Want to get around app whitelists by pretending to be Microsoft? Of course you can...

Discussion in 'other security issues & news' started by Minimalist, Sep 23, 2017.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.theregister.co.uk/2017/09/22/bypassing_app_whitelists_microsoft_windows/
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Good find.:thumb:

    Not only can this subvert signed PowerShell script enforcement via AppLocker, it can also do the same to Device Guard. Additionally, this bypass just doesn't apply to Powershell scripts as noted below. Just one more in a never ending example parade that Windows native protections are crap:


    https://specterops.io/assets/resources/SpecterOps_Subverting_Trust_in_Windows.pdf
     
  3. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    The exploit itself is rather a mute point, the real issue is, as he said,
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.