Notings of Attention™
Acmlmboard 2 Released
Github/GIT | @acmlmboard
Chatting Places
Discord

Affiliates
Super Mario Bros. X | Kuribo64 | NeoRHDN
Views: 12,246,485
Main | FAQ | IRC chat | Memberlist | Active users | Latest posts | Stats | Ranks | Online users | Search
04-03-25 09:13 AM
Guest: Register | Login

0 users currently in msg db 'Computer Address',0xa | 2 bots

Main - msg db 'Computer Address',0xa - ASUS LiveUpdate MitM exploit
Next newer thread | Next older thread


Arisotura
Posted on 06-05-16 03:51 PM, in Link | ID: 90426
Developer
pancakes
Level: 84


Posts: 1014/1870
EXP: 5623891
Next: 38061

Since: 01-05-12
From: France

Last post: 170 days
Last view: 170 days
source


ASUS LiveUpdate is one of ASUS' preinstalled bloatware programs, that updates shit like BIOS, drivers etc...

The updates are retrieved over plain HTTP and not authenticated. There is a way, via MitM and some other trickery, to make it run a malicious executable with admin/system privileges.



Long story short, first thing to do when getting a new computer is axing all the preinstalled bloatware.

____________________
Kuribo64 - melonDS

want some revolution in your coffee?

Danielle
Posted on 06-05-16 07:24 PM, in Link | ID: 90428
Normal User

Miracles Happen
When you believe...
Level: 257


Posts: 2749/25311
EXP: 274403320
Next: 1444128

Since: 07-16-12
From: Albany, NY
OS: Windows 98

Last post: 489 days
Last view: 489 days
Just as bad as the Lenovo "Superfish" malware, too :P Typically whenever I buy a name brand machine I do a full format and erase the hard drive and do a clean install using the OEM supplied key ;)


"Miracles happen, when you believe..."
YouTube

Next newer thread | Next older thread
Main - msg db 'Computer Address',0xa - ASUS LiveUpdate MitM exploit


Acmlmboard v2.5.6 (06/11/2024)
© 2005-2025 Acmlm, Emuz, et al.

Page rendered in 0.047 seconds. (759KB of memory used)
MySQL - queries: 63, rows: 487/520, time: 0.040 seconds.