Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Researcher Finds Tor Exit Node Adding Malware to Binaries
The Kaspersky Lab Security News Service ^ | October 24, 2014 , 12:07 pm | Dennis Fisher

Posted on 10/24/2014 6:54:44 PM PDT by Utilizer

A security researcher has identified a Tor exit node that was actively patching binaries users download, adding malware to the files dynamically. The discovery, experts say, highlights the danger of trusting files downloaded from unknown sources and the potential for attackers to abuse the trust users have in Tor and similar services.

Josh Pitts of Leviathan Security Group ran across the misbehaving Tor exit node while performing some research on download servers that might be patching binaries during download through a man-in-the middle attack. Downloading any kind of file from the Internet is a dodgy proposition these days, and many users know that if they’re downloading files from some random torrent site in Syria or The Marshall Islands, they are rolling the dice. Malware runs rampant on these kinds of sites.

But the scenario that worries security experts much more involves an attacker being able to control the download mechanism for security updates, say for Windows or OS X. If an attacker can insert malware into this channel, he could cause serious damage to a broad population of users, as those update channels are trusted implicitly by the users’ and their machines. Legitimate software vendors typically will sign their binaries and modified ones will cause verification errors. What Pitts found during his research is that an attacker with a MITM position can actively patch binaries–if not security updates–with his own code.

(Excerpt) Read more at threatpost.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: binaries; malware; mswindows; securitybreach; tor
Navigation: use the links below to view more comments.
first previous 1-2021-23 last
To: Swordmaker

Amazing...I actually understood most of that information, thank you. You should be teaching.


21 posted on 10/25/2014 7:13:08 AM PDT by Kackikat (Two wrongs do NOT make a right.... unless you are a Democrat!)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Utilizer

Utilizer - Thanks very much. Your explanation is comprehend-able to me.

Appreciate the time and help.


22 posted on 10/26/2014 5:37:37 PM PDT by Tainan (Cogito, ergo conservatus sum -- "The Taliban is inside the building")
[ Post Reply | Private Reply | To 16 | View Replies]

To: Tainan

Quite welcome. Hope you got some useable information from the information the article was discussing.

Cheers!


23 posted on 10/26/2014 10:58:04 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 22 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-23 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson