Skip to content

One-Click RCE in ASUS's Preinstalled Driver Software

Technology
9 8 55
  • 948 Stimmen
    85 Beiträge
    526 Aufrufe
    L
    Yeah this thread ended up being more hostile to regular Americans than I intended but US culture and US global hegemony are the things that attract and amplify the shitty people from around the world. USA is the final boss of capitalist imperialism and the people have completely lost control over the reins. It's now a matter of when they actually say enough is enough, be it now or after Fascism runs its course and hurts millions of others around the world as well.
  • 0 Stimmen
    1 Beiträge
    12 Aufrufe
    Niemand hat geantwortet
  • Canalys: Companies limit genAI use due to unclear costs

    Technology technology
    8
    1
    25 Stimmen
    8 Beiträge
    46 Aufrufe
    B
    Just wait until all the venture capital OpenAi raised on a valuation that assumes they will singlehandedly achieve the singularity in 2027, replace all human workers by 2028, and convert 75% of the Earth's crust to paperclips by 2030 runs out, they can't operate at a loss anymore, and have to raises prices to a point where they're actually making a profit.
  • Adaptive Keyboards & Writing Technologies For One-Handed Users

    Technology technology
    5
    1
    111 Stimmen
    5 Beiträge
    37 Aufrufe
    T
    Came here to say this.
  • Matrix.org is Introducing Premium Accounts

    Technology technology
    110
    1
    225 Stimmen
    110 Beiträge
    546 Aufrufe
    F
    It's nice that this exists, but even for this I'd prefer to use an open source tool. And it of course helps with migration only if the old HS is still online.. I think most practically this migration function would be built inside some Matrix client (one that would support more than one server to start with), but I suppose a standalone tool would be a decent solution as well.
  • 179 Stimmen
    13 Beiträge
    72 Aufrufe
    S
    I will be there. I will be armed. I will carry a gas mask. I will carry water and medical for my compatriots. I will not start shit. I will fight back if it comes to it.
  • UK government withholding details of Palantir contract

    Technology technology
    3
    1
    15 Stimmen
    3 Beiträge
    24 Aufrufe
    T
    Of all the partners you could have picked. Eek.
  • 1 Stimmen
    8 Beiträge
    40 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.