Deleting System32\curl.exe
daniel.haxx.se
daniel.haxx.se
(I don’t need tips to get around this or anything, I can just connect to another network or use a VPN)
Doesn't work as well today, but there were surprisingly few false positives at the time.
A better solution would be to tell Vodafone to switch off the censorship on your service.
Knowing about it won't help you if every ISP option you have is doing the same thing.
Where I live, we have laws that prevent people from interfering with the mail. If I send a letter to someone, once it's accepted the mail carriers can't generally withhold it and make demands before they deliver it or open my letter and remove or change whatever words/pages they feel like before completing delivery.
I think the internet should be treated the same. Beyond some basic QOS ISPs should be dumb pipes and be mostly forbidden from messing with things you send/receive over the connection.
If your mail service had a "make sure mail from known pornographers doesn't get delivered to my house" option, and you had kids at home, you might well opt for it.
In the UK where 20% of the internet is blocked – it's surprising you haven't experienced this before. Call your service provider and tell them you want access to adult material.
That’s not true. I’ve experienced this once before that I can remember, on https://hackmii.com/ and it doesn’t happen on my home network except on actual scam sites which isn’t a government thing but an ISP feature that can probably be turned off. This is a Vodaphone thing, not a UK thing.
I don’t care that much about this specific site, I guess I just want to complain that they don’t have a way to report false positives which maybe isn’t the best reason to post a comment on an unrelated article but still
According to the `considered-18` post linked by a sibling comment:
> It shows that this filter is for this specific host name only [daniel.haxx.se], not for the entire haxx.se domain.
So, even more of a WTF.
This sounds like an extreme over-estimate. Some ISP's, mostly mobile ones, default to blocking "adult material" unless you tell them to turn that off. Some of the larger ISPs are under court order to block some specific other content (Pirate Bay in particular; my old ISP was one of them, my current ISP happily lets me access it, not that I've ever done so other than to see if it's blocked).
Most ISPs block at most a tiny set of sites and personally in 23 years of using UK ISPs I've never "organically" run into those blocks (as in, no site I actually had any interest in accessing has been blocked; I've only seen them when checking whether people were right that a specific site was blocked). And yes, that includes visiting sites with "adult material" without running into any blocks.
I do have a VPN, so it'd take me as long to bypass as it takes me to press one button in my browser address bar, but I only need that to evade IP region/country blocks - never needed it to get around UK filtering.
That must be one awkward call.
Even on those that do, 20% seems rather high??
I'm not sure why you would want your ISP interfering with your traffic like this. To me, it seems like a dealbreaker.
Not all of them. I’m on Zen, no filters as far as I’m aware, sci-hub works fine. Libgen is fine. Torrent sites that the ‘main’ ISPs block come up just fine, too.
Edit: some of the ISPs that do seem to land on this URL (note http) –
http://www.ukispcourtorders.co.uk
whois shows BT (large ISP and telco) as the owner.
The UK government threatened to make it a legal requirement that all internet connections have filters for adult content on by default.
The major ISPs and mobile networks voluntarily put filtering in place by default to avoid the regulation.
The filters can usually be removed quite easily.
While there are some smaller ISPs that don't put filtering in place, they account for something like < 10% of the market.
Yes, you can disable it quite easily. Usually by entering a credit card number in their app or website to prove you're 18, or alternatively by contacting their customer service chat.
But of course, only pervs who want to access porn would do that, right?
In my experience it's a good idea to disable it regardless, it as there are often a lot of "false positives", and the filtering can sometimes cause performance problems. (Unless you've got kids and really do want to block porn, but eventually they're gong to discover VPNs...)
No? Why would you say this? I disabled this back with my old carrier and it was pretty painless - I don't recall there being any stigma attatched to turning off the filters. I've since moved carriers and I don't remember having to disable filters - maybe I did or maybe something about signing up turned it off?
Painless based on provider, otherwise what described above is a pain.
Are people actually afraid of some stranger call-center worker silently judging them, but not even saying anything out-loud about it because the call is recorded and they'd be fired if they tried to actually shame you?
All of the major ISPs and mobile networks now do it on a voluntary basis.
