Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Jabor
Jul 16, 2010

#1 Loser at SpaceChem
So it's another "antivirus is loving stupid" thing?

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth

lol

Jabor posted:

So it's another "antivirus is loving stupid" thing?

seems like it.

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



i should have known it'd be a problem with antivirus software

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Volmarias posted:

The S in IoT stands for Semen

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

:wow:

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

quote:

NScript is the component of mpengine that evaluates any filesystem or network activity that looks like JavaScript. To be clear, this is an unsandboxed and highly privileged JavaScript interpreter that is used to evaluate untrusted code, by default on all modern Windows systems. This is as surprising as it sounds.

oh come the gently caress on

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Dex posted:

oh come the gently caress on

:vince:

Midjack
Dec 24, 2007



Dex posted:

oh come the gently caress on

hosed up

haveblue
Aug 15, 2005



Toilet Rascal
wait, so this attempts to evaluate as JavaScript all kinds of random content from the internet?

the 2017 equivalent of the old +++ATH thing?

El Mero Mero
Oct 13, 2001

Tweet broke for some reason. Here's a direct link to the write-up: https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5


quote:

On workstations, attackers can access mpengine by sending emails to users (reading the email or opening attachments is not necessary), visiting links in a web browser, instant messaging and so on. This level of accessibility is possible because MsMpEng uses a filesystem minifilter to intercept and inspect all system filesystem activity, so writing controlled contents to anywhere on disk (e.g. caches, temporary internet files, downloads (even unconfirmed downloads), attachments, etc) is enough to access functionality in mpengine. MIME types and file extensions are not relevant to this vulnerability, as MsMpEng uses it's own content identification system.


quote:

Before executing JavaScript, mpengine uses a number of heuristics to decide if evaluation is necessary. One such heuristic estimates file entropy before deciding whether to evaluate any javascript, but we've found that appending some complex comments is enough to trigger this.

The attached proof of concept demonstrates this, but please be aware that downloading it will immediately crash MsMpEng in it's default configuration and possibly destabilize your system. Extra care should be taken sharing this report with other Windows users via Exchange, or web services based on IIS, and so on.


:laffo:

vOv
Feb 8, 2014

yeah that's what I'm curious about is what they do to avoid someone just chewing up CPU/memory

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
usually they just have a short timeout where they go "we ran it for x ms and it didn't do anything bad, so it's probably okay"

so you know, even if the whole setup did do anything beneficial w.r.t catching stuff it's trivially defeated by counting to a large number in a loop at the very start of your malware

Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy

Jabor posted:

usually they just have a short timeout where they go "we ran it for x ms and it didn't do anything bad, so it's probably okay"

so you know, even if the whole setup did do anything beneficial w.r.t catching stuff it's trivially defeated by counting to a large number in a loop at the very start of your malware

the assaulting problem

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

El Mero Mero posted:

Tweet broke for some reason. Here's a direct link to the write-up: https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5




:laffo:
if the tweet is broken it's a problem with your adblocker

cinci zoo sniper
Mar 15, 2013






:nsa: third largest phone carrier in latvia advertising mobile av

Truga
May 4, 2014
Lipstick Apathy
why would you patch your lovely android 3rd party phone, when you can make cash off people buying your av instead???

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
ah this is great: (plus twitter automatically treating e.toString.call as a URL)

https://twitter.com/natashenka/status/861748397409058816

and then further down the thread:

quote:

AND for good measure malware detection and "windows defender" chew up your CPU and IO. (I disable it.) Nice to know it's even worse.
lol

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

El Mero Mero posted:

write-up excerpts

:catstare: well this seems like a problem

Chris Knight posted:

ah this is great: (plus twitter automatically treating e.toString.call as a URL)

https://twitter.com/natashenka/status/861748397409058816

and then further down the thread:

lol

jfc.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


oh how handy i just worked out why local debugging results in 10second response times for all http requests: trend micro real time monitor is doing 'something' to every file touched on the system including all temporary internet files

i wonder if i can cause it to crash by embedding an infinite loop in some js or something

ErIog
Jul 11, 2001

:nsacloud:
I am being forced to give a presentation on Thursday where I instruct all users, even users of Macs, to install antivirus.

There is a caveat in the presentation about how the AV we have a volume license for isn't very good. I'm gonna insert my derision there as much as is reasonable, and try to highlight the fact that antivirus is pretty worthless generally if your behavior is bad.

Shame Boy
Mar 2, 2010

ErIog posted:

I am being forced to give a presentation on Thursday where I instruct all users, even users of Macs, to install antivirus.

