3 ms·
> Failing all that, you can probably just extract the extension into the Chrome profile folder and on next restart it'll pick it up. No, this would be a securi
by mockingbirdy 8y ago
> Failing all that, you can probably just extract the extension into the Chrome profile folder and on next restart it'll pick it up.
No, this would be a security hazard. All the mentioned ways require admin privileges or even group policy privileges. I'm doing it without any permissions.
Chrome hardened the process to protect their users. They're doing the best they can, but the Win-APIs are too powerful and there is no sandbox (like those for Mac) in place. Officially, all ways (registry keys, files, ...) require admin privileges for a very good reason.
See http://www.chromium.org/administrators/pre-installed-extensions http://www.chromium.org/administrators/pre-installed-extensi... for an overview of the official methods.
> SandboxIE doesn't run on macOS or Linux.
Mac has its own sandbox and Linux offers SELinux and I was talking about a security vulnerability I have written for Windows specifically, that's why I gave the tip for Sandboxie.
> Perhaps you could drop a couple of them, so I get a ballpark idea of which direction you're going in with that.
> I would be extremely interested to hear some of the ways you'd particularly go about attacking Linux, which I use everyday.
Sorry, I can't talk about this specific attack in detail because this vulnerability can't be fixed. It's conceptually fairly simple and <400 LoC and I'm sure you can find it on your own if you're determined.
For Linux and security: If you're not constantly monitoring your running processes and bash scripts, privilege escalation and others can be easily pulled off (e.g. simply aliasing sudo). As an example, it's extremely simple to extract all stored passwords from Chrome and others [1]. That's the reason I prefer to use separate password managers (most of them protect their address space), although you can easily hack them as well. That's the reason I prefer encrypted virtual drives - it's unconventional and most tools don't cover it so the hacker has to search for them manually. Security is mainly making it more difficult to find the stuff, it's nearly impossible to hide it completely (otherwise the user wouldn't be able to access it, too).
It's a big field, so I don't really know what what you're interested in. You can find exploits on https://www.exploit-db.com https://www.exploit-db.com and look for things that are interesting for you. For most of the pwnage, you don't need any exploits (except the chain of remote exploits to get in). As soon as you're in, you can do anything without any problems - getting root user, keylogging [2] (very easy for X11), injecting shared libraries (especially easy on Linux with LD_LIBRARY_PATH) and other stuff.
I would recommend sandboxing tools, network- and host-based IDS/IPS, a good firewall which also analyzes behavior patterns and a healthy amount of paranoia. Many AV systems are mainly security risks themselves and add a false sense of security, it's extremely easy to bypass them and their sandbox-analyzers.
[1]: https://securityxploded.com/googlechromesecrets.php https://securityxploded.com/googlechromesecrets.php
[2]: https://github.com/anko/xkbcat https://github.com/anko/xkbcat
- exikyut 8y ago> All the mentioned ways require admin privileges or even group policy privileges. I'm doing it without any permissions. Oh, nice :) > They're doing the best they can, but the Win-APIs are too powerful and there is no sandbox (like those for Mac) in place. Hmmmm. > Mac has its own sandbox and Linux offers SELinux and I was talking about a security vulnerability I have written for Windows specifically, that's why I gave the tip for Sandboxie. I have to admit I've never really poked SELinux. My understanding of it is that because it was bolted-on, both architecturally and conceptually, that getting the most out of it is a real pain. This has put me off. :/ (heh) >> I would be extremely interested to hear some of the ways you'd particularly go about attacking Linux, which I use everyday. > Sorry, I can't talk about this specific attack in detail because this vulnerability can't be fixed. It's conceptually fairly simple and <400 LoC and I'm sure you can find it on your own if you're determined. Righteo then writes program that generates all possible C programs <400 LoC long In all seriousness, you definitely have me interested now :) I guess what might be a relevant question is, how universally applicable is it? Would it run on my minimally-configured Slackware box, for example? And I am _very_ fascinated to hear that this "cannot be fixed". Are you describing a Linux-specific Spectre/Meltdown? If this is Chrome-specific - or, shall we say, could be deeply contextualized into domains very important to Chrome - well, I'm sure you've seen https://bugs.chromium.org/p/chromium/issues/detail?id=648971 https://bugs.chromium.org/p/chromium/issues/detail?id=648971 and https://bugs.chromium.org/p/chromium/issues/detail?id=766253 https://bugs.chromium.org/p/chromium/issues/detail?id=766253, and particularly the one tag with the numbers in it in the sidebar on the left... To be honest I'm not really sure what I'm interested in, you could sort of describe where I'm at as somewhat similar to your post 8 months ago about finding your passion. (In my case it's a resource thing.) I've started playing with X11 recently though, to the extent of just learning the wire protocol for fun. I was actually thinking of making a tiny Xlib-less keylogger the other day, haha. (As in, talking to X via write()/read() directly.) Not quite sure why; perhaps the theoretically-interesting scenario of "not linking to libX11 might be less suspicious?" could be one explanation. I don't seem to need to give myself a rationale to stay motivated on my current track (woohoo), so I'm just tinkering for now. Uh - getting root on Linux isn't exactly straightforward! Although there was that one time I found a very confused Docker installation (running Ubuntu on CentOS... I'd never used Docker before and could not figure out which way was up ("wat, I have yum AND ap--wait no now apt-get disappeared where did it go"), for about an hour lol) and this system may or may not have left /dev/vda1 in the Docker image... and it may have allowed me to mount it read-write from under the host system, with effective UID 0... ._. (IIRC, I think it was visudo that worked great.) I wonder if there's a password manager that stores data in the kernel and/or uses the kernel's crypto keyring - and whether such effort would be worth it? (At least this would thwart local attacks, and only remote attacks via the Wi-Fi stack would work. xD) I've fished forgotten passwords out of Login Data more times than I have fingers, I think. sqlite3 .dump + printf "$(sed 's/../\\x&/g')" FTW. Linux's non-umbrella model, where there's no cohesive oversight, will be its undoing, I think. I've wanted to do do packet inspection for a little while now, incidentally, and the introduction of TLS 1.3 has been most annoying. https://news.ycombinator.com/item?id=17540111 https://news.ycombinator.com/item?id=17540111 On the subject of AV my favorite thing is https://github.com/taviso/loadlibrary https://github.com/taviso/loadlibrary :P (if just for the very non-official "you totally know Google is using this every day.") One thing I was vaguely considering (last night, actually) was an idea I've had for a while - taking forensic memory-dump analysis tools to the next level and making them work in realtime with QEMU. End result being, you run a tool as root with the PID to a running QEMU instance, it attaches (possibly via process_vm_{read,write}v) and lets you watch VT streams, see keys+passwords being typed in SSH, perhaps take screenshots, see the process tree, etc. Thanks for the tips!