10 ms·
Classic Shell hacked with compromised update that erases your partition table
- fletchowns 10y agoRelated thread on reddit: https://www.reddit.com/r/pcmasterrace/comments/4vw21h/massive_psa_do_not_download_classic_shell_read/ https://www.reddit.com/r/pcmasterrace/comments/4vw21h/massiv...
- zamalek 10y agoThe fix: http://www.classicshell.net/forum/viewtopic.php?f=12&t=6434&p=28007#p28007 http://www.classicshell.net/forum/viewtopic.php?f=12&t=6434&... Close one for me: I was downloading WinDirStat when I came across that post.
- fencepost 10y agoSemi-unrelated: WinDirStat is amazing, but you might also look at WizTree for speed - it does its space analysis based just on reading the MFT, so it's quite fast.
- x64architecture 10y agoFossHub was compromised and only downloads from there were affected, various other projects were also affected.
- corobo 10y agoIt looks like this is on Fosshub (at time of writing is offline) which could imply that there's a much larger compromise in progress depending on what popular software is hosted there.
- caf 10y agoIt looks like they have a dump of the Fosshub user database. Audacity was also affected: http://www.audacityteam.org/hacked-download/ http://www.audacityteam.org/hacked-download/
- theandrewbailey 10y agoDamn. You have no idea how close I was to reinstalling Audacity last night.
- ocdtrekkie 10y agoDownloaded it a couple days ago in my case! Close call, though I do backup my important files offsite.
- theandrewbailey 10y agoI keep two offsite backups!
- Buge 10y agoIt sounds to me like one or two people reused passwords between fosshub and some other site that had its database breached.
- Ecio78 10y agoIn FossHub statement on reddit they said that they think they got credentials that were saved inside Redis through probably a zero day exploit. Probably something to be verified
- mtgx 10y agoI also hate that Fosshub doesn't even use HTTPS, even though they could get a Let's Encrypt certificate for free. They only offer file signatures, but even those are MD5 and SHA1, and both types should've been deprecated a while ago.
- flurpitude 10y agoI don't see much value in published file hashes when they're hosted on the same site that hosts the files. If someone compromises the download link they're probably in a good position to update the hashes too.
- 0x0539 10y agoThe purpose of the hashes isn't to prove the file hasn't been tampered with, its confirm that the file wasn't corrupted during download.
- bashinator 10y agoThen just use checksum instead of an obsolete cryptographic hash.
- nailer 10y agoApparently the hacked one wasn't signed. Users would have clicked through a (very prominent) warning to install it.
- d33 10y agoIt's not something that people pay attention to anyways...
- IshKebab 10y agoYeah but loads of software isn't signed so the warning is fairly useless.
- fuzzy2 10y agoUnless SmartScreen complains, the order of dialogs and buttons on those dialogs is exactly the same for both signed and unsigned programs. They only differ in content/design elements. That's not what I'd call prominent. There's nothing like HSTS for signed programs, so it can't be helped, though.
- Someone1234 10y agoOn Windows 10 you cannot install unsigned installers at all without disabling SmartScreen.
- fuzzy2 10y agoThat's not true. Although the screen wide dialog thingy is a little tricky, you can still choose to continue. It doesn't even appear most of the time.
- StavrosK 10y agoI get warnings every time I try to run something I downloaded, so I've just tuned them out. Unless this one was somehow completely different from those, I wouldn't have given it a second thought.
- Forge36 10y ago
- Kristine1975 10y agoTwitter account of the hackers: https://twitter.com/CultOfRazer https://twitter.com/CultOfRazer
- pluma 10y agoI'm not sure it's appropriate to give that kind of people unwarranted publicity.
- teh_klev 10y agoLinks on HN are rel="nofollow" so they're not going to get any google juice.
- eli 10y agoI don't think SEO is what pluma is concerned about
- Karunamon 10y agoSo what are they concerned about then? There's some moral wrong to watching crooks be crooks?
- pluma 10y agoThere's some moral wrong giving people exposure who are being obnoxious in order to get exposure. Linking may not imply endorsement but their twitter account clearly shows they want the public hate as attention, so whether you want it or not, you're doing them a favour by naming them, even if to scold them. This is akin to associating every mass killing with a terrorist organisation (whether accurate or not) and showing detailed videos of those killings when the entire point of a terrorist organisation is spreading terror.
- kuschku 10y agoWhat "kind of people"? They had the power to abuse that data and ship malware to millions, but decided just to give people a scare. That’s just the average grey-hat, or how most hackers were in the 90s. Compared with the profit-obsessed and abusive hackers and companies on the web today, which try to shove actual malware, sometimes installers with tons of preselected options, sometimes bitlocker, they’re not bad.
- Sir_Cmpwn 10y agoInteresting to see malware in this day and age that actually kills your computer instead of installing adware or joining a botnet.
- dhimes 10y agoFrom their Twitter page Fun fact: We actually had an EFI payload. We just had issues with the installer and it was left unadded.
- voltagex_ 10y agoDamn. With the state of most consumer mainboards, an EFI "payload" could leave the system "bricked". I know I've got one el-cheapo laptop that can't boot because I made a mess of the EFI environment and there's no way to reset it.
- deleted 10y ago[deleted]
- Zardoz84 10y agoI'm begin to think that EFI is a very wrong turn way on modern computers.
- Sir_Cmpwn 10y agoYou're a bit behind the curve on this. EFI has been criticized for being horrendously complicated and gross since its inception.
- semi-extrinsic 10y agoObligatory Matthew Garrett quote from a Linux kernel EFI patch in 2011: UEFI stands for "Unified Extensible Firmware Interface", where "Firmware" is an ancient African word meaning "Why do something right when you can do it so wrong that children will weep and brave adults will cower before you", and "UEI" is Celtic for "We missed DOS so we burned it into your ROMs". https://lkml.org/lkml/2011/5/25/228 https://lkml.org/lkml/2011/5/25/228
- posnet 10y agoA youtuber who usually does videos of classic DOS viruses made a video of this one in action. https://www.youtube.com/watch?v=DD9CvHVU7B4 https://www.youtube.com/watch?v=DD9CvHVU7B4
- Forge36 10y agoI hope the auto update wasn't affected. I just did this at work, no big warning screen. Now I'm paranoid to reboot.. Update: Looks like I wasn't affected. There was an official update (4.3.0) which was released on the 30th leading to unfortunate timing.
- fencepost 10y agoThe thread on Classic Shell specifically notes that the auto update pulls from a different source that was not affected.
- ultramancool 10y agoIt also verifies signatures before it will execute the update, so even if that source were hacked it wouldn't have been affected.
- deleted 10y ago[deleted]
- TazeTSchnitzel 10y agoThis is another reminder of how the security model of desktop OSes is pretty terrible. Every time you install software on Windows, you trust it with everything on your computer by giving it administrative rights. OS X doesn't have this problem usually, as most apps don't require admin rights to install, you just copy them to /Applications, but it still has some apps that use installers.
- drewg123 10y agoThere still is not (AFAIK) much partitioning between apps on most desktop OSes. So even if a malicious app doesn't have admin rights, it still can run under your UID, which is almost as bad as it then has access to nearly everything you care about. Obligatory xkcd: https://xkcd.com/1200/ https://xkcd.com/1200/
- TazeTSchnitzel 10y agoYeah, user account access is bad enough on its own.
- ultramancool 10y agoPretty much true. As these attackers stated on their own twitter "You ran it as admin, just be glad we didn't steal everything". All it takes is user access to dump all your stored passwords and run, which is what most attackers would do (there are even public tools they can deploy like iStealer that basically do this for them), from there they sell your accounts. From what I gather on their twitter these guys are pretty much doing it for the lulz.
- kalleboo 10y agoApps on OS X that have been installed through the App Store are sandboxed which is pretty close to the partitioning on iOS - for instance they can only access files the user has explicitly given access to (open dialog, double-clicking, drag and drop onto the app). That doesn't help you with apps you downloaded through the web though, which for me is all my apps because the App Store is a PITA.
- AdmiralAsshat 10y agoSo this appears to be a compromise of the download site, and probably could've been avoided with a hash verification, blah blah blah. Finger wag at developer. Moving on, I've been thinking about the problem of file integrity and how verifying the MD5/SHA sum creates extra gruntwork for the end-user, particularly for your average Windows user. How difficult would it be for the installer to compute its own hash and present it to the end-user when the installer starts, so that they can verify it against the hash posted on the front of the software's webpage? EDIT: Although I suppose if the binary itself is compromised, the hackers could always modify the hash function so that it shows the same hash as an existing "good" version even with the malicious code added. Hmm.
