Elektrine lite

← Feed

@Viss@mastodon.social

Post #3972417

2026-07-20 23:19 UTC

wait wait wait holdup. you can plug an hdmi device into a computer, and you get .. ... ... autorun.inf functionality? it installs and runs entirely without user consent? so we're back to evil usb sticks again that autorun shit, except now ... a malicious... firestick? chromecast? .. hdmi is the new usb?

Replies (7)

  • @voltagex@aus.social 2026-07-20 23:22

    @Viss@mastodon.social depends on what you can get on to the Windows Update server. Windows Update is looking for a driver matching a vendor and product ID, that inf is then declaring a Windows App ID. Realtek, Logitech and NVidia do it too, LG was just louder about it.

    Open ##3972416

  • @Viss@mastodon.social yeah but it’s worse because it comes from windows update to “install drivers and supporting applications”.

    Open ##3974025

  • @wdormann@infosec.exchange 2026-07-21 02:35

    @Viss@mastodon.social Ah, I remember years ago there being some Windows LPE when connecting Razer USB devices. (Driver installation included a GUI-based coinstaller that ran with privileges). I made a raspberry pi script to enumerate known VID/PID combos to see if other devices behaved similar (some did!). Disturbing to see the same thing happen with HDMI devices. 😬 (Assuming that's what's actually happening here, and not that somebody plugged the LG monitor USB connection in)

    Open ##3975422

  • @Viss@mastodon.social Not quite. Unless this is a new technique, the device just sends model and manufacturer IDs. Windows then connects to the Windows Update service to see if there are drivers and installs them. And there is woefully inadequate vetting of the auto-installed stuff. I remember the Razer instance of this because it came a couple of weeks after Microsoft bought Razer cameras for all employees, which was hilarious timing.

    Open ##3979365

  • @jernej__s@infosec.exchange 2026-07-21 08:09

    @Viss@mastodon.social Remember Razer from a few years ago where the driver helper could be abused to get SYSTEM privileges?

    Open ##3980918

  • @Viss@mastodon.social 2026-07-20 23:38

    does anybody out there have any of those old 'gumstick computers'? the whole systems (tiny systems, anyhow) that plug directly into hdmi? im super curious if you can completely fake the device ID that the 'hdmi host' system gets. because if you CAN fake that ID - then .. yeah we're in full-on HDMI rubber duckie territory

    Open ##3981357

  • @bosh@infosec.exchange 2026-07-21 13:07

    @Viss@mastodon.social i mean the right one can do ethernet too soo its an hdmi implant all in one?

    Open ##3986491