TE
TechEcho
StartseiteTop 24hNeuesteBesteFragenZeigenJobs
GitHubTwitter
Startseite

TechEcho

Eine mit Next.js erstellte Technologie-Nachrichtenplattform, die globale Technologienachrichten und Diskussionen bietet.

GitHubTwitter

Startseite

StartseiteNeuesteBesteFragenZeigenJobs

Ressourcen

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. Alle Rechte vorbehalten.

One-Click RCE in Asus's Preinstalled Driver Software

502 Punktevon MrBruhvor 2 Tagen

23 comments

IlikeKittiesvor 1 Tag
Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs are involved and a solution must be find in hours not month, they will become a lot more proactive. Of course it's the end users that would suffer most from this. But then again, they buy ASUS so they suffer already...
评论 #43953220 未加载
评论 #43952444 未加载
评论 #43952585 未加载
评论 #43952403 未加载
评论 #43952959 未加载
评论 #43953183 未加载
评论 #43957675 未加载
评论 #43954076 未加载
评论 #43952758 未加载
评论 #43955767 未加载
评论 #43962299 未加载
Gysvor 1 Tag
&gt; I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty.<p>:(
评论 #43952600 未加载
评论 #43952523 未加载
评论 #43959294 未加载
评论 #43952584 未加载
GuestFAUniversevor 1 Tag
Doesn&#x27;t surprise me. Their software sucks and security wise they are repeat offenders considering the lack of prevention.<p><a href="https:&#x2F;&#x2F;www.techspot.com&#x2F;news&#x2F;95425-years-gigabyte-asus-motherboards-carried-uefi-malware.html" rel="nofollow">https:&#x2F;&#x2F;www.techspot.com&#x2F;news&#x2F;95425-years-gigabyte-asus-moth...</a><p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ASUS&#x2F;comments&#x2F;tg3u2n&#x2F;removing_bloatware&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ASUS&#x2F;comments&#x2F;tg3u2n&#x2F;removing_bloat...</a><p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ASUS&#x2F;comments&#x2F;ojsq80&#x2F;nahimic_service_it_caused_a_lot_of_problems_with&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ASUS&#x2F;comments&#x2F;ojsq80&#x2F;nahimic_servic...</a>
评论 #43952414 未加载
antmldrvor 1 Tag
&gt;so I could see if anyone else had a domain with driverhub.asus.com.* registered. From looking at other websites certificate transparency logs, I could see that domains and subdomains would appear in the logs usually within a month. After a month of waiting I am happy to say that my test domain is the only website that fits the regex, meaning it is unlikely that this was being actively exploited prior to my reporting of it.<p>This only remains true in so far as no-one directly registered for a driverhub subdomain. Anyone with a wildcard could have exploited this, silent to certificate transparency?
评论 #43952423 未加载
评论 #43952619 未加载
评论 #43952527 未加载
评论 #43959413 未加载
satyanashvor 1 Tag
&gt; MY ONBOARD WIFI STILL DOESN’T WORK, I had to buy an external USB WiFi adapter. Thanks for nothing DriverHub.<p>All this, for literally nought
评论 #43953089 未加载
评论 #43952883 未加载
josephcsiblevor 1 Tag
&gt; When submitting the vulnerability report through ASUS’s Security Advisory form, Amazon CloudFront flagged the attached PoC as a malicious request and blocked the submission.<p>Reminder that WAFs are an anti-pattern: <a href="https:&#x2F;&#x2F;thedailywtf.com&#x2F;articles&#x2F;Injection_Rejection" rel="nofollow">https:&#x2F;&#x2F;thedailywtf.com&#x2F;articles&#x2F;Injection_Rejection</a>
liendolucasvor 1 Tag
&gt; This is understandable since ASUS is just a small startup.<p>A small startup with a marketcap of only 15 B. What is more than understandable is that you give a shit not only about your crappy products but the researcher that did a HUGE work for your customers.<p>I truly feel bad for researchers doing this kind of work only to get them dismissed&#x2F;trashed like this. So unfair.<p>The only thing that is ought to be done is not to purchase ASUS products.
sebstefanvor etwa 14 Stunden
&gt;DriverHub only responded to requests with the origin header set to “driverhub.asus.com”. So at least this software wasn’t completely busted and evil hackers can’t just send requests to DriverHub willy-nilly.<p>&gt;When I switched the origin to driverhub.asus.com.mrbruh.com, it allowed my request.<p>One more CVE to developers validating URLs in some silly way<p>Your language comes with a URL parser. Use it! You can&#x27;t handle all the edge cases of the URL format by yourself.<p><pre><code> if ((new URL(&quot;https:&#x2F;&#x2F;user:password@driverhub.asus.com&#x2F;whatever?q=whatever#whatever&quot;)).hostname === &quot;driverhub.asus.com&quot;) { ... }</code></pre>
rkagerervor 1 Tag
<i>I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup[1] and likely does not have the capital to pay a bounty.</i><p>[1]: <a href="https:&#x2F;&#x2F;companiesmarketcap.com&#x2F;asus&#x2F;marketcap&#x2F;" rel="nofollow">https:&#x2F;&#x2F;companiesmarketcap.com&#x2F;asus&#x2F;marketcap&#x2F;</a>
评论 #43956148 未加载
notoranditvor etwa 14 Stunden
&gt; This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty.<p>ASUS is not a small startup. It simply and only minds the money they suck FROM customers. There is no other way around to push money TO customers.<p>But the real point is: how much would be worth selling such an exploit to a malicious agent? Likely more than USD 0.00.<p>But then again, ASUS doesn&#x27;t mind about that. Sad truth.
tuetuopayvor etwa 10 Stunden
