▲ 1639 ▼ Be careful. (feddit.org) submitted 2 years ago by 101@feddit.org to c/technology@lemmy.world 174 comments fedilink hide all child comments Source.
[–] BearOfaTime@lemm.ee 24 points 2 years ago (11 children) Wouldn't it require elevation? Yet another example of why running as root/admin is a Bad Idea© permalink fedilink source hideshow 11 child comments replies: [–] groet@feddit.org 74 points 2 years ago (3 children) No, why would it? It will run code in the context of the current user which is absolutely enough to start a new process that will run in the background, download more code from a attacker server and allow remote access. The attacker will only have as much permissions as the user executing the code but that is enough to steal their files, run a keyloggers, steal their sessions for other websites etc. They can try to escalate to the admin user, but when targeting private victims, all the data that is worth stealing is available to the user and does not require admin privs. permalink fedilink source parent hideshow 3 child comments replies: [–] Womble@lemmy.world 59 points 2 years ago (1 child) permalink fedilink source parent hideshow 1 child comment replies: [–] schizo@forum.uncomfortable.business 17 points 2 years ago This here. The most important thing on your computer are all your session cookies, which are, well, accessible with permissions your user account already has. Dudes don't care about making your shit into a botnet, or putting a rootkit in your firmware, or whatever other technically complex thing you care to think about: they're there to steal your shit, and the most valuable shit you have is sitting there out in the open for the taking for anyone who makes it past a very very low bar of 'make the user do something stupid'. permalink fedilink source parent [–] avidamoeba@lemmy.ca 4 points 2 years ago* Exactly. The moment you hit Enter, the computer becomes part of a botnet on every login. permalink fedilink source parent [–] Treczoks@lemmy.world 4 points 2 years ago Once you run something on windows, elevation is just a thing of using the right toolbox. permalink fedilink source parent [–] IsThisAnAI@lemmy.world 4 points 2 years ago* (4 children) Yes. The prompt asking you if you wanted to do it or not would come up next. Unless they figured out some sneaky way to do something to avoid using admin. permalink fedilink source parent hideshow 4 child comments replies: [–] avidamoeba@lemmy.ca 21 points 2 years ago Deploy a user-level payload that is auto started on login. The computer is now part of the botnet and can already be used for useful ops. Deploy a privilege escalation payload later if needed. permalink fedilink source parent [–] dgriffith@aussie.zone 13 points 2 years ago* (last edited 2 years ago) (2 children) 90% of users when they are presented with the UAC popup when they do something: "Yes yes whateverrr" permalink fedilink source parent hideshow 2 child comments replies: [–] IsThisAnAI@lemmy.world -2 points 2 years ago (1 child) 🤷♂️ people are going to take the path of least resistance permalink fedilink source parent hideshow 1 child comment replies: [–] T156@lemmy.world 1 point 2 years ago It would be trivial to add a "please click 'yes' to the UAC prompt to allow verification" screen, so that isn't really going to stop anyone. I've seen a bit of office malware in the past that did that, where it had a bunch of images instructing you to enable macros and that. permalink fedilink source parent [–] Bezier@suppo.fi 4 points 2 years ago That should be easy on windows, but user permissions might also be enough for whatever it does. permalink fedilink source parent
[–] groet@feddit.org 74 points 2 years ago (3 children) No, why would it? It will run code in the context of the current user which is absolutely enough to start a new process that will run in the background, download more code from a attacker server and allow remote access. The attacker will only have as much permissions as the user executing the code but that is enough to steal their files, run a keyloggers, steal their sessions for other websites etc. They can try to escalate to the admin user, but when targeting private victims, all the data that is worth stealing is available to the user and does not require admin privs. permalink fedilink source parent hideshow 3 child comments replies: [–] Womble@lemmy.world 59 points 2 years ago (1 child) permalink fedilink source parent hideshow 1 child comment replies: [–] schizo@forum.uncomfortable.business 17 points 2 years ago This here. The most important thing on your computer are all your session cookies, which are, well, accessible with permissions your user account already has. Dudes don't care about making your shit into a botnet, or putting a rootkit in your firmware, or whatever other technically complex thing you care to think about: they're there to steal your shit, and the most valuable shit you have is sitting there out in the open for the taking for anyone who makes it past a very very low bar of 'make the user do something stupid'. permalink fedilink source parent [–] avidamoeba@lemmy.ca 4 points 2 years ago* Exactly. The moment you hit Enter, the computer becomes part of a botnet on every login. permalink fedilink source parent
