Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 10th, 2012, 02:26 PM
Dermot7's Avatar
Dermot7 Dermot7 is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Surrey, England.
Posts: 1,842
Default How a malicious help file can install a spyware keylogger

Quote:
Do you think that Windows help file is safe? Think again.
Malware authors can create boobytrapped .HLP files, designed to infect your computer.
http://nakedsecurity.sophos.com/2012...ger-help-file/
__________________
A man's pride shall bring him low: but honour shall uphold the humble in spirit: Proverbs 29,23.
"Only the wasteful virtues earn the sun": William Butler Yeats, April 27, 1916.
  #2  
Old September 10th, 2012, 04:00 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: How a malicious help file can install a spyware keylogger

Pretty clever!

The use of creating boobytrapped files to load or run malicious executables goes back quite a few years.

While today's exploits rely mostly on social engineering tactics, at least 8 years ago, cybercriminals were using different file types in remote code execution exploits. Here are a few from that period:

http://urs2.net/rsj/computing/tests/files_exec


----
rich
  #3  
Old September 10th, 2012, 06:45 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,846
Lightbulb Re: How a malicious help file can install a spyware keylogger

Actually the use of .HLP for malware etc purposes dates back quite a number of years. I don't have specifics to hand, but due to my hearing about such a vector, i've selected ProcessGuard to block/prompt me each & every time

Name:  pg.gif
Views: 241
Size:  23.0 KB

If i DENY it, then i get this

Name:  inv.gif
Views: 243
Size:  3.4 KB

Personally i don't expect to be infected in such a way but it pays to be cautious. Plus after a disguised .HLP was alowed to run, it would need to also run the other files, such as .EXE/SYS/DLL etc. PG & other protection would automatically also block/prompt me each & every time, to those too

People with similar software/solutions can/could do the same.
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #4  
Old September 10th, 2012, 07:49 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: How a malicious help file can install a spyware keylogger

Quote:
Originally Posted by CloneRanger
Actually the use of .HLP for malware etc purposes dates back quite a number of years. I don't have specifics to hand,
Here are a couple:

http://blog.trendmicro.com/calling-w...-vulnerability

http://www.virusbtn.com/news/2011/09_14.xml

Quote:
Originally Posted by CloneRanger
but due to my hearing about such a vector, i've selected ProcessGuard to block/prompt me each & every time

With PG set up the way you show, can you run a legitimate Help file on your system?


----
rich
  #5  
Old September 10th, 2012, 09:09 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,846
Default Re: How a malicious help file can install a spyware keylogger

Quote:
Originally Posted by Rmus

Here are a couple:

Good examples

Quote:
With PG set up the way you show, can you run a legitimate Help file on your system?

Yes, by clicking ALLOW. But whenever i Allow something that's normally Prompted, i do NOT also tick Always perform this action as that would make the action from then on allowed on All such files, unless i reconfigured the permissions back again.

As it only takes a few seconds to Allow or Deny, it's no big deal for me, & unless i'm installing or running something new etc, i don't get prompted all the time. I'm sure you are in a similar situation with DeepFreeze.
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #6  
Old September 12th, 2012, 02:25 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,416
Default Re: How a malicious help file can install a spyware keylogger

Quote:
Originally Posted by Dermot7

I don't want to think again.
Sensational shock info from a company selling security for money.
Boring.
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #7  
Old September 12th, 2012, 06:43 AM
PJC PJC is offline
Very Frequent Poster
 
Join Date: Feb 2010
Location: Internet
Posts: 2,962
Question How a malicious help file can install a spyware keylogger

After PDFs and Images, Help files...
What's next?
  #8  
Old September 12th, 2012, 02:36 PM
safeguy's Avatar
safeguy safeguy is offline
Frequent Poster
 
Join Date: Jun 2010
Location: Singapore
Posts: 872
Default Re: How a malicious help file can install a spyware keylogger

Just a FYI. Windows Help format is not supported in Vista and later. You have to manually obtain the Windows Help program (WinHlp32.exe) if you want it.

-http://support.microsoft.com/kb/917607-
__________________
Uncertainty is the only certainty there is, and knowing how to live with insecurity is the only security...
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:28 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums