Malware Authors Seem Intent on Weaponizing Windows SettingContent-ms Files (bleepingcomputer.com)
An anonymous reader shares a report: Malware authors are frantically trying to weaponize a new infection vector that was revealed at the start of June. The trick relies on using Windows Settings (.SettingContent-ms) shortcut files in order to achieve code execution on Windows 10 PCs. Ever since SpecterOps security researcher Matt Nelson published his research on the matter three weeks ago, malware authors have been playing around with proof-of-concept code in attempts of crafting an exploit that can deploy weaponized malware on a victim's system. With each passing day, more and more exploits are being uploaded on VirusTotal.
See subject & APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between characters & download).
Yields more security/speed/reliability/anonymity vs. any SINGLE solution (99% of threats = hostnames vs. IP address that most firewalls use) more efficiently/FASTER + NATIVELY 4 less!
(Vs. "Bolt on 'MoAr' illogic-logic" competitors slowing you, hosts speed you up 2 ways (adblocks + hardcodes u spend most time @) vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads (messagepass ('souled-out' to advertiser addons) + filtering drivers) & their complexity leads to exploitation).
* ONLY 1 of its kind in GUI on Linux!
Better vs. Windows model in speed/efficiency/merge.
APK
P.S.=> See subject: Block script & malicious site sources used to infest you via the best ad + threat blocker there is above, bar-none... apk
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid - by JazzLad April 20, 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
that APK guy, I use his host file by rogoshen1 Tuesday March 03, 2015
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* Best part's Linux 64-bit model's faster/more efficient (2x work in 1/2 the time)
APK
P.S.=> For a faster/safer/more reliable internet... apk
Good description of the .SettingContent-ms exploit - I would have thought that this would jump out to a Malware author as soon as the feature was announced (regardless of the fact that there is ASR used by large network sysadmins).
Doesn't Microsoft have a bunch of people on staff that think like black hats (probably because they used to be them) with the task of looking for problems like this? At the very least shouldn't somebody have twigged onto the idea that providing a new way to allow new programs to run (as well as spawn new processes) be something that Microsoft security should review?
Mimetics Inc. Twitter
Sure, we all know that *BSD is a failure, but why? Why did *BSD die? Once you get past the fact that *BSD is fragmented between a myriad of incompatible kernels, there is the historical record of failure and of failed operating systems. *BSD experienced moderate success about 20 years ago in academic circles. Since then it has been in steady decline. We all know *BSD effectively lost all of its market share but why? Is it the problematic personalities of many of the key players? Or is it largerthan their troubled personas?
The record is clear on one thing: no operating system has ever come back from the grave. Efforts to resuscitate *BSD are one step away from spiritualists wishing to communicate with the dead. As the situation grows more desperate for the adherents of this doomed OS, the sorrow takes hold. An unremitting gloom has settled in. Now is the end time for *BSD.
BSD users must call National Suicide Prevention Lifeline Call 1-800-273-8255
See subject & APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between characters & download).
Yields more security/speed/reliability/anonymity vs. any SINGLE solution (99% of threats = hostnames vs. IP address that most firewalls use) more efficiently/FASTER + NATIVELY 4 less!
(Vs. "Bolt on 'MoAr' illogic-logic" competitors slowing you, hosts speed you up 2 ways (adblocks + hardcodes u spend most time @) vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads (messagepass ('souled-out' to advertiser addons) + filtering drivers) & their complexity leads to exploitation).
* ONLY 1 of its kind in GUI on Linux!
Better vs. Windows model in speed/efficiency/merge.
APK
P.S.=> See subject: Block script & malicious site sources used to infest you via the best ad + threat blocker there is above bar-none... apk
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid - by JazzLad April 20, 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
that APK guy, I use his host file by rogoshen1 Tuesday March 03, 2015
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* Best part = Linux 64-bit model's faster/more efficient (2x work in 1/2 the time)
APK
P.S.=> For a faster/safer/more reliable internet... apk
See subject & APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between characters & download).
Yields more security/speed/reliability/anonymity vs. any SINGLE solution (99% of threats = hostnames vs. IP address that most firewalls use) more efficiently/FASTER + NATIVELY 4 less!
(Vs. "Bolt on 'MoAr' illogic-logic" competitors slowing you, hosts speed you up 2 ways (adblocks + hardcodes u spend most time @) vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads (messagepass ('souled-out' to advertiser addons) + filtering drivers) & their complexity leads to exploitation).
* ONLY 1 of its kind in GUI on Linux!
Better vs. Windows model in speed/efficiency/merge.
