Post B6Xfdr5Y70mzUHLhMO by NosirrahSec@infosec.exchange
(DIR) More posts by NosirrahSec@infosec.exchange
(DIR) Post #B6Rp8btCPDOLxpYKB6 by munin@infosec.exchange
0 likes, 0 repeats
oh lovely, so there's a new evil maid attack vector in 'yellowkey'?well. that's decidedly unpleasant for y'all windows folks.
(DIR) Post #B6Rp8c2PqwlSQPrgXo by 0xabad1dea@infosec.exchange
0 likes, 0 repeats
@munin to my understanding, the backdoor cannot work if you have a password on bitlocker itself (most people don’t, but if evil maids are a nonhypothetical concern for you, you really should)
(DIR) Post #B6Rp8cDlAlq2zbAkE4 by gsuberland@chaos.social
1 likes, 0 repeats
@0xabad1dea @munin yeah and it really doesn't look like a backdoor. it's just a bad design.@Rairii found a second one too, but for leaking files into memory.
(DIR) Post #B6SCgw2GJ5vPEo80PI by 0xabad1dea@infosec.exchange
0 likes, 0 repeats
@gsuberland @munin @Rairii the fundamental problem here with judging if it's malicious is that if you *wanted* to design a highly deniable backdoor that would nonetheless work on 98% of installations, this would be a really good way to do it 😩
(DIR) Post #B6SEc09xkIL8UOVOHw by Rairii@labyrinth.zone
0 likes, 0 repeats
@mavnn @0xabad1dea @gsuberland @munin i wouldn't say it's *rushed*, rather not all feature interactions were consideredyellowkey happened because they added a new thing and a winpe boot-time recovery tool for that, which can be abused to get winpe init to reach a code path that just pops a shell with derived bitlocker keys still in memory
(DIR) Post #B6Xfdr5Y70mzUHLhMO by NosirrahSec@infosec.exchange
0 likes, 0 repeats
@0xabad1dea @munin REALLY glad I'm not in charge of vuln management for fleets of endpoints right now.But, really sad that I'm not in charge of fleets of endpoints right now.
(DIR) Post #B6XfdrIJLYzu7rJtFg by astraleureka@social.treehouse.systems
0 likes, 0 repeats
@NosirrahSec @0xabad1dea @munin You're not vulnerable if WinRE is disabled thankfully, we were unable to reproduce with our prod config at work. Enabling recovery does trigger the issue, but our sec team considers that out of scope since we don't really hand out local admin ever
(DIR) Post #B6b3smgdjyxWYNEH68 by astraleureka@social.treehouse.systems
0 likes, 0 repeats
@NosirrahSec @0xabad1dea @munin yeah, if we have a successful LPE we have much bigger fish to fry tbqh