Samker's Computer Forum - SCforum.info

Security Software Armory: => Miscellaneous: Anti-Malware tools, discussions, advices... => Topic started by: Samker on 25. November 2015., 07:57:19

Title: How to remove eDellRoot - a powerful root CA certificate & security backdoor ?!
Post by: Samker on 25. November 2015., 07:57:19
(http://4.bp.blogspot.com/-X-cgo2LlgfY/VlQtUPh5BHI/AAAAAAAAlcY/MAkqkpUc6DU/s1600/superfish-malware.png)

Dell has published a guide on how to remove the web security backdoor it installed in its Windows laptops and desktop PCs: http://en.community.dell.com/dell-blogs/direct2dell/b/direct2dell/archive/2015/11/23/response-to-concerns-regarding-edellroot-certificate

This confirms what we all know by now – that Dell was selling computers with a rather embarrassing hole it in their defenses.

New models from the XPS, Precision and Inspiron families include a powerful root CA certificate called eDellRoot, which puts the machines' owners at risk of identity theft and banking fraud: http://www.theregister.co.uk/2015/11/23/dude_youre_getting_pwned/

The self-signed certificate is bundled with its private key, which is a boon for man-in-the-middle attackers: for example, if an affected Dell connects to a malicious Wi-Fi hotspot, whoever runs that hotspot can use Dell's cert and key to silently decrypt the victims' web traffic. This would reveal their usernames, passwords, session cookies and other sensitive details, when shopping or banking online, or connecting to any other HTTPS-protected website.

Stunningly, the certificate cannot be simply removed: a .DLL plugin included with the root certificate reinstalls the file if it is deleted. One has to delete the .DLL – Dell.Foundation.Agent.Plugins.eDell.dll – as well as the eDellRoot certificate.

Dell has posted information [.docx] on how to do this properly, and future machines will not include the dangerous root CA cert: https://dellupdater.dell.com/Downloads/APP009/eDellRootCertRemovalInstructions.docx
A software update process will run from November 24 that will remove the certificate automatically from machines, we're told.

In a statement to the media, the Texas-based IT titan said:

The recent situation raised is related to an on-the-box support certificate intended to provide a better, faster and easier customer support experience. Unfortunately, the certificate introduced an unintended security vulnerability.

Dell said that it started including the root CA certificate with machines in August, although an Inspiron 15 series laptop we bought in July has an eDellRoot certificate on it.

"We deeply regret that this has happened and are taking steps to address it," added Laura Thomas, Dell's chief blogger.

"The certificate is not malware or adware. Rather, it was intended to provide the system service tag to Dell online support allowing us to quickly identify the computer model, making it easier and faster to service our customers. This certificate is not being used to collect personal customer information.

"It’s also important to note that the certificate will not reinstall itself once it is properly removed using the recommended Dell process."

If you've got a new Dell, you can check here to see if you the dodgy root CA cert installed: https://edell.tlsfun.de/
For everyone, we'll leave you with this nightmare fuel...

(ElReg)
Title: Re: How to remove eDellRoot - a powerful root CA certificate & security backdoor ?!
Post by: Fintech on 25. November 2015., 20:15:45
So this affects only DELL computers.  :thumbsup:
Title: Re: How to remove eDellRoot - a powerful root CA certificate & security backdoor ?!
Post by: Samker on 28. November 2015., 10:19:19
So this affects only DELL computers.  :thumbsup:

Yes pal. ;)

Now even Microsoft removes it with its own tools: http://www.pcworld.com/article/3009258/microsoft-zaps-dodgy-dell-digital-certificates.html
Title: Re: How to remove eDellRoot - a powerful root CA certificate & security backdoor ?!
Post by: Fintech on 28. November 2015., 10:24:32
Thanks Sam... :thumbsup:
 :up: