3 ms·
This reminds me of the vulnerability that hit jwt tokens a few years ago, when you could set the 'alg' to 'none'. Surely CrowdStrike encrypts and signs their c
by calrain 2y ago
This reminds me of the vulnerability that hit jwt tokens a few years ago, when you could set the 'alg' to 'none'.
Surely CrowdStrike encrypts and signs their channel files, and I'm wondering if a file full of 0's inadvertently signaled to the validating software than a 'null' or 'none' encryption algo was being used.
This could imply the file full of zeros is just fine, as the null encryption passes, because it's not encrypted.
That could explain why it tried to reference the null memory location, because the null encryption file full of zeroes just forced it to run to memory location zero.
The risk is, if this is true, then their channel loading verification system is critically exposed by being able to load malicious channel drivers through disabled encryption on channel files.
Just a hunch.
- kachapopopow 2y agoThat was the first thing I thought about when I started analyzing this file.