TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: What is in C-00000291*.sys?

129 pointsby franze10 months ago

19 comments

brettermeier10 months ago
Context: CrowdStrike (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41002195">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41002195</a>)
alex_f_k10 months ago
<a href="https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;112812260542179660" rel="nofollow">https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;112812260542179660</a><p>&gt; I&#x27;ve obtained copies of the .sys driver files Crowdstrike customers have. They&#x27;re garbage. Each customer appears to have a different one.<p><a href="https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;112812454405913406" rel="nofollow">https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;112812454405913406</a><p>&gt; The .sys files causing the issue are channel update files, they cause the top level CS driver to crash as they&#x27;re invalidly formatted. It&#x27;s unclear how&#x2F;why Crowdstrike delivered the files and I&#x27;d pause all Crowdstrikes updates temporarily until they can explain.
评论 #41005263 未加载
H8crilA10 months ago
The most successful malware of 2024, even though it only does denial of service.
评论 #41005570 未加载
评论 #41009383 未加载
评论 #41004753 未加载
lordnacho10 months ago
It&#x27;s a crowdstrike update file with a bug in it, from what I gather. This makes your Windows machine go blue screen and stop working as it starts up. If you manage to remove it by various methods, it doesn&#x27;t run and you&#x27;re fine.<p>More informed people will give you more details, but this kind of AV software often has privileged access to the OS, so it can scan your files. The same privileged access also means it can really mess things up if it&#x27;s not well tested.<p>By contrast your ordinary python or VBA script should not be able to blue screen your machine, especially not during startup.
评论 #41005857 未加载
评论 #41006977 未加载
benmmurphy10 months ago
A malware delivery platform sponsored by the US security state. All customers get customised versions nothing to see here.
commercialnix10 months ago
It provides the electrolytes Windows craves.
评论 #41005800 未加载
评论 #41006523 未加载
amarcheschi10 months ago
On another note, I know nothing about cybersec, is there a reason for which antivirus on windows run at ring 0 while I read that on Linux and Mac they don&#x27;t have kernel level access?
评论 #41005310 未加载
评论 #41004932 未加载
cobalt6010 months ago
<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41002195">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41002195</a>
ltadeut10 months ago
Does anyone understand what a channel file is? Some sort of patch&#x2F;dll that a driver loads?
评论 #41009551 未加载
novaRom10 months ago
Just kernel drivers. To know what is inside, you can disassemble them with <a href="https:&#x2F;&#x2F;github.com&#x2F;NationalSecurityAgency&#x2F;ghidra">https:&#x2F;&#x2F;github.com&#x2F;NationalSecurityAgency&#x2F;ghidra</a>
评论 #41005167 未加载
Conasg10 months ago
Specifically, if the file is corrupted, in what way is it corrupt? I’m fascinated by how this issue occurred.
评论 #41004974 未加载
评论 #41053054 未加载
评论 #41009550 未加载
评论 #41005042 未加载
AverageIdiot10 months ago
Hm, is there any website that explains why C-00000291*.sys caused the widespread BSODs? For example, was it some kind of definition file that was accessing invalid memory locations?
评论 #41008288 未加载
yert1410 months ago
New to IT, but this sure seems like a huge security risk. Even though the CEO and others have said otherwise. People who are more experienced, please let me know if I am wrong.
megvt0810 months ago
Does anyone have the actual file, I have a copy but it seems to be a good version unfortunately. Really appreciate if anyone can upload it here
screwgauge110 months ago
Can someone share a link to a copy of the offending channel file. Now a crowd strike customer, but interested in poking at its contents. Thanks!
Si1ent10 months ago
Does anyone have the BSoD dump file when it crashed? our a C-00000291-00000000-00000032.sys output de-identified ?
Si1ent10 months ago
Does anyone have the BSoD dump file our the C-00000291-00000000-00000001.sys de-identified to analyze both
neverminder10 months ago
Wouldn&#x27;t want to be the guy who pushed this particular commit. It&#x27;s ironic that the company that is supposed to prevent this sort of thing causes the biggest worldwide outage ever. Crowdstrike is finished. Let&#x27;s hope this will result in at least a small increase in desktop Linux market share.
评论 #41004982 未加载
评论 #41005032 未加载
评论 #41005064 未加载
评论 #41005040 未加载
评论 #41006691 未加载
评论 #41005883 未加载
评论 #41005374 未加载
评论 #41009571 未加载
rvba10 months ago
How is the * (star &#x2F; asterisk) character allowed in the file name?<p>I thought such characters are forbidden by Windows.<p><a href="https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;windows&#x2F;win32&#x2F;fileio&#x2F;naming-a-file" rel="nofollow">https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;windows&#x2F;win32&#x2F;fileio&#x2F;namin...</a><p>How did the tool even manage to create such a file?
评论 #41005242 未加载
评论 #41005021 未加载