Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Bashware attack makes Linux a security threat to Windows 10
BetaNews ^ | Sep 12, 2017 | Mark Wycislik-Wilson

Posted on 09/17/2017 4:59:04 PM PDT by dayglored

While many people welcomed the arrival of Windows Subsystem for Linux (WSL) in Windows 10, it has been found to be a potential security issue. A new technique known as a Bashware has been discovered by security researchers that makes it possible for malware to use the Linux shell to bypass security software.

While administrator access is needed to execute a Bashware attack, this is fairly easily obtained, and the technique can be used to disguise malicious operations from antivirus software and other security tools. Researchers from Check Point Research point out that the danger stems from the fact that "existing security solutions are still not adapted to monitor processes of Linux executables running on Windows."

In a blog post highlighting the Bashware problem, Check Point Research says: "We have recently found a new and alarming method that allows any known malware to bypass even the most common security solutions, such as next generation anti-viruses, inspection tools, and anti-ransomware. This technique, dubbed Bashware, leverages a new Windows 10 feature called Subsystem for Linux (WSL), which recently exited Beta and is now a fully supported Windows feature."

The researchers say that the technique is very easy to exploit, and it can be used to bypass "most of the leading anti-virus and security products on the market." It is said that the attack vector could place all 400 million computers running Windows 10 at risk.

[...much more including video of the attack, at the link...]

(Excerpt) Read more at betanews.com ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: bash; linux; windows10; windowspinglist
Ruh-roh.
1 posted on 09/17/2017 4:59:04 PM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Windows 10 Linux Bash attack ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 09/17/2017 4:59:45 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Do you need physical access to the computer to execute this attack? Do you need to be sitting at the keyboard typing in the evil shell commands?


3 posted on 09/17/2017 5:03:47 PM PDT by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
...makes it possible for malware to use the Linux shell to bypass security software.

While administrator access is needed to execute a Bashware attack...

I'm not a big Windows guy - I only use it when I have to at work and the systems are administered by the IT staff... But it seems to me once an attacker has admin rights, pretty much the entire machine is his/her playground. I'm not seeing anything startling about being able to screw up a machine via this or that once you're an admin on it.

4 posted on 09/17/2017 5:05:51 PM PDT by ThunderSleeps (Doing my part to help make America great again!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: proxy_user
Not sure yet, gotta read more.

Physical access, plus admin rights, has -always- been "game over", so maybe this isn't as big a deal as it's made out to be. Nonetheless, worth a close look.

5 posted on 09/17/2017 5:07:36 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

Oh, well...
I went back to paying bills by post and purchasing with cash quite a while back, knowing that the private computer age would eventually come crashing down due to all the ‘wares’ out there. Just too bloody risky.


6 posted on 09/17/2017 5:08:27 PM PDT by Patriot777 ("When you see these things begin to happen, look up, for your redemption draweth nigh.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: ThunderSleeps

Yes, with administrator rights you can do just about anything you want to do on that Windows computer, but these “things” will be detected when a malware/virus detector is run on the system. But with this new exploit the admin rights are used to install the malware under the linux subsystem whose processes are not currently monitored by many of the popular malware/virus detection products. This allows the malware to remain undetected and continue doing its evil work while your protection software still thinks everything is hunky-dory. These products will be updated shortly to monitor linux subsystem.


7 posted on 09/17/2017 5:31:26 PM PDT by Garth Tater (Gone Galt and I ain't coming back.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored

If you have physical access then you can get into Linux.


8 posted on 09/17/2017 6:16:38 PM PDT by Nateman (If liberals are not screaming you are doing it wrong!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

ok I’m a big dummy when it comes to this stuff- My question is- this isn’t a linux virus that causes this is it? It’s a windows virus that exploits the linux code somehow?

My second question then becomes- if it’s a windows virus that exploits linux- then when using linux only, and browsing to a site with the virus- linux users are still safe, no? Windows woudl have to be running at same time, right?


9 posted on 09/17/2017 8:18:33 PM PDT by Bob434
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

“While administrator access is needed to execute a Bashware attack ...”

doesn’t sound like a promising attack vector if you have to have administrator access.

once you have administrator access then the rest of any attack is mere details anyway.


10 posted on 09/17/2017 9:31:31 PM PDT by catnipman ( Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Garth Tater

Ah, that makes sense, and I see the reason for concern. It’s one thing to have a problem, it’s another thing entirely to have a problem but not know you have a problem.


11 posted on 09/17/2017 10:25:59 PM PDT by ThunderSleeps (Doing my part to help make America great again!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored
While administrator access is needed to execute a Bashware attack, this is fairly easily obtained...

I think I see the real problem here.

12 posted on 09/18/2017 3:59:39 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Nateman
If you have physical access then you can get into Linux.

Not so easy anymore with RHEL 7. Even single user mode requires admin password. It's no longer optional.

13 posted on 09/18/2017 4:02:02 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 8 | View Replies]

To: ShadowAce
>> While administrator access is needed to execute a Bashware attack, this is fairly easily obtained...

> I think I see the real problem here.

Yep.

14 posted on 10/06/2017 5:58:13 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 12 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson