12 ms·
One-Click RCE in Asus's Preinstalled Driver Software
- IshKebab 1y agoWow, no bug bounty is insane. No more ASUS products for me...
- swinglock 1y agoBoth Asus software and customer support is atrocious and always has been.
- dsab 1y agoWhich motherboard should I buy next time I will upgrade my PC? MSI, Asrock or Gigabyte?
- _pdp_ 1y agothey are a "small startup"
- charcircuit 1y agoThey have over 14500 employees. I wouldn't call that small.
- Gys 1y ago> I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. :(
- Xelbair 1y agono bug bounty, onto black market of exploit it goes. that or full public disclosure.
- LadyCailin 1y agoI wonder how worried they would get if more people actually started selling exploits on the black market, instead of reporting and not getting a bug bounty. If you don’t offer a bug bounty program in the first place, my gut feeling is that they probably wouldn’t care in that case either. Either way, this is a super good reason to not do business with such a company.
- Xelbair 1y agoif the fire it lit under them, after their software leads to widespread hack - they will care. that's the point - to put pressure on them to CARE.
- NooneAtAll3 1y agoI wonder if centralized "sell program vulnerabilities here" government shops can be set up While intelligence agencies are an obvious benefitiary, this would also give leverage of government over capital
- hypercube33 1y agoMaybe something for gamers Nexus to light a fire
- throaway920181 1y agoThis makes me never want to buy another ASUS product again.
- GuestFAUniverse 1y agoDoesn't surprise me. Their software sucks and security wise they are repeat offenders considering the lack of prevention. https://www.techspot.com/news/95425-years-gigabyte-asus-motherboards-carried-uefi-malware.html https://www.techspot.com/news/95425-years-gigabyte-asus-moth... https://www.reddit.com/r/ASUS/comments/tg3u2n/removing_bloatware/ https://www.reddit.com/r/ASUS/comments/tg3u2n/removing_bloat... https://www.reddit.com/r/ASUS/comments/ojsq80/nahimic_service_it_caused_a_lot_of_problems_with/ https://www.reddit.com/r/ASUS/comments/ojsq80/nahimic_servic...
- indrora 1y agoNot even the first of firsts; https://cve.mitre.org/data/board/archives/2016-06/msg00006.html https://cve.mitre.org/data/board/archives/2016-06/msg00006.h... (my old blog is long gone from tumblr, but I archived it:) https://gist.github.com/indrora/2ae05811a2625a6c5e69c677db6ea331 https://gist.github.com/indrora/2ae05811a2625a6c5e69c677db6e...
- nexoft 1y agoI've read Acer for some reason, and was surprise and disappointed it is actually Asus.
- thwaysec 1y ago[flagged]
- kenjackson 1y agoWhy is this not an RCE?
- thwaysec 1y ago[flagged]
- sitharus 1y agoI suggest you re-read the article carefully. The author shows that a website can be created that will make the asus software download and execute an attacker controlled app from a server the attacker controls.
- wonnage 1y agoDid you not see the PoC video?
- thwaysec 1y agoSeems I was wrong. I am utterly surprised at the lack of security in modern browsers. Yes, that backend is misconfigured, but why this request is even allowed to take place in the first place is utterly mindblowing to me.
- IlikeKitties 1y agoResponsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs are involved and a solution must be find in hours not month, they will become a lot more proactive. Of course it's the end users that would suffer most from this. But then again, they buy ASUS so they suffer already...
- okanat 1y agoCiting CGPGrey: Solutions that are the first thing you can think of are terrible and ineffective. Good safety/security culture encourages players to not hide their problems. Corporations are greedy bastards. They'll do everything to hide their security mistakes. You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot.
- IlikeKitties 1y ago> You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot. I don't think you can fathom the amount of people that have phones with roughly 3 years of no android updates as their primary device with which they use all the digital services they use, Banking, Texting, Doomscrolling, Porn, ... Users, especially the most likely to be exploited are already vulnerable to so much shit and even when there's a literal finished fix available, these vendors do shit about it. Only when their bottomline is threatened because even my mom knows "Don't buy anything with ASUS on it, your bank account gets broken into if you do" will we see change.
