bagder,
@bagder@mastodon.social avatar

deleting system32\curl.exe https://daniel.haxx.se/blog/2023/04/24/deleting-system32curl-exe/ - Let me tell you a story about how Windows users are deleting files from their installation and as a consequence end up in tears. #curl

resuna,
@resuna@ohai.social avatar

@bagder My daughter used to have a Windows desktop and I had to reinstall Windows every six months or so because she'd done stuff like this, except more so. So I got her an iMac. A few years later she's having a problem so I open up Terminal... no terminal. Yep. same problem, except that it took years for her to break her Mac to the point she noticed something was wrong.

I ssh-ed in to her iMac and copied Terminal.app and a few other files back from my Mac and everything was good.

pointless_speculations,

@bagder Sheesh. I thought deleting system32 was a meme.

matt_garber,
@matt_garber@mastodon.sdf.org avatar

@bagder Similar situation with Linux distros like RHEL and Ubuntu LTS: too many of the scanners (and security personnel) only look at the major.minor.patch version of installed software which gets flagged for CVEs, and do not realize that almost all long term support OSs backport security fixes into their included versions, so something like PHP 7.4 which is EOL by upstream may be patched and perfectly fine with the appropriate vendor (distro) patch applied. Sigh.

barubary,

deleted_by_author

  • Loading...
  • bagder,
    @bagder@mastodon.social avatar

    @barubary thanks, fixed!

    jsmall,

    @bagder Microsoft should just can answers.microsoft.com. ChatGPT could unironically provide better advise than most of the MVPs advising in those threads.

    0xtero,

    @bagder Ah, reminds me when people used to upload malicious binaries to Virus Total and have payloads link to Windows Update URLs. Then various vendor products would use that to build “Thrat Intel” blocklists for firewalls etc, essentially blocking their orgs from accessing patches

    ciourte,
    @ciourte@piaille.fr avatar

    @bagder Reminds me of the good old days when a hoax spread through e-mail and msn messenger (to date the thing 🧓) pretended that a a system file with a teddy bear as its icon was a dangerous virus you'd been infected by, and that you should delete it.
    https://en.wikipedia.org/wiki/Jdbgmgr.exe_virus_hoax

    thomy2000,

    @bagder Haha, what a great story 😄

    Lafiel,
    @Lafiel@my.elven.pw avatar

    @bagder
    To restore file, can try running the command with administrator privileges:
    sfc /scanfile=c:\Windows\System32\curl.exe

    paoloredaelli,
    @paoloredaelli@mastodon.uno avatar

    @bagder
    The only sane way to fix Windows is to delete it and start using operative systems. 😅😅😅
    But this also requires that users and administrators be conscious and educated. Sadly an appreciable share is not 😢😭

    lefractal,
    @lefractal@mstdn.social avatar

    @bagder Still reading it, found one small typo "but we still strongly discourage everyone from replacing and system files." (and)

    michael,
    @michael@thms.uk avatar

    @bagder deleting any system file on windows:

    This Is Fine GIF

    jugmac00,
    @jugmac00@fosstodon.org avatar

    @bagder I am not entirely sure whether I coined the term, but I'd like to call those issues "CVE dos". Faced similar issues for our project.

    nf3xn,
    @nf3xn@mastodon.social avatar

    deleted_by_author

    nf3xn,
    @nf3xn@mastodon.social avatar

    deleted_by_author

  • Loading...
  • Renegade_GDI,

    @nf3xn @jugmac00 @bagder they have set permissions to TrustedIntaller dude so admins could change owners, but users can't even delete system files

    nf3xn,
    @nf3xn@mastodon.social avatar

    deleted_by_author

  • Loading...
  • Renegade_GDI,

    @nf3xn @jugmac00 @bagder Volume Shadow Copy is optional, most of the users don't switch it on and if that's Home edition they can't even disable updates. Corporate and Pro versions get more stable versions and all bugs go get tested at Home users. So the most fair solution would be pirating the enterprise edition once in 2 years or so

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • thenastyranch
  • tester
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • tacticalgear
  • Youngstown
  • ethstaker
  • osvaldo12
  • slotface
  • everett
  • rosin
  • khanakhh
  • megavids
  • ngwrru68w68
  • Leos
  • modclub
  • cubers
  • cisconetworking
  • Durango
  • InstantRegret
  • GTA5RPClips
  • provamag3
  • normalnudes
  • anitta
  • JUstTest
  • lostlight
  • All magazines