APK
P.S.=> See subject - Block malscript & malicious site sources used to infest you via the best ad + threat blocker there is above bar-none... apk
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid - by JazzLad April 20, 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
that APK guy, I use his host file by rogoshen1 Tuesday March 03, 2015
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* Best part = Linux 64-bit model's faster/more efficient (2x the work in 1/2 the time)
APK
P.S.=> For a faster/safer/more reliable internet... apk
In case this is news to you and you're wondering about this vulnerability, here's a description. .SettingContent-ms) to link to settings pages. In this format a <DeepLink> tag contains the application to run in order to display the settings page. So like program information files (.pif), shortcuts (.lnk), batch files (.bat) and so on these should be treated as executable programs, because these files can do anything the author wishes. Just specify "%WINDIR%\System32\cmd.exe /c ..." as the command line.
Microsoft has introduced a new file format (extension:
But apparently Microsoft itself didn't appropriately mark the new shortcut file type as executable and because it's a new file type, third-party vendors of things like anti-virus software, web browsers and e-mail clients haven't caught up yet either.
All those wankers claiming Win10 is inherently safer than Win7 because it is "new" and "supported".
Fucking idiots the lot of them.
Just try to imagine all of the new code in Win10 and the as-yet undiscovered exploits, just like this one.
Code gets stronger/better/safer over time, which is almost the exact opposite of physical goods.
You admit that your solution is ineffective on its own - by UNIDENTIFIABLE Anonymous STALKER of APK
Where'd I say what YOU falsely accuse me of as you STALK ME by your "courageous" (not) full of "integrity" (not) UNIDENTIFIABLE anonymous posts?
Heuristics generate false positives - & I've proven ArcaVir, Baidu, CA, ClamAV, Comodo, Crowdstrike, Emsisoft, McAfee, NOD32/ESET, Norton/Symantec, Qihoo, SentinelOne, Sophos & Trend WRONG on it (& Tavis Ormandy found SECURITY ISSUES in 'em).
* People from AV companies say hosts = good security.
Also - I never say I DON'T USE DNS. I do (sub 2% of the time & rest avoids DNS issues on 100 of my fav sites I spend most time @ hardcoded in hosts resolving FASTER vs. dns).
APK
P.S.=> I save more vs. 5 min it takes to haul in 1st data set + 2 min merge (small partial data) in blocking ads + speedup from local resolution (vs. DNS security issues, tracking, & slower resolution) vs. running my work... apk
See subject & learn 2 read https://tech.slashdot.org/comm... - twisted to "not effective on its own" by YOU unidentfiable anonymous lunatic liar!
100's of botnets & other threats I've shown hosts NULLIFY prove it!
* I avoid DNS request logs is HOW dumbo hosts help anonymity (99% of the time approximately on 100 favorite sites I spend most time @ avoiding redirect poisoning & down DNS too + RESOLVE FASTER LOCALLY!) - a reverse DNS proxy might nullify that but rare.
APK
P.S.=> 2 minutes per day updates = SMALL PRICE TO PAY vs. INFECTION REMOVAL TIME (which I can't touch sources of so I don't go thru that) + gaining faster local resolution speed (vs. remote DNS slow roundtrip) & more speed ad & script blocking... apk
I too say hosts don't cure all & so do they (NOTHING does - hosts just do more vs. any other method for far less & natively + faster).
* When I call out to DNS, then dns requestlogs = aware of me - HOWEVER:
Using hosts, I bypass DNS for 99% of my queries (as weill most people - it's like T.V. - we all have favorite channels we like where you spend most time @ online (& I get you there FASTER bypassing DNS too + making you safer vs. its security flaws OR being down)).
(I'll take ms (I didn't have in my favor before hosts' use) that add up in a dragrace too that also secures you vs. tracking + does it faster than remote dns does, safer vs. it's security flaws)
APK
P.S.=> You think & act like you snort crank & smoke it for breakfast lunch + dinner (lol) 24x7... apk
See subject & APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between characters & download).
Yields more security/speed/reliability/anonymity vs. any SINGLE solution (99% of threats = hostnames vs. IP address that most firewalls use) more efficiently/FASTER + NATIVELY 4 less!
(Vs. "Bolt on 'MoAr' illogic-logic" competitors slowing you, hosts speed you up 2 ways (adblocks + hardcodes u spend most time @) vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads (messagepass ('souled-out' to advertiser addons) + filtering drivers) & their complexity leads to exploitation).
* ONLY 1 of its kind in GUI on Linux!
Better vs. Windows model in speed/efficiency/merge.
APK
P.S.=> See subject: Block malscript & malicious site sources used to infest you via the best ad/threat blocker there is bar-none above... apk
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid - by JazzLad April 20, 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
that APK guy, I use his host file by rogoshen1 Tuesday March 03, 2015
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* Best part's Linux 64-bit model's faster/more efficient (2x the work in 1/2 the time)
APK
P.S.=> For a faster/safer/more reliable internet... apk
See subject Mr. ADVERTISER/MalwareMaker/Inferior competitor: Registered /.ers disagree w/ you unidentifiable anonymous stalker of me!
