Community


Annoying Message Part II (Fixed)

Links used in this discussion
Alim Nassor, User (Posts: 9)
Apr 14, 2017 1:25:46 am EDT
Support level: Free or trial
Dear Developers,

I would urgently request to remove the message.
I found when I press "Tell me more" and internet explorer session is started.
With that "Local System" account I can do anything (starting explorer etc..) on that computer (via file > open in IE) without logging on!!
This is a MAYOR security concern.

Please fix this URGENTLY!!!!!!!!!

Regards
Edited:Alim Nassor - Apr 20, 2017 7:26:08 pm EDT
Conrad, Support (Posts: 3049)
Apr 14, 2017 5:50:48 am EDT
Hello Alim,

We will fix this problem with the very next update. Thank you for letting us know.
Alim Nassor, User (Posts: 9)
Apr 14, 2017 5:53:23 am EDT
Support level: Free or trial
Hi Conrad,

When will that be?
This is not a small issue, and a standard reply is not enough in this context.

Regards, Alim
Conrad, Support (Posts: 3049)
Apr 14, 2017 6:21:58 am EDT
Hello Alim,

It is this Monday or Tuesday.
Alim Nassor, User (Posts: 9)
Apr 18, 2017 1:13:51 am EDT
Support level: Free or trial
Okay,

It is not fixed on Monday, do you realize you have released a mayor security breach, and are not solving it with the same urgency?
I'm a developer, so I know solving this is really a peace of cake. Takes about 10 minutes to adapt your software.

Alim.
Edited:Alim Nassor - Apr 18, 2017 1:15:26 am EDT
Conrad, Support (Posts: 3049)
Apr 18, 2017 5:06:16 am EDT
Hello, Alim,

This update is going to have other fixes and a reworked MSI Configurator. Today we'll be doing final testing before we provide it. So it's not this only bug that this update is going to fix.

Although the bug you mention is a security concern, it is not THAT major or urgent as you might imagine. If it is of so much extreme importance for you please restrain from distributing your Host installer for a while before we provide an update.

Sorry, we do not utilize a "piece of cake" approach. We need to make sure that the next update has been tested before we can make it public. Besides, publicly speaking about found exploits doesn't make your existing installations more secure, hope you understand.
Alim Nassor, User (Posts: 9)
Apr 18, 2017 5:18:29 am EDT
Support level: Free or trial

Conrad wrote:
Sorry, we do not utilize a "piece of cake" approach.

Not a really friendly comment towards your customers.

If you don't like exploits in your application, you should treat them as such, and be honest towards your customers.

This is my last post here, I will recommend towards our security officer not to continue with your product, this text (not the post, will likely be deleted in minutes by admin), will be forwarded to them.

Thank you for your support.

Alim
Conrad, Support (Posts: 3049)
Apr 18, 2017 5:56:18 am EDT
Hello Alim,

We will not delete the post. If we were afraid of having discussions on our site, we wouldn't have a forum in the first place. As you can see - everyone here can speak. Of course, if they follow our forum rules.  

As for the subject:

1.  This exploit only appears if you run a custom Host installer with the "Generate ID" function enabled AND if you click the "Tell me more" button.

2. This bug can only potentially be exploited by the remote user himself - to elevate their permissions. Yes, perhaps there might be other far less probably uses, but overall it has a very limited application/scope.

In this specific case marking your post as "BIG SECURITY ISSUE" could be misleading.  Someone who visits our forum may think that our software in general has a big security issue that applies to absolutely all cases, which is very far from the truth.

So instead of posting here on the forum you could just send us a ticket or an email, and this bug would have been fixed in a few days without anyone even knowing about it, which is good for security. Security issues are not something that should be immediately disclosed - it is advisable to contact the developers privately first, and see how they respond. And if they don't respond and refuse to deal with the issue it may be time to use public pressure. Unfortunately, you decided to use public pressure right from the start as if we were unresponsive or unwilling to fix issues.

We never said that we didn't like when our customers or users let us know about exploits in our software.  Quite the contrary, we can only be thankful for that and we encourage users to send us security bugs - the more the merrier. However, our concern is that making such information public BEFORE the bug is fixed is somewhat imprudent and can diminish security for existing users who use that specific feature. This is certainly not a proper way security bugs should be dealt with.

Thank you.
Conrad, Support (Posts: 3049)
Apr 20, 2017 7:27:16 pm EDT
Hello,

The issue has been fixed. New version is available here https://www.remoteutilities.com/download/ .

There are quite a few improvements to this version, we'll publish a blog post with the details very soon.

Thanks.

* Website time zone: America/New_York (UTC -5)