- einsteinx2 1y agoI’m not sure that’s a great example as they would be vulnerable to many responsibly disclosed and previously fixed issues anyway since they never update. In fact they would be just as vulnerable to any new responsibly disclosed issues as they would if they were immediately “irresponsibly” disclosed because again, they never update anyway.
- sigmaisaletter 1y agoObligatory "Scumbag Asus" video link: Invidious https://inv.nadeko.net/watch?v=cbGfc-JBxlY https://inv.nadeko.net/watch?v=cbGfc-JBxlY YouTube https://youtube.com/watch?v=cbGfc-JBxlY https://youtube.com/watch?v=cbGfc-JBxlY "ASUS emailed us last week (...) and asked if they could fly out to our office this week to meet with us about the issues and speak "openly." We told them we'd be down for it but that we'd have to record the conversation. They did say they wanted to speak openly, after all. They haven't replied to us for 5 days. So... ASUS had a chance to correct this. We were holding the video to afford that opportunity. But as soon as we said "sure, but we're filming it because we want a record of what's promised," we get silence." Edit: formatting
- Barbing 1y agoThis makes me angry, so can anyone think of a legitimate steelman of their position? Expect my view is consistent with reality, though: they’re chasing profits and getting away with it, so why go on the record and look bad if they can ignore & spend that time on marketing.
- vachina 1y agoASUS doesn’t want to deal with the social media horde, who can and will cherry pick words and take things out of context. If a person comes to talk business with a camera attached to his head, I know he does not come in good faith.
- sigmaisaletter 1y agoIt's a journalist coming, because you said you want to talk to the journalist, because of the bad press you had before, because you fucked up. Seems fair to take a camera.
- jeffparsons 1y agoSo are there any "basically respectable" motherboard manufacturers? Or is there a similar story about each of the big players? Asking for a friend who is thinking about building a new PC soon.
- antmldr 1y ago>so I could see if anyone else had a domain with driverhub.asus.com.* registered. From looking at other websites certificate transparency logs, I could see that domains and subdomains would appear in the logs usually within a month. After a month of waiting I am happy to say that my test domain is the only website that fits the regex, meaning it is unlikely that this was being actively exploited prior to my reporting of it. This only remains true in so far as no-one directly registered for a driverhub subdomain. Anyone with a wildcard could have exploited this, silent to certificate transparency?
- ZoneZealot 1y agoA wildcard certificate is only for a single label level, '*.example.com.' would not allow 'test.test.example.com.', but would allow 'test.example.com.'. If someone issued a wildcard for '*.asus.com.example.com.', then could present a webserver under 'driverhub.asus.com.example.com.' and be seen as valid.
- throaway920181 1y agoYes... I believe you've successfully reworded what your comment's parent said.
- ZoneZealot 1y agoParent comment is making a point that it might have been possible for an attacker to avoid discovery via certificate transparency logs, because anyone 'with a wildcard' could pull off the attack, which is not correct. I'm pointing out that a wildcard at the apex of your domain (which is what basically everyone means when saying 'a wildcard'), would not work for this attack. Instead if you were to perform the attack using a wildcard certificate, it would need to be issued for '*.asus.com.example.com.' - which would certainly be obvious in certificate transparency logs.
- smileybarry 1y agoCan you still publicly apply for a “*.*.mydomain.com” certificate? IIRC a wildcard cert starting with “*.*.” allows you to chain 2+ names with that cert, I think? (E.g.: “*.*.example.com” cert would match “hello.world.and.hi.com.example.com”)
- satyanash 1y ago> MY ONBOARD WIFI STILL DOESN’T WORK, I had to buy an external USB WiFi adapter. Thanks for nothing DriverHub. All this, for literally nought
- ThrowawayTestr 1y agoThe latest wifi drivers don't work, you have to use an older version.
- Avamander 1y agoIt's a nice blogpost though.
- ikekkdcjkfke 1y agoAll our motherboards, the root of trust, are made in Taiwan. All props to their industriousnes and agility but there should be western alterntive in that can be purchased?
- liendolucas 1y ago> This is understandable since ASUS is just a small startup. A small startup with a marketcap of only 15 B. What is more than understandable is that you give a shit not only about your crappy products but the researcher that did a HUGE work for your customers. I truly feel bad for researchers doing this kind of work only to get them dismissed/trashed like this. So unfair. The only thing that is ought to be done is not to purchase ASUS products.
- Gerjek 1y ago[dead]
- Avamander 1y agoA few of the drivers they install (or want to install) are also on Microsoft's vulnerable actively exploited driver blacklist. So that's fun, they have no intention of fixing it because they do not support "third party software". I'm also pretty sure their installer doesn't work without unencrypted HTTP traffic being let through. Plus they keep offering bloatware as "updates" to you. On top of it all, the software they offer is slow and buggy on brand-new hardware. But most of those issues also exist with AMD's or Gigabyte's drivers, most hardware vendors seem trashy like that. Like, if you install Samsung Magician (for their SSDs) then that even asks you if you're in the EEA (because of the privacy laws I suspect), it's absolutely crazy. Microsoft should make it *significantly* harder to ship drivers outside of Windows Update and they should forbid any telemetry/analytics without consent. I find Linux's hardware support model significantly nicer, although some rarer things do not work OOB, there's none of this bullshit.
- matheusmoreira 1y agoHardware manufacturers consistently ship out the worst softwares in existence. It's just a cost center to them. They've already sold the thing, it doesn't matter anymore. My laptop has a fan and keyboard LED application that requires kernel access and takes over a minute to display a window on screen. Not to mention being Windows only. Words can barely describe just how aggravating that thing was. One of the best things I've ever done is reverse engineer that piece of crap and create a Linux free software replacement. Mine works instantly, I just feed it a configuration file. I intend to do this for every piece of hardware I buy from now on.
- Avamander 1y agoI really wish someone made such software for ASUS and Gigabyte both, without dangerous kernel drivers. In that sense fwupd has been an amazing development, as there's now a chance that you can update the firmware of your hardware on Linux and don't have to boot Windows.
- matheusmoreira 1y ago
- cebert 1y agoI am assuming the timeline posted in this article is a year off, and the author means 2024 instead of 2025.
- psolidgold 1y agoWhy would you assume that instead of the more likely scenario of them using DD/MM/YYYY format? The CVE linked has a date in 2025. Not everyone uses the insane American date formatting.
- cobalt60 1y agoMY ONBOARD WIFI STILL DOESN’T WORK, I had to buy an external USB WiFi adapter. Thanks for nothing DriverHub. I feel sorry for this guy, having deviated from the original issue. Though it'd only took a couple of seconds to note the WLAN chipset from specs or OEM packaging and then heading to station-drivers. This was also the very reason I dislike Asus, I don't want a BIOS flag/switch that natively interact with a component in OS layer.
- rkagerer 1y agoI asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup[1] and likely does not have the capital to pay a bounty. [1]: https://companiesmarketcap.com/asus/marketcap/ https://companiesmarketcap.com/asus/marketcap/
- 93po 1y agoalternatively, sarcasm.com ;)
- lucb1e 1y agoI'm surprised to find that this is just a random person's blog. Was very prepared for an ad page, scalped domain, or some corporation trying to make money out of it. On the sadder side, it doesn't seem like this person makes any use of the domain's name at all; they could have had firstlast.cctld for their blog and given this to someone who wants to put a sarcastic joke on it. But better this than ad farms so I don't blame them for keeping it!
- ritcgab 1y agoThis is really a well written blog post. The practice of "injecting pre-installed software through BIOS" is such a deal-breaker. Unfortunately this seems to be widely adopted by the major players in motherboard market.
- josephcsible 1y ago> When submitting the vulnerability report through ASUS’s Security Advisory form, Amazon CloudFront flagged the attached PoC as a malicious request and blocked the submission. Reminder that WAFs are an anti-pattern: https://thedailywtf.com/articles/Injection_Rejection https://thedailywtf.com/articles/Injection_Rejection
- smileybarry 1y agoI like ASUS products but I disable the UEFI-installed support app every single time. IIRC it used to be a full ROG Armory Crate installation, which is really annoying to uninstall. When ASUS acquired the NUC business from Intel, they kept BIOS updates going but at some point a “MyASUS” setup app got added to the UEFI like with their other motherboards. Thankfully, it also had an option to disable and IIRC it defaults to disabled, at least if you updated the BIOS from an Intel NUC version.
