Как ведущие компании по производству ПК «помогают» хакерам

(Microsoft, Oracle, SAP SE ..) , .

, . Duo Security : HP, Dell, Acer, Lenov Asus. , . .



Duo , , OEM (OEM, Original Equipment Manufacturers) (updaters), . . — , . ( PDF).

OEM ( HTTP, ). , .



Duo Security:
, , . , OEM .

— . , . ( ), . , , , . , . .

Duo Security (Darren Kemp) :
- . , , ( ).

. , . , Apple, , . Bloatware ( ).

:
, « » Apple . () Apple… .

, : , . Bloatware — , , . OEM . .

12 . , .

CVE ( )
HPSA (HP )
HPSF DLL
HP Support Framework13 2016 . HP CVE,
HP.com31 2016 .
/ HTTP-,
HPDIA Downloads,
HPDIA Downloads,
AsusAsus LiveUpdate. 125CVE-2016-3966
Asus Giftbox. 125CVE-2016-3967
Acer. 45CVE-2016-3964
. 45CVE-2016-3965
LenovoLiveAgent2016 .CVE-2016-3944

OEM, Dell . , HTTPS. Dell Foundation Services. -, Dell .

Hewlett-Packard . HTTPS, . . , . . , URL. .

Lenovo — Lenovo Solutions Center UpdateAgent. . . .

Acer . , . , .

Asus . , « , ». , , . Asus HTTP HTTPS. , MD5 ( «Asus Live Update»).

, HTTPS . , . Lenovo, HP Dell . Acer Asus .

- . HP . Lenovo . Acer Asus , .

(Steve Manzuik), Duo Labs:
Asus , . ...

Source: https://habr.com/ru/post/es395655/


All Articles