4 ms·
If CrowdStrike's system wasn't able to prevent a kernel driver thats all zeros from getting by, you can be sure a malicious payload would have breezed right thr
by cdchn 2y ago
If CrowdStrike's system wasn't able to prevent a kernel driver thats all zeros from getting by, you can be sure a malicious payload would have breezed right through.
There was no validation, phased roll-outs, almost certain no multi-person verification. I'd bet dollars to donuts this was pushed out by a low/mid-level functionary that could be carried out by dozens if not hundreds of employees. There may have not been a security breach, but it was still one minor security breach, distracted open laptop in a cafe, or disgruntled/paid-off inside actor away from absolute armageddon.
It wasn't an attack, but it was a raccoon who came in through an unlocked screen door in the back of Fort Knox.
If someone had used this to deliver a ransomeware package, they'd be buying a mega-yacht right now.
- saagarjha 2y agoIt’s not a driver, but a configuration file.
- cdchn 2y agoSources I've seen was that there was a .SYS file with all zeros that caused the BSOD. A configuration file shouldn't cause a bluescreen. EDIT: It is in the 'drivers' directory, has a .SYS extension, but was something called a "channel file" but I couldn't get much info on what a channel file does other than "something something named pipes"
- smileybarry 2y agoIt's a ".sys" file but it's not a driver binary at all. It's a binary configuration file, and from what I gather it's a sort-of packed table. The actual kernel driver mounts it, parses the contents, and uses it as configuration. The ".sys" extension is probably for the believability of being a driver so users would leave it alone.