<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I wrote a thing about a thing.]]></title><description><![CDATA[<p>I wrote a thing about a thing.</p><p>Specifically, <a href="https://tharros.com/finding-vulnerabilities-with-crassus-a-case-study-with-eset/" rel="nofollow noopener">Finding Vulnerabilities with Crassus – A Case Study with ESET</a>.</p><p>I created Crassus on a whim a few years ago, and it's interesting to see that it <strong>still</strong> can find things.</p><p>It's also interesting (disappointing) that reporting vulnerabilities to vendors is still as painful as ever.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/342/772/037/238/536/original/7f36e4d8dba6cad6.webp" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/e831a9aa-b13c-4354-8dbd-1b7664b9ced9/i-wrote-a-thing-about-a-thing.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 04:13:11 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/e831a9aa-b13c-4354-8dbd-1b7664b9ced9.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 03 Apr 2026 20:58:45 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I wrote a thing about a thing. on Sat, 04 Apr 2026 11:55:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/j91321%40infosec.exchange">@<span>j91321</span></a></span> <br />Thanks.</p><p>I think at the end of the day, "Product <code>&lt;foo&gt;</code> is vulnerable, but product <code>&lt;bar&gt;</code> mitigates it", does not change the fact that "Product <code>&lt;foo&gt;</code> is vulnerable"</p><p>Specifically, in my original analysis, I installed the product with ESET Endpoint Antivirus 11.0.2044.0, and that product does <strong>not</strong> do anything to mitigate the vulnerability.</p><p>I don't know if it's an EEA vs. EES thing, or a version number thing.  But either way, it is indeed possible to install ESET Inspect Connector in a way that truly is vulnerable.</p><p>Personally, I think that if ESET Inspect Connector contains a vulnerability, then that product itself should get the attention it needs to mitigate it, without relying on another product to mitigate it.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116346306645003557</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116346306645003557</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 11:55:51 GMT</pubDate></item><item><title><![CDATA[Reply to I wrote a thing about a thing. on Sat, 04 Apr 2026 06:34:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> Hey, thanks for the report and sorry about that response. Whoever wrote it was not being very helpful, I'll look into that. By "another product" they mean ESET Endpoint Security which has a driver that (should) enforce self-defense on the path. Without EES, EIConnector doesn't work. That however doesn't make this finding invalid, if you are somehow able to install one without the other.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/j91321/statuses/116345041417367297</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/j91321/statuses/116345041417367297</guid><dc:creator><![CDATA[j91321@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 06:34:05 GMT</pubDate></item><item><title><![CDATA[Reply to I wrote a thing about a thing. on Sat, 04 Apr 2026 02:26:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/fritzadalis%40infosec.exchange">@<span>FritzAdalis</span></a></span> <span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> also came here to say exactly this. Kudos <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60e.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--sunglasses" style="height:23px;width:auto;vertical-align:middle" title="😎" alt="😎" /></p><p>I've been looking to play around with this for a while as it looks awesome.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Slater450413/statuses/116344067493968795</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Slater450413/statuses/116344067493968795</guid><dc:creator><![CDATA[slater450413@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 02:26:24 GMT</pubDate></item><item><title><![CDATA[Reply to I wrote a thing about a thing. on Fri, 03 Apr 2026 23:50:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/fritzadalis%40infosec.exchange">@<span>FritzAdalis</span></a></span> <br />I'm flattered that you even knew about it!  <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f389.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--tada" style="height:23px;width:auto;vertical-align:middle" title="🎉" alt="🎉" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116343455664084402</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116343455664084402</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Fri, 03 Apr 2026 23:50:48 GMT</pubDate></item><item><title><![CDATA[Reply to I wrote a thing about a thing. on Fri, 03 Apr 2026 22:12:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <br />You did Crassus?  Nice, thanks.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/FritzAdalis/statuses/116343070449393224</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/FritzAdalis/statuses/116343070449393224</guid><dc:creator><![CDATA[fritzadalis@infosec.exchange]]></dc:creator><pubDate>Fri, 03 Apr 2026 22:12:50 GMT</pubDate></item><item><title><![CDATA[Reply to I wrote a thing about a thing. on Fri, 03 Apr 2026 21:31:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> "Currently it is not possible to improve behavior."</p><p>-____________-</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/stephen0x2dfox/statuses/116342907217673608</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/stephen0x2dfox/statuses/116342907217673608</guid><dc:creator><![CDATA[stephen0x2dfox@hachyderm.io]]></dc:creator><pubDate>Fri, 03 Apr 2026 21:31:20 GMT</pubDate></item></channel></rss>