Worst Zero Day Ever? Log4J vulnerability exposes billions of devices to hackers

  Рет қаралды 74,903

The PC Security Channel

The PC Security Channel

2 жыл бұрын

Video sponsor: Intezer. Check out analyze.intezer.com/
We provide cybersecurity tests & consulting for business: tpsc.tech/
Buy the best antivirus in our tests: thepcsecuritychannel.com/best...
Log4J or Log4Shell has taken the world by storm in the last few days and is possibly the worst zero day vulnerability in modern times. It can affect all Java applications, webservers and clients on both Windows and Linux. We have even seen ransomware deployed by this threat vector. If you want to learn to protect yourself from such threats don't forget to subscribe: kzbin.info...
Intezer Demo: • Detecting Log4j RCE (L...

Пікірлер: 190
@julkiewicz
@julkiewicz 2 жыл бұрын
Finally, Java's promise realized: write once run everywhere.
@lars3285
@lars3285 2 жыл бұрын
I was so happy when i saw that my Antivirus Company did make a Update in their Exploit Blocker for this Zero Day.
@meganjordaan6690
@meganjordaan6690 2 жыл бұрын
What av are u using
@lars3285
@lars3285 2 жыл бұрын
@@meganjordaan6690 eset
@thevault1575
@thevault1575 2 жыл бұрын
@Cherish God He said eset
@lars3285
@lars3285 2 жыл бұрын
@Cherish God I use the Smart Security Premium because i realy like the password Manager
@maariojm
@maariojm 2 жыл бұрын
@@lars3285 I love Eset and I think that they have improve a lot with Eset Liveguard technology. I woukd really like to see Leo testing it with some advanced configuration because Eset by default is not as good but I'd you configure it correctly it's really effective.
@mysteryunknown1139
@mysteryunknown1139 2 жыл бұрын
Can you do a video on Kaspersky or like McAfee proactiveness against ransomware or malware deployed through log4j, or will this have no affect on them?
@curiousottman
@curiousottman 2 жыл бұрын
Our cloudflare WAP logs show so many hits from numerous Russian and Chinese IPs. What a nightmare.
@atpray
@atpray 2 жыл бұрын
This would be something that will go in history textbooks.
@breakingthe4thwall260
@breakingthe4thwall260 2 жыл бұрын
Thanks for the heads up Leo
@wilfredotorres6628
@wilfredotorres6628 2 жыл бұрын
Hi Leo, This is almost as bad as snatch-and-grab it seems that criminals are becoming more aggressive under the circumstances and there doesn't seem to be enough serious punishment to wavier these crimes.
@mintsushi9598
@mintsushi9598 2 жыл бұрын
fun fact: the company whcih exploited that is from china according to another video, they're probably doing that just for competitive reasons which sucks
@finoderi
@finoderi 2 жыл бұрын
There isn't enough punishment for retarded programming.
@mintsushi9598
@mintsushi9598 2 жыл бұрын
r word
@finoderi
@finoderi 2 жыл бұрын
@@mintsushi9598 I don't give a fuck.
@BigBlackCrypto
@BigBlackCrypto 2 жыл бұрын
Yupp, in canada 🇨🇦 there having a field day
@AlmightyGTR
@AlmightyGTR 2 жыл бұрын
IPS systems with Web application safeguard, if updated to latest signatures, should be able to detect and manage this vulnerability. Ofcourse this is not a remediation, only an additional level of defence till we, as you pointed out, patch all the vulnerable applications. So this should buy us time till we patch all apps.
@ifur
@ifur 2 жыл бұрын
This is your reminder to backup offline, away from any kind of network and electricity.
@malwaretestingfan
@malwaretestingfan 2 жыл бұрын
Java is going the way of Flash at this point with all the exploits that run on it.
@robi8020
@robi8020 2 жыл бұрын
Integer is awesome! I’ve been amazed by their tech since I first ran across them at a small booth at RSA many years ago.
@angeloalonzo5500
@angeloalonzo5500 2 жыл бұрын
This makes me woried when I realized that this affects java and the school project we are creating is in... java 😱
@Hartono25277
@Hartono25277 2 жыл бұрын
Oh no, my college is also in Java!
@henrymach
@henrymach 2 жыл бұрын
Use Java, they say. It will be fun, they say...
@spookyrahhh
@spookyrahhh 2 жыл бұрын
I was waiting for this video since I heard about it!
@misterak4603
@misterak4603 2 жыл бұрын
Oh dang, doesn't this spread by compromising sites and replacing them with ransomware-infested programs?
@xasmaniusvolk8416
@xasmaniusvolk8416 2 жыл бұрын
0:40 playing Minecraft online may not be the best idea these times,same for being online with any Computer that has Java installed...
@jamesmcv
@jamesmcv 2 жыл бұрын
This was bad because it hit EVERYTHING. Not just servers, but firewalls and many network devices. From a corporate IT Security perspective, it was drop everything and spend the next couple weeks applying hotfix/patches. Also, it hit right before Christmas........
@zetectic7968
@zetectic7968 2 жыл бұрын
There is another channel on YT that keeps saying AVAM is not important just keep you browser updated and you are protected. I very much doubt that this will help defeat this threat.
@dilkir
@dilkir 2 жыл бұрын
Love your work ❤
@YTshashmeera
@YTshashmeera 2 жыл бұрын
I actually had a nightmare about log4j 3 days ago
@citizenkimi
@citizenkimi 2 жыл бұрын
Just don't panic, you are most likely subject to general updates just like me and any desktop user.
@hrsh042
@hrsh042 2 жыл бұрын
Pray.
@Hue_Sam
@Hue_Sam 2 жыл бұрын
Log4shell appears: Everyone: We’re Screwed
@hansfox
@hansfox 2 жыл бұрын
Pc security and family 😍, a Merry Christmas and a Happy New Year 💻💾🔬And Greetings from Hans of the Dutch Lowlands NL 😷 🖖
@faded_ink3545
@faded_ink3545 2 жыл бұрын
It’s been a busy few days in CTI…
@teddym2808
@teddym2808 2 жыл бұрын
Just so I understand, will a good AV like Kaspersky protect against this exploit or does it have to be done at an OS level?
@ashinylilligant9723
@ashinylilligant9723 2 жыл бұрын
It's a vulnerability with the log4j library of logging features. Unfortunately it's not really something that can be covered via antivirus as far as I'm aware, the remote execution of ransomware or malware COULD be prevented with an AV however the actual exploit isn't something that can be blocked by it, just due to the way it works. Any unpatched java application that is running logging via the log4j family and is unpatched to disable RCE is vulnerable.
@teddym2808
@teddym2808 2 жыл бұрын
@@ashinylilligant9723 thank you
@hrsh042
@hrsh042 2 жыл бұрын
@@ashinylilligant9723 damn.
@jgsource552
@jgsource552 2 жыл бұрын
@@ashinylilligant9723 how do you protect a linux system then?? I dont really hear of people using antiviruses in that system so what do you do in that case?
@iTakeCash
@iTakeCash 2 жыл бұрын
So do I have to download something, click on a link or visit a link to be targeted? Or is it just random?
@vram1974
@vram1974 2 жыл бұрын
This entire industry needs to go into maintenance mode and concentrate on auditing/fixing things instead of "agile" and the need to push new and shiny. Either a useless update just moves things around or a new product is released that solves absolutely Jack S.
@EvilTim1911
@EvilTim1911 2 жыл бұрын
Yup, I hate this "release now, fix later" bullshit
@SecurityTalent
@SecurityTalent 2 жыл бұрын
Thanks
@pcsecuritychannel
@pcsecuritychannel 2 жыл бұрын
Open source scanner for usage of Log4J on Linux: github.com/intezer/log4jscan You can use this to scan your servers and systems for this zero-day.
@Hilol-nx3wf
@Hilol-nx3wf 2 жыл бұрын
@🌟:awesome: Run Linux in a VM
@ExtrymGamingLTU
@ExtrymGamingLTU 2 жыл бұрын
Thank you so much for explaining what this malware exploits and where it can be found
@citizenkimi
@citizenkimi 2 жыл бұрын
4:49 Devs that use the library and programs that factually deploy and/or employ them are the main bubble to my sense.
@atol71
@atol71 2 жыл бұрын
I just wonder if the log4j library has been used by Oracle (sic) developers in java JVM(JDK) development and has the whole Java ecosystem been compromised? Maybe? Eh? Could it?
@randyjohnson3654
@randyjohnson3654 2 жыл бұрын
Log4j has already stated the vulnerable versions and are actively working to resolve it. Most developers, professional at least, should have at least mitigated the issues.
@AnthonyJames7
@AnthonyJames7 2 жыл бұрын
Log4j is destroying network administrators holiday all over the world :) RIP
@spryzenshu989
@spryzenshu989 2 жыл бұрын
Your awesome friend keep going
@NickPatron
@NickPatron 2 жыл бұрын
Why wont my vulnerbility scanner find this?
@DavidG2P
@DavidG2P 2 жыл бұрын
I had about 34 copies of it on my desktop PC
@Tomd4850
@Tomd4850 2 жыл бұрын
So wait, it's executing code through Java programs and apps. Can't I just uninstall Java/JRE on my personal systems and be fine? (assuming desktops only, not mobile devices) I'm aware that applications can run their own runtime of Java that is independent of what would be installed and could still be capable of getting infected/exploited. However, to be protected from infected web sites, would removing the local Java runtime protect me from that kind of scenario?