[–] Womble@lemmy.world 59 points 2 years ago (1 child) permalink fedilink source parent hideshow 1 child comment replies: [–] schizo@forum.uncomfortable.business 17 points 2 years ago This here. The most important thing on your computer are all your session cookies, which are, well, accessible with permissions your user account already has. Dudes don't care about making your shit into a botnet, or putting a rootkit in your firmware, or whatever other technically complex thing you care to think about: they're there to steal your shit, and the most valuable shit you have is sitting there out in the open for the taking for anyone who makes it past a very very low bar of 'make the user do something stupid'. permalink fedilink source parent
[–] schizo@forum.uncomfortable.business 17 points 2 years ago This here. The most important thing on your computer are all your session cookies, which are, well, accessible with permissions your user account already has. Dudes don't care about making your shit into a botnet, or putting a rootkit in your firmware, or whatever other technically complex thing you care to think about: they're there to steal your shit, and the most valuable shit you have is sitting there out in the open for the taking for anyone who makes it past a very very low bar of 'make the user do something stupid'. permalink fedilink source parent
[–] avidamoeba@lemmy.ca 4 points 2 years ago* Exactly. The moment you hit Enter, the computer becomes part of a botnet on every login. permalink fedilink source parent
[–] Treczoks@lemmy.world 4 points 2 years ago Once you run something on windows, elevation is just a thing of using the right toolbox. permalink fedilink source parent
[–] IsThisAnAI@lemmy.world 4 points 2 years ago* (4 children) Yes. The prompt asking you if you wanted to do it or not would come up next. Unless they figured out some sneaky way to do something to avoid using admin. permalink fedilink source parent hideshow 4 child comments replies: [–] avidamoeba@lemmy.ca 21 points 2 years ago Deploy a user-level payload that is auto started on login. The computer is now part of the botnet and can already be used for useful ops. Deploy a privilege escalation payload later if needed. permalink fedilink source parent [–] dgriffith@aussie.zone 13 points 2 years ago* (last edited 2 years ago) (2 children) 90% of users when they are presented with the UAC popup when they do something: "Yes yes whateverrr" permalink fedilink source parent hideshow 2 child comments replies: [–] IsThisAnAI@lemmy.world -2 points 2 years ago (1 child) 🤷♂️ people are going to take the path of least resistance permalink fedilink source parent hideshow 1 child comment replies: [–] T156@lemmy.world 1 point 2 years ago It would be trivial to add a "please click 'yes' to the UAC prompt to allow verification" screen, so that isn't really going to stop anyone. I've seen a bit of office malware in the past that did that, where it had a bunch of images instructing you to enable macros and that. permalink fedilink source parent
[–] avidamoeba@lemmy.ca 21 points 2 years ago Deploy a user-level payload that is auto started on login. The computer is now part of the botnet and can already be used for useful ops. Deploy a privilege escalation payload later if needed. permalink fedilink source parent
[–] dgriffith@aussie.zone 13 points 2 years ago* (last edited 2 years ago) (2 children) 90% of users when they are presented with the UAC popup when they do something: "Yes yes whateverrr" permalink fedilink source parent hideshow 2 child comments replies: [–] IsThisAnAI@lemmy.world -2 points 2 years ago (1 child) 🤷♂️ people are going to take the path of least resistance permalink fedilink source parent hideshow 1 child comment replies: [–] T156@lemmy.world 1 point 2 years ago It would be trivial to add a "please click 'yes' to the UAC prompt to allow verification" screen, so that isn't really going to stop anyone. I've seen a bit of office malware in the past that did that, where it had a bunch of images instructing you to enable macros and that. permalink fedilink source parent
[–] IsThisAnAI@lemmy.world -2 points 2 years ago (1 child) 🤷♂️ people are going to take the path of least resistance permalink fedilink source parent hideshow 1 child comment replies: [–] T156@lemmy.world 1 point 2 years ago It would be trivial to add a "please click 'yes' to the UAC prompt to allow verification" screen, so that isn't really going to stop anyone. I've seen a bit of office malware in the past that did that, where it had a bunch of images instructing you to enable macros and that. permalink fedilink source parent
[–] T156@lemmy.world 1 point 2 years ago It would be trivial to add a "please click 'yes' to the UAC prompt to allow verification" screen, so that isn't really going to stop anyone. I've seen a bit of office malware in the past that did that, where it had a bunch of images instructing you to enable macros and that. permalink fedilink source parent
[–] Bezier@suppo.fi 4 points 2 years ago That should be easy on windows, but user permissions might also be enough for whatever it does. permalink fedilink source parent