killer lettuce !!iNo3FkiZx joined in and replied with this 11 years ago, 11 minutes later[^][v]#588,777
son of a fuck
this doesn't affect me in any way, but i shall pass the word along to my father
thanks, m8
Green !BEERiVqJJw joined in and replied with this 11 years ago, 20 minutes later, 32 minutes after the original post[^][v]#588,782
Does it affect Lenovo Tablets?
Anonymous A (OP) replied with this 11 years ago, 26 minutes later, 59 minutes after the original post[^][v]#588,786
@previous (Green !BEERiVqJJw)
If they run Windows, maybe. Don't know. Lenovo's terrible track record makes it seem like you shouldn't take the chance in any case.
Green !BEERiVqJJw replied with this 11 years ago, 7 minutes later, 1 hour after the original post[^][v]#588,791
Anonymous A (OP) replied with this 11 years ago, 1 minute later, 1 hour after the original post[^][v]#588,794
@previous (Green !BEERiVqJJw)
Yes, you've covered this already. However it's not a computer. Please stop derailing this thread now.
dw joined in and replied with this 11 years ago, 1 minute later, 1 hour after the original post[^][v]#588,795
meh
Anonymous A (OP) replied with this 11 years ago, 41 minutes later, 1 hour after the original post[^][v]#588,801
@previous (dw)
This is an actual big deal. Reinstalling windows won't work, they just reinfect you on boot.
(Edited 8 seconds later.)
dw replied with this 11 years ago, 4 minutes later, 2 hours after the original post[^][v]#588,805
@previous (A)
Yeah i get that but i was expecting keyloggers or something
Anonymous A (OP) replied with this 11 years ago, 1 minute later, 2 hours after the original post[^][v]#588,807
@previous (dw)
Who knows what kind of shit it does. Superfish wasn't meant to completely disable ssl for the machine, but it did. Lenovo doesnt do software security
Anonymous E joined in and replied with this 11 years ago, 42 minutes later, 2 hours after the original post[^][v]#588,813
Isn't Lenovo a Chinese company?
FuckAlms !vX8K53rFBI joined in and replied with this 11 years ago, 4 minutes later, 2 hours after the original post[^][v]#588,817
beckyderp !4aMoRa.T2Q joined in and replied with this 11 years ago, 54 minutes later, 3 hours after the original post[^][v]#588,839
I'm fine with this.
Anonymous A (OP) replied with this 11 years ago, 7 minutes later, 3 hours after the original post[^][v]#588,842
@previous (beckyderp !4aMoRa.T2Q)
Stockholm syndrome
Anonymous A (OP) double-posted this 11 years ago, 3 minutes later, 3 hours after the original post[^][v]#588,844
> Before booting windows 7 or 8, the bios checks if C:\Windows\system32\autochk.exe is the Lenovo one or the original Microsoft one. If it is not the lenovo one, it moves it to C:\Windows\system32\0409\zz_sec\autobin.exe, and then writes it's own autochk.exe. During boot, the Lenovo autochk.exe writes a LenovoUpdate.exe and a LenovoCheck.exe file to the system32 directory, and sets up a services to run one of them when an internet connection is established. I don't know too much exactly what those do, but one appears to phone home to http://download.lenovo.com/ideapad/windows/lsebios/win8_en-us_32_oko.jsonwhich is a bit worrying with the combination of a "ForceUpdate" parameter shown and the lack of ssl, making it fairly likely that it's exploitable for remote code execution by anyone who can intercept your traffic(public wifi, etc).
Fake anon !ZkUt8arUCU joined in and replied with this 11 years ago, 1 minute later, 3 hours after the original post[^][v]#588,845
@previous (A)
Can you explain why that is bad in a way that someone who isn't a nerd can understand?
The Owl !KThEOwLwbU joined in and replied with this 11 years ago, 3 minutes later, 4 hours after the original post[^][v]#588,848
It checks if the file that manages booting windows is the normal one or their special one and forces you to use the special one. That second one forces an update but the connection isn't encrypted, so a hacker could exploit it to download from their server instead of lenovos server and infect your computer
Fake anon !ZkUt8arUCU replied with this 11 years ago, 1 minute later, 4 hours after the original post[^][v]#588,849
@previous (The Owl !KThEOwLwbU)
How would they do that without already infecting your computer?
Anonymous A (OP) replied with this 11 years ago, 11 seconds later, 4 hours after the original post[^][v]#588,850
@588,845 (Fake anon !ZkUt8arUCU)
Okay so this is speculative but the interpretation is that the following can happen:
* You install a clean, legitimate, version of Windows. This install is entirely clean and exists as it was made by microsoft.
* You turn on your lenevo laptop and log in to Windows. Now a few things will have happened, before you get to the login screen the lenovo BIOS will have overwritten a file that Windows runs during startup. It uses this file to then install two other files and makes them execute when the computer has an internet connection.
* When the computer has an internet connection the aforementioned files will run, and download http://download.lenovo.com/ideapad/windows/lsebios/win8_en-us_32_oko.json from the internet. The crucial part here is that this is a HTTP link, not HTTPS. This means that anyone snooping on your internet connection can modify the download.
* You use your laptop in a coffee shop/airport/some other public wifi network and if there's a hacker/virus present on that network targeting this vulnerability then your laptop has been pwnd. What happened is that the lenovo software once again tried to download http://download.lenovo.com/ideapad/windows/lsebios/win8_en-us_32_oko.json, but the hacker intercepted this (because no https was used), they change the DownloadURL and FileName and set ForceUpdate to Yes. This would presumably cause the lenovo software to download the update package from the new location and execute it. This update package would then be malware.
Anonymous A (OP) double-posted this 11 years ago, 41 seconds later, 4 hours after the original post[^][v]#588,851
@588,849 (Fake anon !ZkUt8arUCU)
By controlling the internet you're using. Think public wifi networks. Coffee shops, restaurants, airports, etc. Oh, and of course your ISP and the NSA.
Also, the computer may have already been infected by malware that has not yet managed to have elevated itself to SYSTEM permissions. I assume that being able to set a system proxy is enough to do that now.
(Edited 1 minute later.)
Fake anon !ZkUt8arUCU replied with this 11 years ago, 3 minutes later, 4 hours after the original post[^][v]#588,852
@588,850 (A)
So could they..idk "patch" the startup procedure by just sticking an s after http? Do they not have their site encrypted? What's the fix?
Anonymous A (OP) replied with this 11 years ago, 1 minute later, 4 hours after the original post[^][v]#588,853
@previous (Fake anon !ZkUt8arUCU)
They could do that, but it's highly likely there are other issues with their software that haven't yet been uncovered. The bigger issue is that the BIOS is installing (or overwriting) software during boot. This should absolutely not happen in general principle.
Also, the introducing of https would not really patch the problem from malware already on the computer trying to elevate itself, though that's less of a risk I suppose. In any case, malware like that could just add their own certificate authority to the trust store and break https like that. Pretty similar to what lenovo previously did with superfish.
(Edited 1 minute later.)
Anonymous J joined in and replied with this 11 years ago, 2 hours later, 6 hours after the original post[^][v]#588,890
It's like Sony's compact discs that would instal rootkit malware on your computer without telling you. Fuck companies that pull shit like this.