* Funny how those "downmods" only come the NEXT DAY when you via your MULTIPLE SOCKPUPPET alternate accounts you use to farm "downmodpoints" get more of them the next day (to NO avail - I simply repost eventually/inevitably RUNNING YOU DRY of them, lol - outthinking/outsmarting AND JUST PLAIN "OUTING" you as I have now).
APK
P.S.=> You're powerless vs. me - accept it & give up already, lol - but I certainly have POWER over YOU: FEAR! You fear to face me directly via your main sockpuppet account (as I've probably DUSTED you in tech debate beneath it & your other sockpuppets 1 by 1 over time)... apk
Learn 2 read https://tech.slashdot.org/comm... twisted 2 "not effective on its own" by U unidentfiable anonymous lunatic liar (see subject & LMAO).
100's of botnets & other threats I've shown hosts NULLIFY prove it!
* I avoid DNS request logs is HOW dumbo hosts help anonymity (99% of the time approximately on 100 favorite sites I spend most time @ avoiding redirect poisoning & down DNS too + RESOLVE FASTER LOCALLY!) - a reverse DNS proxy might nullify that but rare.
HOW DO I KNOW I WON (don't have to try, you defeat yourself for me, lol)?
YOU TRIED "DOWNMOD HIDING" THIS VERY SAME POST https://tech.slashdot.org/comm...
APK
P.S.=> 2 minutes per day updates = SMALL PRICE TO PAY vs. INFECTION REMOVAL TIME (which I can't touch sources of so I don't go thru that) + gaining faster local resolution speed (vs. remote DNS slow roundtrip) & more speed ad & script blocking... apk
Nelson contacted Microsoft, but the OS maker did not consider this a vulnerability in the OS.
Thanks a lot, Microsoft.
Hohohohoho see the CLASSIC proof of that here soyboys as you DRINK the golden wine https://tech.slashdot.org/comm... straight from MY tap (of GOLDEN piss), all natural ingredients, naturally filtered (of ME pissing right into your shitbag mouths & funniest part is, you help me DO it - you LIKE it, lol!).
Do you LIKE the taste? Obviously yes - just like folks like my hosts engine, anything I put out, even piss, is GOOD (unlike "your kind").
Above all else though? Hey - MOMMY LOVES YOU!
APK
P.S.=> Hahahahaha (I think this is the BEST overall letting you SHEMALE soyboys destroy yourselves for GOLD (ask SuckerBERG about that - he's the expert as is all his kind are - heading into ZylonB & Furnace time again judging by what's happening - the PRICE of it is that, always, they don't learn)... apk
Obviously U FEAR me hiding by UNIDENTIFIABLE anonymous you HARASS me w/ FAILING hosts vs. whitelist https://news.slashdot.org/comm...
You STALK ME by UNIDENTIFIABLE anonymous & LOSE vs. me EVERYTIME (see link above).
What GIVES AWAY you know you lost? 2 things:
HIDING my parent post (came RIGHT after link above & you "downmod hid it" - but unlike MOST ac's I have NO POST LIMIT & RUN YOU DRY of your limited # of "downmodpoints" you ABUSE & I repost).
You give it away MORE you got NUKED by me as you do FLURRIES of posts to try "forums slide" BURY you got your ass kicked - you must be sadomasochists! APK
P.S.=> & MULTIPLE personalities? YOU losers do SOCKPUPPETS galore OR FAKE NAMES for your FAKE LIES of WASTED lives - proof?? Look @ Zontar's "TrollingForHostsFiles" https://slashdot.org/comments.... to HARASS & STALK me (I dusted him in BOTH guises FAKE NAME & sockpuppet)... apk
See subject & my ps (classic, lol): There's REALITY https://yro.slashdot.org/comme... that works vs. SOYboy addled by estogen mimickers in SOYMilk (lol, that you're addicted to) "Phantasy" - lol!
... apk
I see your estrogen is LOW - lol, don't worry: Make SURE you put your soymilk in bisphenol A plastic containers (You'll get a "good dose" then - you need it (Cravings to be a woman, you sure act like one you do-nothing "ne'er-do-well", lol)).
Eventually, you'll get SO bad you'll inject it like Bruce Willis in LOOPER (you are 'loopy' lol) from Year 6 -> Year 23 (LMAO).
* RoTfLmAo... you want to get rid of me/kill me? For once you're doing a GOOD job making me laugh myself to death!
Ah, it's good to see I've BLOWN you away w/ truth & fact & YOU ARE OUT OF DOWNMODPOINTS evidently (your kind? Can't EVER win vs. guys like me - accept it - your destiny in this LIFE was to be the LOSER almost WOMAN you are, lol).
APK
P.S.=> Hahahahaha "HELP ME MOMMY" lmao (apk's outsmarted us AGAIN & ran us DRY of our ABUSED "downmodpoints" lol) https://tech.slashdot.org/comm...