There is a caveat in the presentation about how the AV we have a volume license for isn't very good. I'm gonna insert my derision there as much as is reasonable, and try to highlight the fact that antivirus is pretty worthless generally if your behavior is bad.

technically i'm supposed to have AV on my mac but I've been told by the head of IT that "you can just install it when the auditors are here and uninstall it afterwards i'm well aware that antivirus is worthless" :ssh:

haveblue
Aug 15, 2005



Toilet Rascal

ate all the Oreos posted:

technically i'm supposed to have AV on my mac but I've been told by the head of IT that "you can just install it when the auditors are here and uninstall it afterwards i'm well aware that antivirus is worthless" :ssh:

corporate IT forced me to install an awful AV package that greatly increased build times, so I broke it by messing around in terminal and they got tired of trying to unbreak it

(they tried to fix the build time issue themselves a couple of times but it never took)

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad


Hacker Vo

oh gently caress off I don't even care anymore

Shame Boy
Mar 2, 2010

haveblue posted:

corporate IT forced me to install an awful AV package that greatly increased build times, so I broke it by messing around in terminal and they got tired of trying to unbreak it

(they tried to fix the build time issue themselves a couple of times but it never took)

originally i just disabled parts of it that annoyed me but it phoned home to a central screen and showed a big red warning light and THIS COMPUTER IS UNPROTECTED on the central thing

also it installs a root certificate so it can MITM everything and besides being awful that breaks a lot of the local debugging I do and disabling it shows that red light :discourse:

akadajet
Sep 14, 2003

Rufus Ping posted:

symantec are trying to avoid having the smackdown laid on them by going over everyones head and crying directly to google execs

https://twitter.com/konklone/status/861392893747101696

hope this simply results in an even more punitive outcome for trying to subvert the official process

tbf who in their right mind uses firefox in 2017?

Babies Getting Rabies
Apr 21, 2007

Sugartime Jones

(in extremely hacker voice) i'm in

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

stdin

30 TO 50 FERAL HOG
Mar 2, 2005



haveblue
Aug 15, 2005



Toilet Rascal
time for some penetration testing

flakeloaf
Feb 26, 2003

Still better than android clock

slambus

fins
May 31, 2011

Floss Finder

ate all the Oreos posted:

technically i'm supposed to have AV on my mac but I've been told by the head of IT that "you can just install it when the auditors are here and uninstall it afterwards i'm well aware that antivirus is worthless" :ssh:

Can you install it in a VM?

FlapYoJacks
Feb 12, 2009

:vince:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

stderr

cinci zoo sniper
Mar 15, 2013




so this train company sells ride tickets on their website. i downloaded their android app later, after i bought the first ticket, to buy another one. as i entered the same email for delivery, the app greeted me with my bank card details, with a few *** in the middle of the 16 digit code, and the cvv missing

:how:

akadajet
Sep 14, 2003

https://blog.travis-ci.com/2017-05-08-security-advisory

quote:

Various GitHub OAuth tokens and secure environment variables that users included in their builds were accidentally exposed via inclusion in build logs on Travis CI. The vulnerability was responsibly disclosed by security researcher Ivan Vyshnevskyi, first to the Google Security team, who in turn disclosed it to Travis CI in a private channel. To our knowledge, no exposed OAuth tokens have been published. Neither Travis CI nor GitHub have been compromised.

lol

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
so is the windows defender thing meant to be the same as this
https://twitter.com/taviso/status/860681252034142208

or is that a second major thing that hasn't been announced yet. cuz the wording is kind of a bit more dire than what actually got announced (since a lot of default windows installs are going to be with some crap like Norton installed and defender disabled, let alone all the 7 and older machines out there which are still the majority of windows installs

(windows versions that had modern defender installed by default are currently about 38% of Windows systems online)

Bonfire Lit
Jul 9, 2008

If you're one of the sinners who caused this please unfriend me now.

fishmech posted:

since a lot of default windows installs are going to be with some crap like Norton installed and defender disabled
that's not a default install then, it's some OEM crapware infested install

Shame Boy
Mar 2, 2010

fishmech posted:

so is the windows defender thing meant to be the same as this
https://twitter.com/taviso/status/860681252034142208

or is that a second major thing that hasn't been announced yet. cuz the wording is kind of a bit more dire than what actually got announced (since a lot of default windows installs are going to be with some crap like Norton installed and defender disabled, let alone all the 7 and older machines out there which are still the majority of windows installs

(windows versions that had modern defender installed by default are currently about 38% of Windows systems online)

was there a worse windows remote code exec in recent memory? i'm legit asking i don't remember

James Baud
May 24, 2015

by LITERALLY AN ADMIN
So I didn't​ read the full report / write-up, but how did they justify calling malicious javascript wormable?

Adbot
ADBOT LOVES YOU

haveblue
Aug 15, 2005



Toilet Rascal

James Baud posted:

So I didn't​ read the full report / write-up, but how did they justify calling malicious javascript wormable?

it can be triggered by automated inbound data like email bodies, IMs, etc

  • Locked thread