4 ms·
This is separate from anything an AV might do, so forget the scanner part. A virus scanner with a signature for this malicious JAR will still catch it. What thi
by a2tech 6y ago
This is separate from anything an AV might do, so forget the scanner part. A virus scanner with a signature for this malicious JAR will still catch it. What this is avoiding is the prompt and extra scrutiny Windows throws up if you try and run an executable from the Internet.
Think of the legitimate MSI and malicious JAR files as separate short stories in the same book. The 'book' comes to your computer claiming to be one thing (the legitimately signed MSI) but the second chapter is something completely different (the malicious jar file). When your computer reads the book (calculates and verifies the signature) it only does it off the first chapter. That lets the second part slide under the additional scrutiny Windows applies to files downloaded from the Internet.
- Xylakant 6y agoBy “scanner” I meant the built-in windows defender tooling, which is - afair - affected. It trusts the signature. But you’re entirely correct - a virus scanner that does not rely on the signature w could catch the malicious code. However, this blog post mentions that various security solutions trust the windows code signing, but it does not mention which ones - https://blog.virustotal.com/2019/01/distribution-of-malicious-jar-appended.html?m=1 https://blog.virustotal.com/2019/01/distribution-of-maliciou...
- pbhjpbhj 6y ago>It trusts the signature. // Wtf? Am I reading this right, if part of the file is signed by MS then it just doesn't bother running it through the detection algo? That looks exceedingly like a designed in security hole. Presumably paired with the OP "bug" means MS could, with an NSA letter say, drop malware on devices if those devices were using Windows Defender for AV. Just as well MS don't snoop on what software user's are running./s
- Xylakant 6y agoI may very well be wrong, but that’s how I read the beginning of this blog post: https://medium.com/@TalBeerySec/glueball-the-story-of-cve-2020-1464-50091a1f98bd https://medium.com/@TalBeerySec/glueball-the-story-of-cve-20...: “ Digitally signed files are more trusted by the Operating System. This higher trust allows such files to execute in sensitive contexts or excluded from Antivirus scans.” It seems that msi installer packages with a trusted code signature (1) are excluded from scans by various antivirus protections. Which kind of makes sense: driver packages may contain code that would trigger heuristics a lot. > Presumably paired with the OP "bug" means MS could, with an NSA letter say, drop malware on devices if those devices were using Windows Defender for AV. Microsoft can already do that. To be quite honest - pretty much every institution with the right signing powers can on practically all OS. Have you verified the latest chrome installer package? This bug seems to allow something more insidious: you could download the latest google chrome msi and append your payload jar to that msi and redistribute it. The signature remains valid. This allows bypassing the code signing checks even if you have no code signing powers. (1) not from Microsoft, Microsoft only hands out the certificates, the signing is done by the developer
- lawnchair_larry 6y agoThis isn’t suspicious at all. All AV does it for good reasons, both efficacy and performance related. And no, that’s not how the NSA works.
- pbhjpbhj 6y agoAll AV ignores files which are concatenated to an MS-signed file? Huh, presumably you mean only on Windows, but really? No AV treats .jar files concatenated with signed MSI as suspicious -- how did that situation arise?? It's a strange heuristic. Isn't it like having a special 'I know my bag smells like drugs to sniffer dogs but I promise I don't have drugs' channel at airport arrivals; and when people go down that channel you don't bother to check their bags.
- mulmen 6y agoDon’t we have that? I don’t think TSA pre-check goes through the sniffers. Not sure what benefits that gives on arrival. I know there’s an express lane on the US/Canada border though.
- lawnchair_larry 6y agoYes, kind of like that. That’s basically the point of digital signatures (when they don’t have a bug to bypass them, like in this case). They don’t treat concatenated malicious files as safe, they trust that files signed by MS are safe. You aren’t supposed to be able to concatenate a file and still have the signature check out. That’s the bug. If you want a good reason why, ask McAfee about the time that they incorrectly detected svchost.exe as a virus and made every customer’s windows machine around the world unbootable.