4 ms·
To answer the downvotes: You can install Chrome extensions without the user noticing (built this in the past) which gives you access to basically everything wi
by mockingbirdy 8y ago
To answer the downvotes:
You can install Chrome extensions without the user noticing (built this in the past) which gives you access to basically everything without even resorting to DLL injections (I don't share this because it's dangerous and can't be fixed by the Chromium team). Reminder: It's possible to hijack 2FA and online banking with this method. I've read the source code of Zeus and SpyEye, I can do the same thing a) without AV detection and b) without DLL injections (which are very easy to spot).
If you know the Win32 APIs, it's extremely easy to build malicious software that doesn't need escalated privileges.
edit: I'm pretty sure I can implement it on Mac and Linux, too. I don't like the sentiment that those systems are more secure, it's just the difference in usage.
edit2: I can recommend Sandboxie. Please use it to get a little bit more security.
- exikyut 8y agoI'm genuinely curious how you'd go about doing what you describe. I'm vaguely aware that Chrome has a mechanism to silent-install extensions, IIRC when they're placed in the filesystem in a certain way, specified in the registry, or configured via GP. I don't remember which, but I think they install silently. Failing all that, you can probably just extract the extension into the Chrome profile folder and on next restart it'll pick it up. You saying it "gives you access to basically everything" makes me think you're doing one of the techniques above, which does bypass the permissions dialogs. And sure, "Access all data on all websites you visit" would grant you the ability to see everything in every webpage and do what you're describing. I honestly wouldn't mind knowing which Win32 APIs you're referring to. Perhaps you could drop a couple of them, so I get a ballpark idea of which direction you're going in with that. Finally, the reason I'm writing this comment, really, is that I'm _most_ curious how you'd implement "it" on macOS and Linux too. I 100% agree that both are just as vulnerable as Windows in their own ways but have less market share. I would be extremely interested to hear some of the ways you'd particularly go about attacking Linux, which I use everyday. SandboxIE doesn't run on macOS or Linux.
- mockingbirdy 8y ago> Failing all that, you can probably just extract the extension into the Chrome profile folder and on next restart it'll pick it up. No, this would be a security hazard. All the mentioned ways require admin privileges or even group policy privileges. I'm doing it without any permissions. Chrome hardened the process to protect their users. They're doing the best they can, but the Win-APIs are too powerful and there is no sandbox (like those for Mac) in place. Officially, all ways (registry keys, files, ...) require admin privileges for a very good reason. See http://www.chromium.org/administrators/pre-installed-extensions http://www.chromium.org/administrators/pre-installed-extensi... for an overview of the official methods. > SandboxIE doesn't run on macOS or Linux. Mac has its own sandbox and Linux offers SELinux and I was talking about a security vulnerability I have written for Windows specifically, that's why I gave the tip for Sandboxie. > Perhaps you could drop a couple of them, so I get a ballpark idea of which direction you're going in with that. > I would be extremely interested to hear some of the ways you'd particularly go about attacking Linux, which I use everyday. Sorry, I can't talk about this specific attack in detail because this vulnerability can't be fixed. It's conceptually fairly simple and <400 LoC and I'm sure you can find it on your own if you're determined. For Linux and security: If you're not constantly monitoring your running processes and bash scripts, privilege escalation and others can be easily pulled off (e.g. simply aliasing sudo). As an example, it's extremely simple to extract all stored passwords from Chrome and others [1]. That's the reason I prefer to use separate password managers (most of them protect their address space), although you can easily hack them as well. That's the reason I prefer encrypted virtual drives - it's unconventional and most tools don't cover it so the hacker has to search for them manually. Security is mainly making it more difficult to find the stuff, it's nearly impossible to hide it completely (otherwise the user wouldn't be able to access it, too). It's a big field, so I don't really know what what you're interested in. You can find exploits on https://www.exploit-db.com https://www.exploit-db.com and look for things that are interesting for you. For most of the pwnage, you don't need any exploits (except the chain of remote exploits to get in). As soon as you're in, you can do anything without any problems - getting root user, keylogging [2] (very easy for X11), injecting shared libraries (especially easy on Linux with LD_LIBRARY_PATH) and other stuff. I would recommend sandboxing tools, network- and host-based IDS/IPS, a good firewall which also analyzes behavior patterns and a healthy amount of paranoia. Many AV systems are mainly security risks themselves and add a false sense of security, it's extremely easy to bypass them and their sandbox-analyzers. [1]: https://securityxploded.com/googlechromesecrets.php https://securityxploded.com/googlechromesecrets.php [2]: https://github.com/anko/xkbcat https://github.com/anko/xkbcat