06-20-2016, 04:20 AM
https://www.pugetsystems.com/blog/2016/0...urity-808/
Sorry I didn't post about this earlier.
Sorry I didn't post about this earlier.
Quote:So I just ran into this wonderful news regarding ASUS and their LiveUpdate utility. Apparently LiveUpdate allows for the running of updates via HTTP without properly verifying them. It's kind of a big deal. Basically, with this sort of attack open, somebody can script a bit of software to run on your system and it will show up in LiveUpdate as just another random security update.
The way it works is that the program checks for a specific set of update files online every hour. If the files report an update, they pass along the info for the update. Here's the thing. Since it's all handled via HTTP, it's possible for somebody to use a man-in-the-middle attack to alter the update files. In doing so, it's possible to run malware on the system, or even to have your BIOS modified via an update. Based on my reading of the report, it looks like you'd have to actively run the false update from inside the LiveUpdate utility for it to do its work, but it still presents a huge security risk, as most folks will simply trust it, expecting it to be a real ASUS update.

