3 ms·
Up to now, I confirm I can reproduce the following steps: - download of official "iventoy-1.0.20-win64-free.zip" - extraction of "iventoy.dat" - conversion b
by _a8di 1y ago
Up to now, I confirm I can reproduce the following steps:
- download of official "iventoy-1.0.20-win64-free.zip"
- extraction of "iventoy.dat"
- conversion back to "iventoy.dat.xz" thanks to @ppatpat's Python code
- confirm that "wintool.tar.xz" is recognized by VirusTotal as something that injects fake root certificates
The next steps are scary, given the popularity of Ventoy/iVentoy :
> Analyzing "iventoy.dat.xz\iventoy.dat.\win\vtoypxe64.exe" we see it includes a self signed certificate named "EV" certificate "JemmyLoveJenny EV Root CA0" at offset=0x0002C840 length=0x70E.
> vtoypxe64.exe programmatically installs this certificate in the registry as a "trusted root certificate"
- Maxious 1y agoJemmyLoveJenny still lives! https://www.bleepingcomputer.com/news/security/hackers-exploit-windows-policy-to-load-malicious-kernel-drivers/ https://www.bleepingcomputer.com/news/security/hackers-explo...
- _a8di 1y agoPlaying devil's advocate, could it be that they require a temporary access to a customized Windows driver (and thus they fake a trusted root certificate) to make Ventoy work? If that's the case, they should have documented it properly in the source... Or do you think it's 100% malicious?
- ziml77 1y agoThis year old issue regarding blobs in the repo with a ton of replies has not gotten responses from the author https://github.com/ventoy/Ventoy/issues/2795 https://github.com/ventoy/Ventoy/issues/2795 Doesn't mean for sure it's malicious but them not even explaining why there's blobs like this is very suspicious.
- Maxious 1y agoI think regardless of intent, it is a security vulnerability to install these ring 0 loopholes. Microsoft is cracking down on RGB lighting and anticheat software drivers similarly