4 ms·
Maybe some NetSec guys could answer this please. What would happen with his update to Notepad++? Would it still update the package? Even if the target set his
by quackerhacker 13y ago
Maybe some NetSec guys could answer this please. What would happen with his update to Notepad++? Would it still update the package?
Even if the target set his computer to auto-update (or something that did not require admin authentication), wouldn't he have some type of notion that something went wrong during his update?
With the target being an InfoSec guy, I would've imagined he would at least be running some type of network monitoring, like wireshark or little snitch, ESP on his personal computer. Wouldn't he have to authorize the outgoing packets?
Sorry, if I come off analytical to the story...it's a great read...I just want to make sure my networks are locked down. I've even went as far as dedicated networks for my server and home usage, and preventing internal ip addresses from communicating to each other (sucks for airplay).
- ma2rten 13y agoWouldn't he have some type of notion that something went wrong during his update? There is a way of injecting your code into an existing executable so that the executable still works like it did before. Basically your code gets called first and than the original program entry point gets called. Wouldn't he have to authorize the outgoing packets? He might have updated this Notepad++ on purpose? He obviously did not know his router was compromised.
- quackerhacker 13y agoThank you. You helped me realized that even if the target had wireshark or little snitch, the router was acting as the MITM since the packets would piggyback on outgoing requests that appeared normal cause of the router's DNS settings. I was trying to figure out how he had the key logger sending out it's packets.
- dehrmann 13y ago> There is a way of injecting your code into an existing executable so that the executable still works like it did before. Only if it's unsigned (or someone doesn't check the signatures) and it's over HTTP. I can't seem to find it, but someone complained about just how hard it is to get a version of putty that you can at least be sure came from the right domain.