- ayuvar 10y agoSigning the installer would help detect tampering, except it seems like in this case the compromised installer was not signed and the usual one is. Nothing really stops you from unpacking all of the contents of the first installer, and repacking it with your payload into an unsigned installer which is likely what happened here.
- ianlevesque 10y agoIn theory that's what Windows SmartScreen is there to prevent.
- Someone1234 10y agoUnfortunately every single one of those terrible "stop Windows 10 spying on you!!!" guides tells people to turn off SmartScreen along with UAC/Windows Firewall/Windows Defender. Or worse tells them to download an unknown program which turns off a bunch of security features at a single click without an explanation of the cost. But at least the user feels less spied upon or something...
- Karunamon 10y agoSmartScreen is functionally useless, though. All it provides is a UAC warning for unsigned code, the likes of which through a legitimate user has clicked an untold number of times for perfectly legitimate reasons. Here's a video where the malicious file is executed. Nothing immediately seems amiss: https://youtu.be/DD9CvHVU7B4?t=1m43s https://youtu.be/DD9CvHVU7B4?t=1m43s
- warbiscuit 10y agoThis comment (http://www.classicshell.net/forum/viewtopic.php?p=27961&sid=e793bf88f4ac6301869fea98aab54756#p27961 http://www.classicshell.net/forum/viewtopic.php?p=27961&sid=...) on the forum thread posted md5/sha1 checksums of clean & infected 4.3.0 installers (though it's not clear if those are only infected checksums). ClassicShellSetup_4_3_0_clean.exe MD5: e10881b65c27c6e09e5a33cd8bcd99c6 SHA1: a6b06d07fe3b1a7204b1b62c67fbf3c602385364 File size: 7220496 bytes ClassicShellSetup_4_3_0_infected.exe MD5: c67dff7c65792e6ea24aa748f34b9232 SHA1: 438b6fa7d5a2c7ca49837f403bcbb73c14d46a3e File size: 7148732 bytes
- beefhash 10y agoAre the people over there sure that it's a good idea to rely on the broken[1] MD5 and the close-to-be-broken[2] SHA-1 for verifying checksums in the context of malicious actors? Though I guess the hashes and file sizes differ, so I guess this is just being pedantic. [1] https://en.wikipedia.org/wiki/MD5#Collision_vulnerabilities https://en.wikipedia.org/wiki/MD5#Collision_vulnerabilities [2] https://sites.google.com/site/itstheshappening/ https://sites.google.com/site/itstheshappening/
- Grom_PE 10y agoMD5 is broken in a sense that you can craft two different files with the same hash, but it's still hard to create a file with specific MD5 hash. So it's still good for identifying files that aren't specifically crafted to have a malicious counterpart.
- kalleboo 10y agoIt seems more reliable to check the developer signature in Properties on the EXE - the correct developer is "Ivaylo Beltchev". The infected download is unsigned and requires you to click through a warning.
- warbiscuit 10y agoThough annoyingly it's signed using sha1, not sha256. So if they were gonna put effort into making an sha1 collision, they'd probably target the signed payload, not the overall exe. Though it doesn't look like sha1 is that broken yet, for the budget of this grade of attacker.
- PeanutNore 10y agoI must have gotten very lucky, because I downloaded and installed installed Classic Shell on a fresh Windows 10 install yesterday afternoon and was not affected - the installer bore the right signature and my system is intact and boots fine. If I had tried a few hours later, I would probably be reinstalling Windows 10 for the second time in 2 days.
- fencepost 10y agoAudacity was also affected for a brief time, and the Audacity page about it (http://www.audacityteam.org/compromised-download-partner/ http://www.audacityteam.org/compromised-download-partner/) has much more information including the FossHub statement. It's described there as the Audacity portion being a compromise of an Audacity developer's account, with another reference to two compromised accounts. There were also other attack attempts going on at the same time, so the FossHub folks took things down for a time - not sure if they're done with their checking or not. According to FossHub there were only ~300 downloads of Classic Shell during this time, and they may have caught the Audacity one faster.
- kalsk 10y agoClassic Windows. I miss the 90s.