Are we even sure this is vodaphone? This sounds so much like a scam pop up ad.
I would have edited this in to my original comment but it won’t let me any more
Next time anyone runs into a similar problem you might just want to zip the file before deleting it put a password if you AV still reports it. Or just get rid of your AV software it clearly su*ks if it reports legit system files.
Run DISM first, then SFC.
https://support.microsoft.com/en-us/topic/use-the-system-fil...
If you are running Windows 10, Windows 8.1 or Windows 8, first run the inbox Deployment Image Servicing and Management (DISM) tool prior to running the System File Checker. (If you are running Windows 7 or Windows Vista, skip to Step 3.)
It gets top SEO billing, and seems to be entirely unmoderated, or at least moderated by people who don't know anything about Windows. It's less informative than Quora. All this does is take all the air out of the room for an actual information source about Windows problems, and it's clearly ignored by Microsoft internal teams.
Creating a "Support Forum" for your brand that never offers actual support should be fraud.
I don't even know who else to blame for this.
Ive tested a two or three years old Chrome version with JIT compiler vulnerability and guess what - on empty Linux vm it managed to escape chrome and execute code
Meanwhile on Windows with Crowdstrike Chrome just showed some error message about mem. access
Im not sure who handled that attack - was it Windows or Crowdstrike, but eitherway Ive been impressed
C:\> alias curl
CommandType Name Version
Source
----------- ---- ------- ------
Alias curl -> Invoke-WebRequestcurl > curl.exe > C:\Windows\System32\curl.exe
[1] https://learn.microsoft.com/en-us/powershell/scripting/whats...
> The people who deleted or replaced the curl executable noticed that they cannot upgrade because the Windows update procedure detects that the Windows install has been tampered with and it refuses to continue.
This policy makes absolutely no sense.
As noted on the blog post, the solution is to run the system file checker (sfc) to repair it before running the update
The people who told them that deleting system binaries would fix their problems?
> I have been pointed to responses on the Microsoft site answers.microsoft.com done by “helpful volunteers” that specifically recommend removing the curl.exe executable as a fix.
Don't trust strangers on the internet with advice you don't understand the implications of. Even if they are sincere and mean well, they can still be wrong.
if that's the case we should just delete the entire OS as there are vulns all over it.
If you are responsible for the security posture and compliance in your organization, reading and acting on security assessments, and yet you do random changes based on random comments on forums, you deserve the blame.
I don't think we're not talking about individual end-users here. Those do not scan their systems for CVEs and do not have a requirement to get to 0 alerts.
Are you sure about that? From TFA:
> Lots of Windows users everywhere runs security scanners on their systems with regular intervals in order to verify that their systems are fine. At some point after December 21, 2022, some of these scanners started to detect installations of curl that included the above mentioned CVE. Nessus apparently started this on February 23.
> This is not helpful.
> Lots of Windows users everywhere then started to panic when these security applications warned them about their vulnerable curl.exe.
That sounded like it included individual end-users to me.
Anectodally, I know a few Windows users who don't trust Microsoft to do security well, but can't bring themselves to move off Windows for whatever reason, so run 3rd party AV and security tools to help protect themselves.
Either you're security-conscious or you do random changes based on anonymous forum posts, I just don't really see an overlap.
In any case, I don't think it's fair to blame the forums for giving you the solution given your whacky requirements.
I think there's going to be a not-totally-insignificant minority of people out there who are both worried about security, but just don't have great technical knowledge. (They sometimes show up on r/privacy if you need convincing they even exist.) Even if it's a really small percentage of users, given how large the Windows install base is, that's still going to be a fair amount of people looking for any kind of fix for the "problem" that their security scanner has warned them about.
It's not as easy. Of course experienced sysadmins know it's bullshit. The problem is that cybersecurity insurance policies require "immediate action" on alerts and no one, even assuming a competent CTO, wants to be stuck with the bill should a security incident arise and the insurance say "audit says no of your machines had mitigated issue xyz, claim denied". Deleting a flagged binary is evidence of mitigation.
The amount of utter bullshit, not to mention the literal spyware that is insurance-compliant antivirus solutions, that insurances force clients to comply with is insane.
