• Login
  • Register
  • Dolphin Forums
  • Home
  • FAQ
  • Download
  • Wiki
  • Code


Dolphin, the GameCube and Wii emulator - Forums › Offtopic › Delfino Plaza v
« Previous 1 ... 6 7 8 9 10 ... 64 Next »

"Give Me CRX" Chrome extension contains virus
View New Posts | View Today's Posts

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Thread Modes
"Give Me CRX" Chrome extension contains virus
10-30-2016, 08:40 PM
#1
Qaazavaca Qaanic
Unregistered
 
So I wrote this thing. How do I get famous? Link: https://gist.github.com/jimbo1qaz/bc73a2491f0c39b7f206359f089dd79c

"Give Me CRX" (https://chrome.google.com/webstore/detail/give-me-crx/acpimoebmfjpfnbhjgdgiacjfebmmmci/reviews) contains a virus hidden in the source code.

Reviewer "Adam Carbonell" first discovered existence of the malware. He mentioned that icon2.png contains malicious code.

bg.js (last modified 11/11/2016) extracts the code by reading icon2.png (last modified 11/10/2016) as text, extracting data between init> and <end strings (I assume a PNG comment), and xor-ing it with char ^ 77.

The resulting text is then run as Javascript. I think around 24 hours after extension installation, every tab will have <script src='hXXp//s3.eu-central-1.amazonaws.com/forton/give_me_crx.js'> injected whenever "chrome.tabs.onUpdated".

This link appears to return an "Access Denied" XML file right now. Was the exploit taken down? Is it not up yet? Did they just infect the extension, and are waiting for a critical mass of users before loading the exploit?

* The exploit was discovered around 10/28/2016. Today is 10/30/2016. The last modified dates point to 11/10/2016, which is in the future.
Reply
10-31-2016, 12:31 AM
#2
Helios Offline
Stellaaaaaaa
**********
Developers (Some Administrators and Super Moderators)
Posts: 4,397
Threads: 15
Joined: May 2012
whoops. I was very confused why this thread was here, I thought it was in the dev forum.

Cool, I guess?
Find
Reply
10-31-2016, 03:42 PM (This post was last modified: 10-31-2016, 03:42 PM by DacoTaco.)
#3
DacoTaco Offline
His royal bitchness Tacoboy
*******
Moderators
Posts: 1,134
Threads: 31
Joined: Mar 2009
well played good sir
[Image: PeachSig.jpg]
[Image: 566286.png]
[Image: 2280403.png]
Website Find
Reply
« Next Oldest | Next Newest »


  • View a Printable Version
  • Subscribe to this thread
Forum Jump:


Users browsing this thread: 1 Guest(s)



Powered By MyBB | Theme by Fragma

Linear Mode
Threaded Mode