vissha Posted September 16, 2016 Share Posted September 16, 2016 Windows Safe Mode Can Be Used to Steal PC Logins, Disable Antivirus Software Safe Mode proves to be a valuable tool for hackers Quote Research published by CyberArk, a US cyber-security vendor, reveals various attack scenarios that leverage Windows Safe Mode to carry out malicious attacks undetected, harvest PC credentials from nearby workstations, or to disable security software. The described attack is not a security vulnerability, but an exploitation scenario that can be carried out after a malicious actor has managed to compromise a PC and gain administrator privileges. This hypothetical scenario is more than achievable because Windows computers get compromised with all sorts of malware on a daily basis, and various exploits are freely available to escalate privileges to admin level. Safe Mode can help attackers cripple security software The reason the attack works is because Windows allows applications to prompt the user to restart the PC, and secretly force the restart in Safe Mode. Safe Mode is important to an attacker because it prevents all third-party software from starting, including antivirus systems. When the computer reboots in Safe Mode, an attacker could alter registry keys for applications such as antivirus and anti-malware toolkits, which are hands off in Normal Mode and would trigger a security alert. An attacker with a foothold on an infected system could leverage this technique to disable antivirus software for good and make sure his presence remains undetected until he finishes whatever malicious tasks he wants to carry out. Users should avoid out-of-the-blue Safe Mode reboot prompts Of course, the attack still relies on tricking users to allow the computer to reboot, and not being alarmed that they ended up in Safe Mode. Executing most of the malicious commands while in Safe Mode takes little time, and the computer could then reboot again to Normal Mode, which would look less conspicuous since some Windows installation procedures are known to reboot PCs several times over. Besides disabling security software installed on the PC, this attack scenario can be used to harvest login credentials from computers on the same network by utilizing the Pass-the-Hash attack. Safe Mode can be leveraged to collect login credentials Special tools are needed for this attack. Normally, an attacker would use registry keys to load these tools in Normal Mode. Since these aren't allowed in Safe Mode, the attacker would need to disguise them inside malicious services and COM objects. With all the tools available and loaded, the attacker can then collect NTLM password hashes for nearby PCs, for which tools exist to reverse them back to their cleartext versions. This data can then be passed to the attacker, and used to escalate access to nearby systems when the PC returns to Normal Mode. Additionally, this same attack can be used to steal credentials for the current PC as well. A typical attack relies on rebooting the PC in Safe Mode, showing a login prompt, logging the credentials, and then rebooting the PC in Normal Mode. Because this is not a security vulnerability and also requires attackers to have already compromised systems, Microsoft, who CyberArk informed of this attack scenario, said it can't do anything about it. And theoretically, it can't. Source Link to comment Share on other sites More sharing options...
straycat19 Posted September 16, 2016 Share Posted September 16, 2016 Don't these so-called researchers ever get tired of coming up with bullshit hacks that might work 1 out of 1,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000 times and then only if the 'perfect storm' of events happen. This isn't even deserving of the internet space it wasted. Based on their level of expectations I could say I can hack any computer in the world using the stolen users login credentials. All I have to do is compromise their login credentials thru social engineering and then gain access to their system to enter them. That is more likely to happen than the scenario posted above. Link to comment Share on other sites More sharing options...
Holmes Posted September 16, 2016 Share Posted September 16, 2016 If you tried that on me stray you would fail I would catch on then prank you back (give you bogus credentials) and make you do the whole process for nothing at the end i would say you just got punked. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.