5 ms·
The scarier thought I've had -- if a black hat had discovered this crash case, could it have been turned into a widely deployed code execution vulnerability?
by Fr0styMatt88 2y ago
The scarier thought I've had -- if a black hat had discovered this crash case, could it have been turned into a widely deployed code execution vulnerability?
- MBCook 2y agoI had that same one. If loading a file crashed the kernel module, could it have been exploitable? Or was there a different exploitable bug in there? Did any nation states/other groups have 0-days on this? Did this event reveal something known to the public, or did this screw up accidentally protect us from someone finding + exploiting this in the future?
- plorkyeran 2y agoShockingly it turns out that installing a rootkit can have some negative security implications.
- llm_trw 2y agoTrying to explain to execs that giving someone root access to your computers means they have root access to your computers is surprisingly difficult.
- tonetegeatinst 2y agoI mean kernal level access does provide feature not accessible in userspace. Is it alsooverused when other solutions exist, you bet. Most people don't need this stuff. Just keeping shit up to date, no not on the nightly build branch, but like installing windows update atleast a day or two after they come out. Or maby regular antivirus scans. But let's be honest, your kernal drivers are useless if your employees fall for phishing or social engineering. See then its not malware, its an authorized user on the system....just copying data onto a USB drive or a rouge employee taking your customer list to your competition. That fancy pants kernal driver might be really good at stopping sophisticated threats and I'm sure the marketing majors at any company cram products full of buzz words. But remember, you can't fix incompetent or malicious employees unless your taking steps to prevent it. What's more likely: some foreign government hacking khols? Or a script kiddie social engineers some poor worker pretending to be the support desk? Not here to shit on this product, it has its place and it obviously does a good job....(heard its expensive but most xrd/edr is) Seems like we are learning how vulnerable certain things are once again. As a fellow security fellow, I must say that Jia Tan must be so envious that he couldn't have this level of market impact.
- rdtsc 2y agoStart a story for them: "and then, the hackers managed to install a rootkit which runs in kernel mode. The rootkit has sophisticated C2 mechanism with configuration files pretending to be drivers suffixed with .sys extensions. And then, they used that to prevent hospitals and 911 systems around the world from working, resulting in delayed emergency responses, injuries, possibly deaths". After they cuss the hackers under their breath exclaiming something like: "they should be locked up in jail for the rest of their lives!...", tell them that's exactly what happened, but CS were the hackers, and maybe they should reconsider mandating installing that crap everywhere.
- deleted 2y ago[deleted]
- naveen99 2y agoThe hard part is the deploying. Yes if you can get control of the crowdstrike deployment machinery, you can do whatever you want on hundreds of millions of machines. but you don’t need any vulnerabilities in the crowdstrike deployed software for that only the deploying servers.
- tranceylc 2y agoCall me crazy but that is a real worry for me, and has been for a while. How long until we see some large corporate software have their deployment process hijacked, and have it affect a ton of computers that auto-update?
- spydum 2y agoI mean, isn't that roughly the solarwinds story? There is no real shortage of supply chain incidents in the last few years. The reality is we are all mostly okay with that tradeoff.
- jen20 2y agoAround -4 years? [1] [1]: https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach https://en.wikipedia.org/wiki/2020_United_States_federal_gov...
- alsodumb 2y agoYou mean like the SolarWinds hack that happened a lil while ago? https://www.techtarget.com/whatis/feature/SolarWinds-hack-explained-Everything-you-need-to-know https://www.techtarget.com/whatis/feature/SolarWinds-hack-ex...
- btown 2y agoOne of the most dangerous versions of this IMO is someone who compromises a NPM/Pypi package that's widely used as a dependency. If you can make it so that the original developer doesn't know you've compromised their accounts (spear-phished SIM swap + email compromise while the target is traveling, for instance, or simply compromising the developer themselves), you don't need every downstream user to manually update - you just need enough projects that aren't properly configured with lockfiles, and you've got code execution on a huge number of servers. I'm hopeful that the fallout from Crowdstrike will be a larger emphasis on software BOM risk - when your systems regularly phone home for updates, you're at the mercy of the weakest link in that chain, and that applies to CI/CD and end user devices alike.
- Murky3515 2y agoProbably would've been use to mine bitcoin before it was patched
- deleted 2y ago[deleted]
- phire 2y agoNo. To trigger the crash, you need to write a bad file into C:\Windows\System32\drivers\CrowdStrike\ You need Administrator permissions to write a file there, which means you already have code execution permissions, and don't need an exploit. The only people who can trigger it over network are CrowdStrike themselves... Or a malicious entity inside their system who controls both their update signing keys, and the update endpoint.
- cyrnel 2y agoAnyone know if the updates use outbound HTTPS requests? If so, those companies that have crappy TLS terminating outbound proxies are looking juicy. And if they aren't pinning certs or using CAA, I'm sure a $5 wrench[1] could convince one of the lesser certificate authorities to sign a cert for whatever domain they're using. [1]: https://xkcd.com/538/ https://xkcd.com/538/
- phire 2y agoThe update files are almost certainly signed. Even if the HTTPS channel is compromised with a man-in-the-middle attack, the attacker shouldn't be able to craft a valid update, unless they also compromised CrowdStrke's keys. However, the fact that this update apparently managed to bypass any internal testing or staging release channels makes me question how good CrowdStrike's procedures are about securing those update keys.
- cyrnel 2y agoDepends when/how the signature is checked. I could imagine a signature being embedded in the file itself, or the file could be partially parsed before the signature is checked. It's wild to me that it's so normal to install software like this on critical infrastructure, but questions about how they do code signing is a closely guarded/obfuscated secret.
- jmb99 2y agoKind of a side talent, but I’m currently (begrudgingly) working on a project with a Fortune 20 company that involves a complicated mess of PKI management, custom (read: non-standard) certificates, a variety of management/logging/debugging keys, and (critically) code signing. It’s taken me months of pulling teeth just to get details about the hierarchy and how the PKI is supposed to work from my own coworkers in a different department (who are in charge of the project), let alone from the client. I still have absolutely 0 idea how they perform code signing, how it’s validated, or how I can test that the non-standard certificates can validate this black-hole-box code signing process. So yeah, companies really don’t like sharing details about code signing.
- deleted 2y ago[deleted]