brutal but at least it's easily reversible if you discover that "oh I needed that to download the vendor patch that will _actually_ fix the problem"
- oneeyedpigeon 3y agoEven more low-tech: I can't believe people just hose the executable (and immediately empty their recycle bin?) rather than just renaming it.
- sumtechguy 3y agoReally depends on how windows put that curl.exe there in the first place. WinSxS would probably detect the damage and fix it. It is kind of how MS 'fixed' DLL hell. Windows really tries to stop that sort of thing. Also depending on how it was installed you may be able to get the windows installer subsystem that controls it to just uninstall it for you. Would just depend if it s part of another bundle or not. If you want to see how there are tons of vids on how people make stripped down windows installs. Also if you are stuck with this another way to fix it is to just run the file out of a different directory and/or rename your new one. Windows load hierarchy is local folder first, then path (which usually has system32 in there somewhere). But if you are dead set on your chmod method yes you could use calcs to do it. Add the executable permission to false. You prob would have to do that from a decently privlaged account. You probably could also do it from active directory using a group policy. A better way is to open a phone support ticket with MS if they are the ones installing it. Going onto their web support boards is usually basically a dead end. If you bought your PC from an OEM you can call them too then they can open a ticket with MS.
- jhoelzel 3y agoyes there is, you just need to right click the file and remove the privileges for system. I just did this for the "AsusComService" which would take 30% of my i9 13k simply because i have dns blocking running for it.
- Laaas 3y ago
- noxer 3y agoCMD > run as admin > enter "sfc /scannow" without quotes then update should work again. Next time anyone runs into a similar problem you might just want to zip the file before deleting it put a password if you AV still reports it. Or just get rid of your AV software it clearly su*ks if it reports legit system files.
- justeleblanc 3y agoAnd after that "DISM /Online /Cleanup-Image /RestoreHealth" to make sure everything is fine and dandy.
- rejectfinite 3y agoActually the reverse. Run DISM first, then SFC. https://support.microsoft.com/en-us/topic/use-the-system-file-checker-tool-to-repair-missing-or-corrupted-system-files-79aa86cb-ca52-166a-92a3-966e85d4094e https://support.microsoft.com/en-us/topic/use-the-system-fil... If you are running Windows 10, Windows 8.1 or Windows 8, first run the inbox Deployment Image Servicing and Management (DISM) tool prior to running the System File Checker. (If you are running Windows 7 or Windows Vista, skip to Step 3.)
- Jon_Lowtek 3y agoThe article doesn't mention an AV software, but a vulnerability assessment solution. Its purpose is to report known vulnerabilities and it would suck, if it did not report known vulnerabilities in system files out of fear of a downstream PEBKAC.
- yabones 3y agoOne of the very few times 'sfc /scannow' actually fixes something...
- ziml77 3y agoIf you are missing curl.exe, the System File Checker may be able to restore it. Worth giving sfc /scannow a shot.
- jeroenhd 3y agoSFC takes a while, so `sfc /scanfile=c:\windows\system32\curl.exe` may be more useful for people who encounter this specific problem.
- causality0 3y agothey cannot upgrade because the Windows update procedure detects that the Windows install has been tampered with and it refuses to continue. I'm surprised I've never heard of this before. In my experience you can almost hear Windows Update cackling with glee as it un-customizes your Windows install.
- foobarbecue 3y agoMoral of the story: answers.microsoft.com is the worst
- jeroenhd 3y agoEvery time I run into a Windows related problem I find an answers.microsoft.com post of someone with the exact problem I'm having and every time the thread runs dry after some Verified Super Duper Senior Adviser Technician Microsoft Windows Expert Professional says "have you tried reinstalling Windows 11". I don't know if you get forum points for suggesting wiping your drive or something but I've never seen a useful response from someone tagged as some kind of expert by answers.microsoft.com.
- lodonnell9213 3y agoOr have you tried disabling anti-virus...
- taskforcegemini 3y agothat actually is a solution to many problems though
- saw-lau 3y agoTIL that curl is installed in Windows 10 and 11 - useful article for that alone!
- taskforcegemini 3y agocurl on windows is my fallback to telnet (which is even less likely to be available on a clients windows computer) to quickly check connectivity and address resolution without having to install anything
- tssva 3y agoAnother one a lot of people don't realize ships with Windows 10 & 11 is tar. Specifically bsdtar which along with tar files can also create and extract zip files.
- deleted 3y ago[deleted]
- WirelessGigabit 3y agoI love the sneer towards the helpful voulonteers on the Microsoft forums. Hello, <name>, how are you? Good day! I'm <other name> a Windows user like you and I'll be happy to assist you today. I know this has been difficult for you, Rest assured, I'm going to do my best to help you Please do <giant copy paste including scf /scannnow and dism /something> If the problem still persists, please try to update using the Microsoft tool. Kindly let me know if this helps or if you have any further concerns. Sincerely, <other name> Independent Advisor Standard Disclaimer: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.
- mrguyorama 3y agoI'm of the opinion that answers.microsoft.com exists only to mislead and confuse people so they stop reporting issues. I have NEVER seen an actual answer on there, and have never seen an answer that wasn't just copy/pasted by a stranger from an irrelevant Microsoft knowledgebase article. It gets top SEO billing, and seems to be entirely unmoderated, or at least moderated by people who don't know anything about Windows. It's less informative than Quora. All this does is take all the air out of the room for an actual information source about Windows problems, and it's clearly ignored by Microsoft internal teams. Creating a "Support Forum" for your brand that never offers actual support should be fraud.