Notices where this attachment appears
-
Embed this notice
"- Visit website with driverhub.asus.com.* subdomain
- Site makes UpdateApp request for PoC executable “calc.exe”
- “calc.exe” will be downloaded, fail the signature check and not be executed
- Site makes UpdateApp request for custom AsusSetup.in
- This will also be downloaded and not executed
- Site makes UpdateApp request for signed ASUS binary “AsusSetup.exe”
- This will be downloaded and executed with admin permissions and does a silent install using -s, which will cause it to read the AsusSetup.ini file and run “calc.exe” specified in “SilentInstallRun” also with admin permissions
I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. [link to marketcap with 14 BILLION :guraKekw: ]"
https://mrbruh.com/asusdriverhub/
im glad i don't use a operating system which relies on horrible proprietary OEM software for essential drivers.