Dejkala
No Result
View All Result
  • Home
  • Tech
  • Banking & loan
  • Games
  • Car’s & Bike’s
  • Home
  • Tech
  • Banking & loan
  • Games
  • Car’s & Bike’s
No Result
View All Result
Dejkala
No Result
View All Result
Home Latest update

Microsoft is scanning the inside of password-protected zip files for malware- Dejkala

by hasibul
May 16, 2023
in Latest update
0
Microsoft is scanning the inside of password-protected zip files for malware- Dejkala
0
VIEWS
Share on FacebookShare on Twitter


Black and white close up of sinister-looking male eyes looking suspiciously through the slats of a closed venetian blind. Could be a criminal or a stalker or a watchful home owner.

Microsoft cloud services are scanning for malware by peeking inside users’ zip files, even when they’re protected by a password, several users reported on Mastodon on Monday.

Compressing file contents into archived zip files has long been a tactic threat actors use to conceal malware spreading through email or downloads. Eventually, some threat actors adapted by protecting their malicious zip files with a password the end user must type when converting the file back to its original form. Microsoft is one-upping this move by attempting to bypass password protection in zip files and, when successful, scanning them for malicious code.

While analysis of password-protected in Microsoft cloud environments is well-known to some people, it came as a surprise to Andrew Brandt. The security researcher has long archived malware inside password-protected zip files before exchanging them with other researchers through SharePoint. On Monday, he took to Mastodon to report that the Microsoft collaboration tool had recently flagged a zip file, which had been protected with the password “infected.”

“While I totally understand doing this for anyone other than a malware analyst, this kind of nosy, get-inside-your-business way of handling this is going to become a big problem for people like me who need to send their colleagues malware samples,” Brandt wrote. “The available space to do this just keeps shrinking and it will impact the ability of malware researchers to do their jobs.”

Fellow researcher Kevin Beaumont joined the discussion to say that Microsoft has multiple methods for scanning the contents of password-protected zip files and uses them not just on files stored in SharePoint but all its 365 cloud services. One way is to extract any possible passwords from the bodies of email or the name of the file itself. Another is by testing the file to see if it’s protected with one of the passwords contained in a list.

Advertisement

“If you mail yourself something and type something like ‘ZIP password is Soph0s’, ZIP up EICAR and ZIP password it with Soph0s, it’ll find (the) password, extract and find (and feed MS detection),” he wrote.

Brandt said that last year Microsoft’s OneDrive started backing up malicious files he had stored in one of his Windows folders after creating an exception (i.e., allow listing) in his endpoint security tools. He later discovered that once the files made their way to OneDrive, they were wiped off of his laptop hard drive and detected as malware in his OneDrive account.

“I lost the whole bunch,” he said.

Brandt then started archiving malicious files in zip files protected with the password “infected.” Up until last week, he said, SharePoint didn’t flag the files. Now they are.

Microsoft representatives acknowledged receipt of an email asking about the practices of bypassing password protection of files stored in its cloud services. The company didn’t follow up with an answer.

A Google representative said the company doesn’t scan password-protected zip files, though Gmail does flag them when users receive such a file. My work account managed by Google Workspace also prevented me from sending a password-protected zip.

The practice illustrates the fine line online services often walk when attempting to protect end users from common threats while also respecting privacy. As Brandt notes, actively cracking a password-protected zip file feels invasive. At the same time, this practice almost surely has prevented large numbers of users from falling prey to social engineering attacks attempting to infect their computers.

One other thing readers should remember: password-protected zip files provide minimal assurance that content inside the archives can’t be read. As Beaumont noted, ZipCrypto, the default means for encrypting zip files in Windows, is trivial to override. A more dependable way is to use an AES-256 encryptor built into many archive programs when creating 7z files.


