GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Sunday, 11-May-2025 20:26:19 JST 翠星石 翠星石
    in reply to
    • DarkMahesvara
    @DarkMahesvara >Proprietary garbage Wi-Fi card that doesn't operate without proprietary software loaded at runtime resulted in the internal Wi-Fi card not working and he had to buy an external usb adapter.
    Many such cases.

    I hope he purchased a freedom-respecting one.
    In conversation about 10 days ago from freesoftwareextremist.com permalink
    • Embed this notice
      DarkMahesvara (darkmahesvara@varishangout.net)'s status on Sunday, 11-May-2025 20:26:20 JST DarkMahesvara DarkMahesvara
      "- Visit website with driverhub.asus.com.* subdomain
      - Site makes UpdateApp request for PoC executable “calc.exe”
      - “calc.exe” will be downloaded, fail the signature check and not be executed
      - Site makes UpdateApp request for custom AsusSetup.in
      - This will also be downloaded and not executed
      - Site makes UpdateApp request for signed ASUS binary “AsusSetup.exe”
      - This will be downloaded and executed with admin permissions and does a silent install using -s, which will cause it to read the AsusSetup.ini file and run “calc.exe” specified in “SilentInstallRun” also with admin permissions

      I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. [link to marketcap with 14 BILLION :guraKekw: ]"

      https://mrbruh.com/asusdriverhub/

      im glad i don't use a operating system which relies on horrible proprietary OEM software for essential drivers.
      In conversation about 10 days ago permalink

      Attachments



      1. No result found on File_thumbnail lookup.
        MrBruh's Epic Blog
        One-Click RCE in ASUS’s Preinstalled Driver Software Introduction This story begins with a conversation about new PC parts. After ignoring the advice from my friend, I bought a new ASUS motherboard for my PC. I was a little concerned about having a BIOS that would by default silently install software into my OS in the background. But it could be turned off so I figured I would just do that.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.