38 ms·
If CrowdStrike's system wasn't able to prevent a kernel driver thats all zeros from getting by, you can be sure a malicious payload would have breezed right thr
by cdchn 2y ago
If CrowdStrike's system wasn't able to prevent a kernel driver thats all zeros from getting by, you can be sure a malicious payload would have breezed right through.
- chrisoverzero 2y agoIt wasn’t a driver.
- therein 2y agoOh yeah, at a quick glance looks like that file could have had any payload and it would have been loaded right into the kernel.
- saagarjha 2y agoWhat makes you think so?
- therein 2y agoEarlier there were some screenshots showing an entirely zero-filled .sys file but now we know that's not what the payload was.
- echoangle 2y agoTo send a malicious payload into the kernel, you would have to take over crowdstrikes deploy infrastructure first, right? I hope the program doesn’t just accept updates from anywhere