ShareTweetShare

Related Posts

Amazon job listings hint at ChatGPT-like conversational AI for online store- Dejkala
Latest update

Amazon job listings hint at ChatGPT-like conversational AI for online store- Dejkala

May 16, 2023
WhatsApp introduces Chat Lock, which lets users put chats in a password- or biometrics-protected folder and hide chats' contents and senders in notifications (Jay Peters/The Verge)- Dejkala
Latest update

WhatsApp introduces Chat Lock, which lets users put chats in a password- or biometrics-protected folder and hide chats' contents and senders in notifications (Jay Peters/The Verge)- Dejkala

May 16, 2023
The best TVs for PS5 of 2023- Dejkala
Latest update

The best TVs for PS5 of 2023- Dejkala

May 15, 2023
Buffalo Mass Shooting Victims’ Families Sue Meta, Reddit, Amazon- Dejkala
Latest update

Buffalo Mass Shooting Victims’ Families Sue Meta, Reddit, Amazon- Dejkala

May 15, 2023
WhatsApp’s new privacy feature locks sensitive chats and hides them from notifications- Dejkala
Latest update

WhatsApp’s new privacy feature locks sensitive chats and hides them from notifications- Dejkala

May 15, 2023
Facebook fixes friend request bug that revealed viewing habits- Dejkala
Latest update

Facebook fixes friend request bug that revealed viewing habits- Dejkala

May 15, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Earn Money Online
  • Game news and review
  • Laptops
  • Latest update
  • Smartphone Reviews & News
  • TODAY Tech News
  • Upcoming Technology
  • Wordpress plugin
  • WordPress themes
  • World Wide Bike Reviews and News
  • World Wide Car News

Recommended

A study finds 11 data brokers selling data on Americans' mental health information, including on antidepressants and insomnia, likely acquired from app makers (Drew Harwell/Washington Post)- Dejkala

A study finds 11 data brokers selling data on Americans' mental health information, including on antidepressants and insomnia, likely acquired from app makers (Drew Harwell/Washington Post)- Dejkala

February 13, 2023
This eufy robot vacuum just dropped to less than $120 at Walmart- Dejkala

This eufy robot vacuum just dropped to less than $120 at Walmart- Dejkala

November 15, 2022
Sources and leaked images: the next Microsoft Surface Dock will debut in coming weeks with Thunderbolt 4 support, a slimmer design, and no proprietary connector (Zac Bowden/Windows Central)- Dejkala

Sources and leaked images: the next Microsoft Surface Dock will debut in coming weeks with Thunderbolt 4 support, a slimmer design, and no proprietary connector (Zac Bowden/Windows Central)- Dejkala

April 3, 2023
Microsoft finally authorizes Windows 11 on Apple M1 and M2 Macs- Dejkala

Microsoft finally authorizes Windows 11 on Apple M1 and M2 Macs- Dejkala

February 17, 2023
Leftover hardware from Mars mission to be used on the Moon- Dejkala

Leftover hardware from Mars mission to be used on the Moon- Dejkala

October 26, 2022
How to automatically convert Google Drive uploads to Docs format- Dejkala

How to automatically convert Google Drive uploads to Docs format- Dejkala

November 10, 2022
Microsoft is scanning the inside of password-protected zip files for malware- Dejkala

Microsoft is scanning the inside of password-protected zip files for malware- Dejkala

May 16, 2023
Amazon job listings hint at ChatGPT-like conversational AI for online store- Dejkala

Amazon job listings hint at ChatGPT-like conversational AI for online store- Dejkala

May 16, 2023
WhatsApp introduces Chat Lock, which lets users put chats in a password- or biometrics-protected folder and hide chats' contents and senders in notifications (Jay Peters/The Verge)- Dejkala

WhatsApp introduces Chat Lock, which lets users put chats in a password- or biometrics-protected folder and hide chats' contents and senders in notifications (Jay Peters/The Verge)- Dejkala

May 16, 2023

Categories

  • Earn Money Online
  • Game news and review
  • Laptops
  • Latest update
  • Smartphone Reviews & News
  • TODAY Tech News
  • Upcoming Technology
  • Wordpress plugin
  • WordPress themes
  • World Wide Bike Reviews and News
  • World Wide Car News

Pages

  • About Us
  • Banking & loan
  • Car’s & Bike’s
  • Contact Us
  • Games
  • Home
  • Home 2
  • Privacy Policy
  • Tech

© 2022 Dejkala

No Result
View All Result
  • Homepages
    • Home – Layout 1
    • Home – Layout 2

© 2022 Dejkala