Just in:
AI sharpens cyber battle across financial markets // Sun’s personal WLFI claims stay in federal court // Wuxi Symphony Orchestra Debuts at Ljubljana Festival: Sounds of the East Illuminate the Historic Central European City // 40 Teams Gather in Hong Kong to Compete in the “AI x Cybersecurity Challenge” // Objective Digital Psychological Assessment Launches in Singapore, Offering Clarity for Inattention and Hyperactivity Concerns // 5G Capital Sets a New Benchmark:China Unicom Beijing and Huawei Power the 2nd World Humanoid Robot Games with 5G-A GigaUplink // MacSync rotates domains as macOS credential theft expands // Grok glitch sends users streams of gibberish // NASA images expose crater from Falcon 9 crash // CFTC prepares crypto rules as Clarity Act stalls // TDCX Opens Second Hyderabad Campus, Reinforcing India as Key Global Delivery Hub // Trump’s new green card era: What changes for US immigrants // F1 backs Abu Dhabi for 2026 season finale // GEMS students post strong gains in GCSE results // From Vietnam to the U.S: East West Barbershop takes on the world’s most competitive market // Expired Visa cards exposed by contactless payment flaw // ISCA and ICAI Deepen Collaboration on AI Fluency and Professional Recognition // Bitcoin surges beyond $75,000 as rally strengthens // ToxicPanda 2.0 widens Android banking attack reach // MyRepublic expands GAMER lineup with Dreamcore x MyRepublic RTX 5060 Ti Gaming PC and Limited Edition ASUS T1 Graphics Card Broadband Bundle //

Windows 10 credential theft: Google is working on fix for Chrome flaw

1495028250 updated start 1024x683

updated-start-1024x683.png

The problem affects the latest Chrome running on the latest version of Windows 10.


Image: Microsoft

Attackers can use Google’s Chrome browser to install and automatically run a malicious file on a Windows PC to steal passwords.

DefenseCode security researcher Bosko Stankovic has detailed a credential theft attack on Windows that works by tricking a Chrome user into downloading a Windows Explorer Shell Command File or SCF (.scf), a format that’s been used since Windows 98 as a Show Desktop icon shortcut.

The SCF file can be used to trick Windows into an authentication attempt to an attacker-controlled remote SMB server, which is designed to capture the victim’s user Microsoft LAN Manager (NTLMv2) password hash.

The hash can then be cracked offline or used to impersonate the victim on a service, such as Microsoft Exchange, that accepts the same kind of NTLM-based authentication.

The problem affects the latest Chrome running on the latest version of Windows 10.

“Currently, the attacker just needs to entice the victim, using fully updated Google Chrome and Windows, to visit his website to be able to proceed and reuse victim’s authentication credentials,” writes Stankovic.

“Even if the victim is not a privileged user, for example, an administrator, such a vulnerability could pose a significant threat to large organizations, as it enables the attacker to impersonate members of the organization.”

The attack relies on the way Chrome and Windows treat SCF files. The specific problem with Chrome is that it does not sanitize SCF files as it does with LNK files, which are given a .download extension. Chrome started sanitizing LNK files after the discovery that government hackers were abusing LNK files to infect Windows machines with Stuxnet.

Google told Kaspersky’s ThreatPost it is addressing this problem in Chrome. This affects Chrome for all versions of Windows, including Windows 10.

A second issue with Chrome is that it relies on Windows default behavior once the SCF file has been downloaded. As Stanovic points out, Chrome automatically downloads files that it deems safe.

This approach might be fine if the user needs to manually run the file, but in Windows the SCF file will trigger a request to authenticate to the attacker’s SMB server as soon as the download directory is opened in Windows File Explorer.

“There is no need to click or open the downloaded file — Windows File Explorer will automatically try to retrieve the ‘icon’,” notes Stankovic.

His tests of “several leading antivirus” found that none flagged the downloaded SCF files as dangerous.

“SCF file analysis would be easy to implement as it only requires inspection of the IconFile parameter considering there are no legitimate uses of SCF with remote icon locations,” he writes.

Chrome users can protect themselves by disabling automatic downloads. This can be done in Settings, and selecting Show advanced settings, followed by checking the option to ‘Ask where to save each file before downloading’.

This step should significantly reduce the risk of NTLMv2 credential theft attacks using SCF files, according to Stankovic.

He also recommends restricting SMB traffic to private networks, and configuring the firewall block ports that can be used to connect with a malicious internet-based SMB server.

Read more about Google’s Chrome browser

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…