Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I wrote a thing about a thing.

I wrote a thing about a thing.

Scheduled Pinned Locked Moved Uncategorized
7 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • wdormann@infosec.exchangeW This user is from outside of this forum
    wdormann@infosec.exchangeW This user is from outside of this forum
    wdormann@infosec.exchange
    wrote last edited by
    #1

    I wrote a thing about a thing.

    Specifically, Finding Vulnerabilities with Crassus – A Case Study with ESET.

    I created Crassus on a whim a few years ago, and it's interesting to see that it still can find things.

    It's also interesting (disappointing) that reporting vulnerabilities to vendors is still as painful as ever.

    Link Preview Image
    stephen0x2dfox@hachyderm.ioS fritzadalis@infosec.exchangeF j91321@infosec.exchangeJ 3 Replies Last reply
    1
    0
    • wdormann@infosec.exchangeW wdormann@infosec.exchange

      I wrote a thing about a thing.

      Specifically, Finding Vulnerabilities with Crassus – A Case Study with ESET.

      I created Crassus on a whim a few years ago, and it's interesting to see that it still can find things.

      It's also interesting (disappointing) that reporting vulnerabilities to vendors is still as painful as ever.

      Link Preview Image
      stephen0x2dfox@hachyderm.ioS This user is from outside of this forum
      stephen0x2dfox@hachyderm.ioS This user is from outside of this forum
      stephen0x2dfox@hachyderm.io
      wrote last edited by
      #2

      @wdormann "Currently it is not possible to improve behavior."

      -____________-

      1 Reply Last reply
      0
      • wdormann@infosec.exchangeW wdormann@infosec.exchange

        I wrote a thing about a thing.

        Specifically, Finding Vulnerabilities with Crassus – A Case Study with ESET.

        I created Crassus on a whim a few years ago, and it's interesting to see that it still can find things.

        It's also interesting (disappointing) that reporting vulnerabilities to vendors is still as painful as ever.

        Link Preview Image
        fritzadalis@infosec.exchangeF This user is from outside of this forum
        fritzadalis@infosec.exchangeF This user is from outside of this forum
        fritzadalis@infosec.exchange
        wrote last edited by
        #3

        @wdormann
        You did Crassus? Nice, thanks.

        wdormann@infosec.exchangeW slater450413@infosec.exchangeS 2 Replies Last reply
        0
        • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

          @wdormann
          You did Crassus? Nice, thanks.

          wdormann@infosec.exchangeW This user is from outside of this forum
          wdormann@infosec.exchangeW This user is from outside of this forum
          wdormann@infosec.exchange
          wrote last edited by
          #4

          @FritzAdalis
          I'm flattered that you even knew about it! 🎉

          1 Reply Last reply
          0
          • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

            @wdormann
            You did Crassus? Nice, thanks.

            slater450413@infosec.exchangeS This user is from outside of this forum
            slater450413@infosec.exchangeS This user is from outside of this forum
            slater450413@infosec.exchange
            wrote last edited by
            #5

            @FritzAdalis @wdormann also came here to say exactly this. Kudos 😎

            I've been looking to play around with this for a while as it looks awesome.

            1 Reply Last reply
            0
            • wdormann@infosec.exchangeW wdormann@infosec.exchange

              I wrote a thing about a thing.

              Specifically, Finding Vulnerabilities with Crassus – A Case Study with ESET.

              I created Crassus on a whim a few years ago, and it's interesting to see that it still can find things.

              It's also interesting (disappointing) that reporting vulnerabilities to vendors is still as painful as ever.

              Link Preview Image
              j91321@infosec.exchangeJ This user is from outside of this forum
              j91321@infosec.exchangeJ This user is from outside of this forum
              j91321@infosec.exchange
              wrote last edited by
              #6

              @wdormann Hey, thanks for the report and sorry about that response. Whoever wrote it was not being very helpful, I'll look into that. By "another product" they mean ESET Endpoint Security which has a driver that (should) enforce self-defense on the path. Without EES, EIConnector doesn't work. That however doesn't make this finding invalid, if you are somehow able to install one without the other.

              wdormann@infosec.exchangeW 1 Reply Last reply
              0
              • j91321@infosec.exchangeJ j91321@infosec.exchange

                @wdormann Hey, thanks for the report and sorry about that response. Whoever wrote it was not being very helpful, I'll look into that. By "another product" they mean ESET Endpoint Security which has a driver that (should) enforce self-defense on the path. Without EES, EIConnector doesn't work. That however doesn't make this finding invalid, if you are somehow able to install one without the other.

                wdormann@infosec.exchangeW This user is from outside of this forum
                wdormann@infosec.exchangeW This user is from outside of this forum
                wdormann@infosec.exchange
                wrote last edited by
                #7

                @j91321
                Thanks.

                I think at the end of the day, "Product <foo> is vulnerable, but product <bar> mitigates it", does not change the fact that "Product <foo> is vulnerable"

                Specifically, in my original analysis, I installed the product with ESET Endpoint Antivirus 11.0.2044.0, and that product does not do anything to mitigate the vulnerability.

                I don't know if it's an EEA vs. EES thing, or a version number thing. But either way, it is indeed possible to install ESET Inspect Connector in a way that truly is vulnerable.

                Personally, I think that if ESET Inspect Connector contains a vulnerability, then that product itself should get the attention it needs to mitigate it, without relying on another product to mitigate it.

                1 Reply Last reply
                0
                • R relay@relay.infosec.exchange shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups