3 weeks ago
3 weeks ago
3 weeks ago
Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.
We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.
After a huge controversy over Super fish Adware fiasco in Lenovo laptops, another story is in the market. Tom Forbes, an independent researcher, has written blog revealing a backdoor present in "Dell System Detect" software. According to Tom Forbes, Dell System Detect software has a critical flaw that lets an attacker to remotely attack a user by drive by download technique and execute arbitrary file without user consent. This Remote Code Execution vulnerability in Dell System Detect software has been fixed by Dell on successful reporting by Tom.
Dell System Detect is a software program found on Dell's Support Website for Driver downloads. Whenever a user wants to download a particular driver, there is a need to enter either Service Tag number of the product or Download Dell System Detect software, which has been found to have a backdoor. Backdoor Found in Dell Support Program, is used to detect the system model number and other necessary related information to get the exact driver downloads available for the system to the user. Tom Forbes explained the bypass mechanism used in protections put in by Dell.

Dell Laptop owners are quite familiar with the screen above. It is the Dell Support page for downloading drivers for the system. Whenever a user chooses clicking "Detect Product" button over Entering Service Tag, a small Dell System Detect file download is initiated, used to autofill the service tag input (Just in case you are being too lazy) and shows us the relevant drivers for download.
"While investigating this rather innocuous looking program I discovered that it accepts commands by listening for HTTP requests on localhost:8884 and that the security restrictions Dell put in place are easily bypassed, meaning an attacker could trigger the program to download and install any arbitrary executable from a remote location with no user interaction at all", further tells Forbes.
After further investigation Fores found that the code for "http" follows eSupport.Common.Client.Service.RequestHandlers.ProcessRequest which is responsible for processing a request through the processes HTTP port. Why is this a problem? The HTTP Referrer can contain the full request URI including the host and path. This means an attacker could easily make a request with an origin of "http://hacker.com/dell" and this would pass the initial test as "dell" is in the string. Further, Forbes investigated the issues and concluded that the program does a little bit more than simply retrieve your service tag. More technical details can be found here on his blog.
Forbes discussed the problem with Dell Security Department who fixed the issue. But Forbes said,
"While I cannot be sure I think they simply changed the conditional from "if dell in referrer" to "if dell in referrer domain name", which may be slightly harder to exploit but just as severe. There is now also a big agreement you have to accept before downloading that specifies what the software can do."
In response to Forbes comments, Dell issued a public statement denying that it never installed backdoors on PCs it supplies.
Dell has a long-standing commitment to design, build and ship secure products and quickly address instances when issues are discovered. A key Dell priority is the protection of customer data and information, which is reflected in our robust and comprehensive privacy and information security program and policies. We take very seriously any issues that may impact the integrity of our products or customer security and privacy.
Should we become aware of a possible vulnerability in any of Dell's products we will communicate with our customers in a transparent manner as we have done in the past.
Dell does not work with any government to compromise our products to make them vulnerable for exploit, including through software implants or so-called backdoors.
Since the above statement does not clarifies the security concerns raised by Forbes but, Dell told this issue to be unintentional and has been now fixed and hence, users can now use the software without any problem.
Download the CDI Official Android App to have news directly on your phone.