Another Word For It Patrick Durusau on Topic Maps and Semantic Diversity

December 1, 2015

New Rule for Software Patches: Don’t Make Things Worse

Filed under: Cybersecurity,Security — Patrick Durusau @ 7:36 pm

Security Advisory: Dell Foundation Services Remote Information Disclosure (II)

From the post:

Dell Foundation Services starts an HTTPd that listens on port 7779. The previous service tag leak was fixed by removing the JSONP API.

However, the webservice in question is still available; it is now a SOAP service, and all methods of that webservice can be accessed, not just the ServiceTag method.

One of the methods accessible is List GetWmiCollection(string wmiQuery) – this returns the results of a given Windows Management Instrumentation (WMI) query, enabling access to information about hardware, installed software, running processes, installed services, accessible hard disks, filesystem metadata (filenames, file size, dates) and more.

Amazing isn’t it?

The post recommends removal of Dell Foundational Services. Same way you cure Adobe Flash security problems.

No Comments

No comments yet.

RSS feed for comments on this post.

Sorry, the comment form is closed at this time.

Powered by WordPress