• Hackers Are Exploiting a Flaw Microsoft Fixed 9 Years Ago

    Home » Forums » Cyber Security Information and Advisories » Cyber Security for Home Users » Hackers Are Exploiting a Flaw Microsoft Fixed 9 Years Ago

    Author
    Topic
    #2410795
    • This topic was modified 3 years, 4 months ago by unbob.
    • This topic was modified 3 years, 4 months ago by unbob.
    Viewing 1 reply thread
    Author
    Replies
    • #2410824

      An article over on Check Point Research provides a strict Authenticode verification registry key.

      Safety Tips

      We recommend that users apply Microsoft’s update for strict Authenticode verification. To do so, paste these lines into Notepad and save the file with .reg extension before running it.

      Windows Registry Editor Version 5.00
      
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config]
      
      “EnableCertPaddingCheck”=”1”
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config]
      
      “EnableCertPaddingCheck”=”1”

      We should also note that after applying the fix, some signatures of legitimate benign installers will show up with an invalid signature. In addition, if mshta.exe is not relevant in your environment, you may disable it and mitigate the execution of scripts that are inserted into such files….

      Most of the victims downloaded malicious DLL files are found in the USA according to their findings, see graph on linked page above.

      TIP: you may wish to add 134.0.117.16 to your firewall in/outbound block list 😉

      Windows - commercial by definition and now function...
      1 user thanked author for this post.
    • #2411175

      These Unicode double quotes presented here do not work. The command line program reg and (hopefully the regedit program proper) rightly rejects these, replace them using the double quotes on your keyboard and this strict Authenticode checking mitigation will be applied as intended.

    Viewing 1 reply thread
    Reply To: Hackers Are Exploiting a Flaw Microsoft Fixed 9 Years Ago

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: