4 ms·
The tricky bit I imagine is the gap between step 4 and step 5 in your attack scenario. To get this to trigger you need to get the JRE to invoke on the MSI file.
by a2tech 6y ago
The tricky bit I imagine is the gap between step 4 and step 5 in your attack scenario. To get this to trigger you need to get the JRE to invoke on the MSI file. The JRE isn't typically associated with MSIs so you would need a secondary step to trigger the JRE to look at that file and load the malicious JAR tacked on to the end of the MSI.
- phire 6y agoNo, because the attacker renames the file to .jar before sending it to the target. Windows still sees it as a MSI file while doing signature checking. But because it has a .jar extension, the JRE runs it when you double click. Signature verification is done as a independent check, completely separate from execution. Because windows needs to know the signature is valid before even allowing the file to be executed. It also needs to show the signature check in the right-click -> properties dialog.
- Lammy 6y agoYou shouldn't assume the rename process or payload execution have to be manually triggered. That's what browser exploits are for :)