Site icon WinCert

Windows 10 custom themes can be used to steal user credentials

<p>Security researcher Jimmy Bayne discovered a new Windows 10 vulnerability in the operating system&&num;8217&semi;s themes engine that can be used to steal users&&num;8217&semi; credentials&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-2929" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;01&sol;theme2&lowbar;accent&period;jpg" alt&equals;"" width&equals;"844" height&equals;"480" &sol;><&sol;p>&NewLine;<blockquote class&equals;"twitter-tweet" data-width&equals;"500" data-dnt&equals;"true">&NewLine;<p lang&equals;"en" dir&equals;"ltr">&lbrack;Credential Harvesting Trick&rsqb; Using a Windows &period;theme file&comma; the Wallpaper key can be configured to point to a remote auth-required http&sol;s resource&period; When a user activates the theme file &lpar;e&period;g&period; opened from a link&sol;attachment&rpar;&comma; a Windows cred prompt is displayed to the user 1&sol;4 <a href&equals;"https&colon;&sol;&sol;t&period;co&sol;rgR3a9KP6Q">pic&period;twitter&period;com&sol;rgR3a9KP6Q<&sol;a><&sol;p>&NewLine;<p>&mdash&semi; bohops &lpar;&commat;bohops&rpar; <a href&equals;"https&colon;&sol;&sol;twitter&period;com&sol;bohops&sol;status&sol;1302264069311926274&quest;ref&lowbar;src&equals;twsrc&percnt;5Etfw">September 5&comma; 2020<&sol;a><&sol;p><&sol;blockquote>&NewLine;<p><script async src&equals;"https&colon;&sol;&sol;platform&period;twitter&period;com&sol;widgets&period;js" charset&equals;"utf-8"><&sol;script><&sol;p>&NewLine;<p>Windows 10 allows you to create and share themes by navigating to <strong>Settings &vert; Personalization &vert; Themes<&sol;strong> and then selecting the <em><strong>Save theme for sharing option<&sol;strong><&sol;em>&period; This action will create a new file with <strong>&ast;deskthemepack<&sol;strong> extension that can be shared with other Windows 10 users&period;<&sol;p>&NewLine;<p>Attackers have found a way to exploit this vulnerability by creating a malicious theme that asks for user credentials once opened&period; When users types their credentials an NTLM hash is sent to a malicious web site&period; Furthermore&comma; an attacker can then use de-hashing software to crack non-complex passwords&period;<&sol;p>&NewLine;<p>To avoid being hacked&comma; we advise you to download only themes from trusted sources like <a href&equals;"https&colon;&sol;&sol;www&period;microsoft&period;com&sol;en-us&sol;store&sol;collections&sol;windowsthemes" target&equals;"&lowbar;blank" rel&equals;"noopener noreferrer">Microsoft Store<&sol;a>&period;<&sol;p>&NewLine;

Exit mobile version