The core problem is that insurances don't have the time to actually do deep dives to check if their clients have decent or no IT security. Hell, I'd wager everyone here knows of "that one server that never got updates, was in no inventory or whatever, and once the last disk failed suddenly everything else came crashing down". And so, insurances go with a 12 pound hammer to which everything is a nail, as it is the best way for them to be able to underwrite policies with the insane amount of coverage that GDPR and friends expose the clients to.
>Many Windows users are even contractually “forced” to fix (all) such security warnings within a certain time period or risk bad consequences and penalties.
So the blame would be on managers who think checking boxes is how every single job works.
Microsoft. It's their binary shipped in their system, and their customers are being directed to break their own systems. It's on them to remediate the situation.
End of the day this as Daniel says is scare mongering by others who don't know what they are doing.
The phrase, if someone told you to jump off a cliff, would you?, and, Your scientists were so preoccupied with whether or not they could, they didn't stop to think if they should...
CVE numbers have exploded while their quality has declined partly due to things like company and project bug bounties, where individuals get bonuses internally for submitting CVEs that get an ID. There's a virtual army of people doing nothing but looking for subtle ways to exploit key tools just to be able to earn a bonus. Some bigger projects, like the linux kernel, dispute some CVEs (e.g. CVE-2023-23005) because they are b.s., but smaller projects don't have the luxury.
See the curl maintainer's take on this: https://daniel.haxx.se/blog/2023/03/06/nvd-makes-up-vulnerab...
This is a quote from the Cyber Essentials requirements (https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-...):
""" The Applicant must be active in its management of computers and network devices. It must routinely
...
remove or disable unnecessary software (including applications, system utilities and network services) """
So, based on the quote above, curl.exe must be removed if it is not used, no matter whether it is vulnerable or not (yes I know it is a misreading, but it's frightening that the most literal interpretation is a misreading).
I don't know if you get forum points for suggesting wiping your drive or something but I've never seen a useful response from someone tagged as some kind of expert by answers.microsoft.com.
I'm surprised I've never heard of this before. In my experience you can almost hear Windows Update cackling with glee as it un-customizes your Windows install.
It is a network scanner
Also if you are stuck with this another way to fix it is to just run the file out of a different directory and/or rename your new one. Windows load hierarchy is local folder first, then path (which usually has system32 in there somewhere).
But if you are dead set on your chmod method yes you could use calcs to do it. Add the executable permission to false. You prob would have to do that from a decently privlaged account. You probably could also do it from active directory using a group policy.
A better way is to open a phone support ticket with MS if they are the ones installing it. Going onto their web support boards is usually basically a dead end. If you bought your PC from an OEM you can call them too then they can open a ticket with MS.
I just did this for the "AsusComService" which would take 30% of my i9 13k simply because i have dns blocking running for it.
Or differently said, modern asus motherboards actively come with a rootkit.
Windows has so far randomly undone these changes so there's probably some kind of recovery mechanism that gets triggered when you alter file permissions. A script running on login setting the permissions through powershell seems to have put that stupid executable in stasis on my machine at least, so perhaps it works for curl too.
* compattelrunner is a telemetry generation tool that seemingly cannot be killed. I have applied every registry hack, privacy tool, and Windows setting, but that damned thing will not be disabled. If it weren't for the driver signature enforcement, I would've written a minifilter driver that makes all files with that name disappear to finally rid myself of this curse.
Hello, <name>, how are you?
Good day! I'm <other name> a Windows user like you and I'll be happy to assist you today. I know this has been difficult for you, Rest assured, I'm going to do my best to help you
Please do
<giant copy paste including scf /scannnow and dism /something>
If the problem still persists, please try to update using the Microsoft tool.
Kindly let me know if this helps or if you have any further concerns.
Sincerely,
<other name> Independent Advisor
Standard Disclaimer: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.
Worth remembering this is only the case if you buy a retail license.
If you cheaped out with an OEM license, you are your own customer support and Microsoft won't help you.
If you bought a laptop or pre-made desktop, you have an OEM license provided to you by whoever manufactured your computer and they are your customer support; Microsoft won't help you.