Just in:
Tech Giant Discharges Workers Following Disruptive Protest // Czar Workspace: a Modern Workspace Solutions in Dubai // Get Based with Mr. Based: The Future of Community-Driven Cryptocurrency // Innovative Study On Solvent Recycling In Warfare Published // Qmiax Exchange: Shaping a New Future of Secure and Compliant Cryptocurrency Trading // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // VT Markets Releases Study on Upcoming Bitcoin Halving and Market Implications // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // Petrochemical Storm Clouds Gather Over Saudi Arabia // Gen Zs Trust User and Expert Insights on Shopee // Global Cooperation Takes Center Stage at Dubai International Humanitarian Aid and Development Conference and Exhibition // NEOM welcomes leading industry figures and investors to Hong Kong showcase as part of its ‘Discover NEOM’ China tour // Sharjah Charity International Extends Helping Hand to Flood Victims // Abu Dhabi Environment Agency Endorses ADNOC’s Decarbonization Push // Hong Kong’s R&D Receives International Recognition HKPC’s “InspecSpider” Wins Prestigious “Edison Award” in Innovation Field // Andertoons by Mark Anderson for Fri, 19 Apr 2024 // AI Race Heats Up: Meta Unveils Powerful New Llama // Takeoff After Turbulence: Flydubai Restarts Operations at Dubai International Airport // VinFast expands access to comprehensive aftersales network in France and Germany through agreement with Mobivia // A Feast Without Footprint – Shiok Kitchen Catering Redefines Delicious Dining with Carbon Neutral Catering //

Windows 10 credential theft: Google is working on fix for Chrome flaw

1495028250 updated start 1024x683

updated-start-1024x683.png

The problem affects the latest Chrome running on the latest version of Windows 10.


Image: Microsoft

Attackers can use Google’s Chrome browser to install and automatically run a malicious file on a Windows PC to steal passwords.

DefenseCode security researcher Bosko Stankovic has detailed a credential theft attack on Windows that works by tricking a Chrome user into downloading a Windows Explorer Shell Command File or SCF (.scf), a format that’s been used since Windows 98 as a Show Desktop icon shortcut.

ADVERTISEMENT

The SCF file can be used to trick Windows into an authentication attempt to an attacker-controlled remote SMB server, which is designed to capture the victim’s user Microsoft LAN Manager (NTLMv2) password hash.

The hash can then be cracked offline or used to impersonate the victim on a service, such as Microsoft Exchange, that accepts the same kind of NTLM-based authentication.

The problem affects the latest Chrome running on the latest version of Windows 10.

“Currently, the attacker just needs to entice the victim, using fully updated Google Chrome and Windows, to visit his website to be able to proceed and reuse victim’s authentication credentials,” writes Stankovic.

“Even if the victim is not a privileged user, for example, an administrator, such a vulnerability could pose a significant threat to large organizations, as it enables the attacker to impersonate members of the organization.”

The attack relies on the way Chrome and Windows treat SCF files. The specific problem with Chrome is that it does not sanitize SCF files as it does with LNK files, which are given a .download extension. Chrome started sanitizing LNK files after the discovery that government hackers were abusing LNK files to infect Windows machines with Stuxnet.

Google told Kaspersky’s ThreatPost it is addressing this problem in Chrome. This affects Chrome for all versions of Windows, including Windows 10.

A second issue with Chrome is that it relies on Windows default behavior once the SCF file has been downloaded. As Stanovic points out, Chrome automatically downloads files that it deems safe.

This approach might be fine if the user needs to manually run the file, but in Windows the SCF file will trigger a request to authenticate to the attacker’s SMB server as soon as the download directory is opened in Windows File Explorer.

“There is no need to click or open the downloaded file — Windows File Explorer will automatically try to retrieve the ‘icon’,” notes Stankovic.

His tests of “several leading antivirus” found that none flagged the downloaded SCF files as dangerous.

“SCF file analysis would be easy to implement as it only requires inspection of the IconFile parameter considering there are no legitimate uses of SCF with remote icon locations,” he writes.

Chrome users can protect themselves by disabling automatic downloads. This can be done in Settings, and selecting Show advanced settings, followed by checking the option to ‘Ask where to save each file before downloading’.

This step should significantly reduce the risk of NTLMv2 credential theft attacks using SCF files, according to Stankovic.

He also recommends restricting SMB traffic to private networks, and configuring the firewall block ports that can be used to connect with a malicious internet-based SMB server.

Read more about Google’s Chrome browser

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
Gen Zs Trust User and Expert Insights on Shopee // Gunfire exchange near Manipur polling booth // UAE Delegation Engages in Arab Parliament Committee Discussions // VT Markets Releases Study on Upcoming Bitcoin Halving and Market Implications // Sharjah Charity International Extends Helping Hand to Flood Victims // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // Petrochemical Storm Clouds Gather Over Saudi Arabia // Takeoff After Turbulence: Flydubai Restarts Operations at Dubai International Airport // A Feast Without Footprint – Shiok Kitchen Catering Redefines Delicious Dining with Carbon Neutral Catering // VinFast expands access to comprehensive aftersales network in France and Germany through agreement with Mobivia // Qmiax Exchange: Shaping a New Future of Secure and Compliant Cryptocurrency Trading // Hong Kong’s R&D Receives International Recognition HKPC’s “InspecSpider” Wins Prestigious “Edison Award” in Innovation Field // Get Based with Mr. Based: The Future of Community-Driven Cryptocurrency // Innovative Study On Solvent Recycling In Warfare Published // Global Cooperation Takes Center Stage at Dubai International Humanitarian Aid and Development Conference and Exhibition // NEOM welcomes leading industry figures and investors to Hong Kong showcase as part of its ‘Discover NEOM’ China tour // The International Exhibition of Inventions in Geneva Reveals More than 40 Scientific and Technological Innovation Achievements from Hong Kong // Emirates Offer Support as Wildfires Ravage Greece // Global Energy Leaders Chart Course for Sustainable Future at IRENA Assembly //