Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Thursday May 25 2017, @11:08PM   Printer-friendly
from the another-day-another-UAC-bypass dept.

Malware authors have a new UAC bypass technique at their disposal that they can use to install malicious apps on devices running Windows 10.

Responsible for discovering this new UAC bypass method is a German student that goes online by the name of Christian B., currently working on his master's thesis, centered on UAC bypass techniques.

The technique he came up with is a variation on another Windows 10 UAC bypass method discovered by security researcher Matt Nelson in August 2016.

While Nelson's method used the built-in Event Viewer utility (eventvwr.exe), Christian's UAC bypass uses the fodhelper.exe file, located at:

C:\Windows\System32\fodhelper.exe

If this file name isn't familiar to you, this is the window that appears when you press the "Manage optional features" option in the "Apps & features" Windows Settings screen.

Both techniques work in the same way and take advantage of what's called "auto-elevation," which is a state that Microsoft assigns to trusted binaries (files signed with Microsoft certificate, and located in trusted locations such as "C:\Windows\System32").

Just like eventvwr.exe, fodhelper.exe is also a trusted binary, meaning Windows 10 won't show a UAC window when launched into execution, or when other processes spawn from the fodhelper.exe parent process.

The technique employs changing the value of a registry key to contain the command to be executed. Since fodhelper.exe is trusted, the command is executed without the UAC prompt. The article continues with how to avoid the exploit. First off, do NOT run as an Administrator by default. Second, set the UAC level to "Always notify."

Bleeping Computer


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2, Insightful) by Anonymous Coward on Friday May 26 2017, @12:07AM (6 children)

    by Anonymous Coward on Friday May 26 2017, @12:07AM (#515759)

    master's thesis, centered on UAC bypass techniques

    Um, what?? Bypassing security features of proprietary operating systems, I did in grade school. I did it for fun and I got no credit for it from anyone. If this jerk deserves a master's degree for kids' stuff, I demand ten doctorates. Right now. Give. Keep them coming. I'm feeling another idea coming out.

    Starting Score:    0  points
    Moderation   +2  
       Flamebait=1, Insightful=2, Funny=1, Total=4
    Extra 'Insightful' Modifier   0  

    Total Score:   2  
  • (Score: -1, Flamebait) by Anonymous Coward on Friday May 26 2017, @12:29AM

    by Anonymous Coward on Friday May 26 2017, @12:29AM (#515767)

    You fucked around with kid's stuff before malware became big business. There's a shitton of money in malware research but not for bitter old washed up whiners like you. You're just not valuable. Kill yourself.

  • (Score: 0) by Anonymous Coward on Friday May 26 2017, @02:53AM (1 child)

    by Anonymous Coward on Friday May 26 2017, @02:53AM (#515802)

    Did you document it and write a paper up on it then defend it or just brag about it?

    Sometimes once the work is done the bullshit has just begun. You did the 'fun' part then skipped the showing why it works part...

    • (Score: 0) by Anonymous Coward on Friday May 26 2017, @03:20PM

      by Anonymous Coward on Friday May 26 2017, @03:20PM (#515991)

      Or showing that it actually works.

  • (Score: 4, Insightful) by canopic jug on Friday May 26 2017, @04:55AM

    by canopic jug (3949) Subscriber Badge on Friday May 26 2017, @04:55AM (#515836) Journal
    M$ pays colleges now days. Their tactic seems to be to dump a paltry sum of money into a department and that results in all the M$-paid researchers dropping their real work and turning into M$ marketeers. Then if the results get published in a blog somewhere, the former researcher adds "... and M$ Research" to the credits at the top. It's pure marketing.
    --
    Money is not free speech. Elections should not be auctions.
  • (Score: 0) by Anonymous Coward on Friday May 26 2017, @06:14AM (1 child)

    by Anonymous Coward on Friday May 26 2017, @06:14AM (#515857)

    Everybody has a degree today, so degrees are worthless because they represent nothing.

    • (Score: 4, Interesting) by canopic jug on Friday May 26 2017, @09:36AM

      by canopic jug (3949) Subscriber Badge on Friday May 26 2017, @09:36AM (#515902) Journal

      They are also worth nothing because they contain nothing. That situation now extends especially to Computer Science degrees.

      As degree programmes fall to M$, they start churning out fools that know nothing except how to resell M$ products. This has been going on long enough that they are feeding back into the system and replacing faculty members, creating a downward spiral. Each year that goes by, there are fewer people left than know about computers and fewer that can do anything advanced. In a generation or two, real generations not academic generations, we'll be in a situation were we have mostly information communication technologies that completely fail to perform. Of those few that still work, no one will know how to maintain them let alone how to change or improve them.

      --
      Money is not free speech. Elections should not be auctions.