I still don&#x27;t understand why vendors like Asus bother developing their own (crappy) driver installation tool. It&#x27;s always bad, takes developer resources, for something that&#x27;s handled way better by Windows Update.<p>The cynical me imagines juicy telemetry to sell to advertisers.<p>The realist me imagines time gains by not needing to go through Microsoft&#x27;s driver update validation process (like companies keep linux drivers out-of-tree to not cleanup their code).<p>It&#x27;s probably both.
sigmaisalettervor 1 Tag
Obligatory &quot;Scumbag Asus&quot; video link:<p>Invidious <a href="https:&#x2F;&#x2F;inv.nadeko.net&#x2F;watch?v=cbGfc-JBxlY" rel="nofollow">https:&#x2F;&#x2F;inv.nadeko.net&#x2F;watch?v=cbGfc-JBxlY</a><p>YouTube <a href="https:&#x2F;&#x2F;youtube.com&#x2F;watch?v=cbGfc-JBxlY" rel="nofollow">https:&#x2F;&#x2F;youtube.com&#x2F;watch?v=cbGfc-JBxlY</a><p>&quot;ASUS emailed us last week (...) and asked if they could fly out to our office this week to meet with us about the issues and speak &quot;openly.&quot; We told them we&#x27;d be down for it but that we&#x27;d have to record the conversation. They did say they wanted to speak openly, after all. They haven&#x27;t replied to us for 5 days. So... ASUS had a chance to correct this. We were holding the video to afford that opportunity. But as soon as we said &quot;sure, but we&#x27;re filming it because we want a record of what&#x27;s promised,&quot; we get silence.&quot;<p>Edit: formatting
评论 #43952762 未加载
评论 #43952381 未加载
IshKebabvor 2 Tagen
Wow, no bug bounty is insane. No more ASUS products for me...
评论 #43952184 未加载
评论 #43952166 未加载
cobalt60vor 1 Tag
<i>MY ONBOARD WIFI STILL DOESN’T WORK, I had to buy an external USB WiFi adapter. Thanks for nothing DriverHub.</i><p>I feel sorry for this guy, having deviated from the original issue. Though it&#x27;d only took a couple of seconds to note the WLAN chipset from specs or OEM packaging and then heading to station-drivers.<p>This was also the very reason I dislike Asus, I don&#x27;t want a BIOS flag&#x2F;switch that natively interact with a component in OS layer.
Avamandervor 1 Tag
A few of the drivers they install (or want to install) are also on Microsoft&#x27;s vulnerable actively exploited driver blacklist. So that&#x27;s fun, they have no intention of fixing it because they do not support &quot;third party software&quot;. I&#x27;m also pretty sure their installer doesn&#x27;t work without unencrypted HTTP traffic being let through. Plus they keep offering bloatware as &quot;updates&quot; to you.<p>On top of it all, the software they offer is slow and buggy on brand-new hardware.<p>But most of those issues also exist with AMD&#x27;s or Gigabyte&#x27;s drivers, most hardware vendors seem trashy like that. Like, if you install Samsung Magician (for their SSDs) then that even asks you if you&#x27;re in the EEA (because of the privacy laws I suspect), it&#x27;s absolutely crazy.<p>Microsoft should make it *significantly* harder to ship drivers outside of Windows Update and they should forbid any telemetry&#x2F;analytics without consent.<p>I find Linux&#x27;s hardware support model significantly nicer, although some rarer things do not work OOB, there&#x27;s none of this bullshit.
评论 #43954112 未加载
评论 #43953642 未加载
评论 #43959047 未加载
ritcgabvor 1 Tag
This is really a well written blog post.<p>The practice of &quot;injecting pre-installed software through BIOS&quot; is such a deal-breaker. Unfortunately this seems to be widely adopted by the major players in motherboard market.
smileybarryvor 1 Tag
I like ASUS products but I disable the UEFI-installed support app <i>every single time</i>. IIRC it used to be a full ROG Armory Crate installation, which is really annoying to uninstall.<p>When ASUS acquired the NUC business from Intel, they kept BIOS updates going but at some point a “MyASUS” setup app got added to the UEFI like with their other motherboards. Thankfully, it also had an option to disable and IIRC it defaults to disabled, at least if you updated the BIOS from an Intel NUC version.
saghmvor 1 Tag
I have a similar model motherboard from ASUS in my desktop I had custom built a few years ago, and I&#x27;ve mostly just been annoyed that I have to have Windows installed to be able to even update the BIOS at all given that the previous one I had (which I think was also from them?) would just let me do it over ethernet if I booted directly into the BIOS setup menu. Now I have much larger concerns in addition to the risk of not updating as frequently seeming much larger...
评论 #43959609 未加载
cebertvor 1 Tag
I am assuming the timeline posted in this article is a year off, and the author means 2024 instead of 2025.
评论 #43955060 未加载
raszvor 1 Tag
&gt; When submitting the vulnerability report through ASUS’s Security Advisory form, Amazon CloudFront flagged the attached PoC as a malicious request and blocked the submission.<p>Reminds me of the time I reported SQL disclosure vuln to Vivaldi and their WAF banned my account for - wait for it - &#x27;SQL injection attempt&#x27; so hard their admin was unable to unlock it :)
serguzestvor 1 Tag
It is not just a mainboard issue. I had an asus mechanical keyboard. After I started using it, Windows kept installing software and background services in system that is a listening port. I kept deleted it manually and no matter I did, windows kept installing it without my consent. It was really annoying.
nexoftvor 1 Tag
I&#x27;ve read <i>Acer</i> for some reason, and was surprise and disappointed it is actually <i>Asus</i>.
ikekkdcjkfkevor 1 Tag
All our motherboards, the root of trust, are made in Taiwan. All props to their industriousnes and agility but there should be western alterntive in that can be purchased?