- serguzest 1y agoIt is not just a mainboard issue. I had an asus mechanical keyboard. After I started using it, Windows kept installing software and background services in system that is a listening port. I kept deleted it manually and no matter I did, windows kept installing it without my consent. It was really annoying.
- rasz 1y ago> When submitting the vulnerability report through ASUS’s Security Advisory form, Amazon CloudFront flagged the attached PoC as a malicious request and blocked the submission. Reminds me of the time I reported SQL disclosure vuln to Vivaldi and their WAF banned my account for - wait for it - 'SQL injection attempt' so hard their admin was unable to unlock it :)
- saghm 1y agoI have a similar model motherboard from ASUS in my desktop I had custom built a few years ago, and I've mostly just been annoyed that I have to have Windows installed to be able to even update the BIOS at all given that the previous one I had (which I think was also from them?) would just let me do it over ethernet if I booted directly into the BIOS setup menu. Now I have much larger concerns in addition to the risk of not updating as frequently seeming much larger...
- Arnavion 1y agoAny mobo will let you download the firmware file to a FAT32-formatted USB drive etc, and then use that to update the UEFI within the UEFI UI. Yes some mobos have the feature in their UEFI to connect to the internet and download the update, but it's best to not rely on that since you have no idea how securely that is implemented. Considering how the submitted article is about a shitty implementation in a regular Windows program, you can be sure the implementation in UEFI is even shittier (may not check certs, may not even use HTTPS, etc). Asrock used to have an "Internet Flash" feature in their UEFI and then suddenly removed it, probably because it was too insecure to fix.
- saghm 1y ago> Considering how the submitted article is about a shitty implementation in a regular Windows program, you can be sure the implementation in UEFI is even shittier (may not check certs, may not even use HTTPS, etc) I don't think it's fair to conflate the security of perpetually running daemon that allows arbitrary instructions from remote endpoints with a manual download that's only initiated in very specific circumstances. Yes, it would be bad not to check certs or use HTTPS, but I'm not sure I buy that this would be "too insecure to fix" compared to trying to allow something to remotely push updates that I never asked for. You don't have to accept that my threat model where I've decided that I'm willing to risk one manually-initiated request that might be somewhat unsafe every few months or so is worth it, but I don't see how you can argue that it's somehow _more_ dangerous than the version that runs continuously at all times and doesn't require any input from me.
- sebstefan 1y ago>DriverHub only responded to requests with the origin header set to “driverhub.asus.com”. So at least this software wasn’t completely busted and evil hackers can’t just send requests to DriverHub willy-nilly. >When I switched the origin to driverhub.asus.com.mrbruh.com, it allowed my request. One more CVE to developers validating URLs in some silly way Your language comes with a URL parser. Use it! You can't handle all the edge cases of the URL format by yourself. if ((new URL("https://user:password@driverhub.asus.com/whatever?q=whatever#whatever")).hostname === "driverhub.asus.com") { ... }
- notorandit 1y ago> This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. ASUS is not a small startup. It simply and only minds the money they suck FROM customers. There is no other way around to push money TO customers. But the real point is: how much would be worth selling such an exploit to a malicious agent? Likely more than USD 0.00. But then again, ASUS doesn't mind about that. Sad truth.
- MrBruh 1y agoOn the black market such an exploit would be worth 200-500k USD
- tuetuopay 1y agoI still don't understand why vendors like Asus bother developing their own (crappy) driver installation tool. It's always bad, takes developer resources, for something that's handled way better by Windows Update. The cynical me imagines juicy telemetry to sell to advertisers. The realist me imagines time gains by not needing to go through Microsoft's driver update validation process (like companies keep linux drivers out-of-tree to not cleanup their code). It's probably both.