@hackersland8972
@hackersland8972 2 жыл бұрын
Two iranian kid hacked that and usa put reward of $10M for catching them. This happened by 2022
@JMA5566
@JMA5566 2 жыл бұрын
the consequences of this bug are extremely exaggerated and it is very difficult to exploit.
@johnny5805
@johnny5805 2 жыл бұрын
Does this affect any GAMES too ? Or will the main vector for infection be by visiting a website that has been compromised ?
@Xenephos
@Xenephos 2 жыл бұрын
It for sure can affect Minecraft. Being on multiplayer servers is pretty dangerous right now if they aren’t properly patched, though it may be fixed now. I haven’t followed up on it lately
@richardh9071
@richardh9071 2 жыл бұрын
The vulnerability only affects devices running the Java log4j library, which are usually servers. If you are a home user visiting a website compromised by the log4j vulnerability it’s unlikely you will be targeted by it. There is of course a risk of threat actors using drive-by downloads on servers they compromised to deliver malware to your home device, or installing magecart or other card scrapers to steal your banking/credit card details should you input them on a compromised site.
@spookyrahhh
@spookyrahhh 2 жыл бұрын
Steam was also affected
@voidwalker7507
@voidwalker7507 2 жыл бұрын
Nice job, Leo. I'm still watching, and I hope you have been well; as Sun Tzu once said "He who knows his enemy and knows himself fears not the result of one thousand battles." 😜🖤
@aMulliganStew
@aMulliganStew 2 жыл бұрын
"Ha, ha, ha. I run diskless." ? My main fear is that attackers would find some way to infiltrate the bios/UEFI. So long as they stay outta there, I feel pretty safe. Thoughts, comments, suggestions please?
@alepa2357
@alepa2357 2 жыл бұрын
Uefi is not safe, like 100%. There are rootkits that embed to it. Take moonbounce for one.
@MrTimoosh
@MrTimoosh 2 жыл бұрын
This is not a zero day as the title suggests, this is a known exploit presented by two security professionals at BlackHat over 5 years ago, there is a video on this presentation on youtube as well.
@julkiewicz
@julkiewicz 2 жыл бұрын
Wasn't that just about Java's JNDI and its unchecked class loading under certain conditions in general? This is JNDI + Log4j and as far as Log4j is concerned, this is a zero day.
@sudiptochoudhury990
@sudiptochoudhury990 2 жыл бұрын
this is not good seems like every application from now on needs to be run under a sandbox
@murkyemu5256
@murkyemu5256 2 жыл бұрын
Can you review scanguard?
@ifur
@ifur 2 жыл бұрын
I was wondering can online banking be affected by this? I’m kinda worried about the big reset and money sitting at my bank account.
@jmdefault
@jmdefault 2 жыл бұрын
It allows attackers to run any kind of code they please. So yes. Deploying a keylogger to record the passwords you type in the banking website wouldn't be difficult. I can only give you the same advice you've probably heard a million times: Make sure you have 2-factor-authentication enabled. Every bank should support it by now and it is designed to prevent exactly this kind of attack.
@AlyxSharkBite-2000
@AlyxSharkBite-2000 2 жыл бұрын
I'm glad I don't use that logger in my code.
@olivert.7192
@olivert.7192 2 жыл бұрын
is it really possible to run ransomeware? Because the Log4J shouldn't be running at root privileges - right? So I guess, when someone gets RCE, they will just get the permissions that log4j is running at. So ransomware would then be on the user files, or would it be possible to ransomware the entire system?
@qsxmirage7274
@qsxmirage7274 2 жыл бұрын
Windows doesnt really work like that its fundamentally broken (: on linux servers yes this will sorta sandbox it to user privs
@BTrain-is8ch
@BTrain-is8ch 2 жыл бұрын
I think talk about the vulnerability has engaged in a bit of sensationalism. For sure, technical organizations that have done essentially everything wrong are going to have a bad time. For orgs that operate with sane security practices (e.g. principles of least privilege and defense in depth) this is inconvenient and is going to cause your cyber security team to lose sleep monitoring for a while but the world isn't ending. The exploit depends on a bit of a chain of many people getting things very wrong culminating in app servers having unrestricted access to the internet for no reason.
@malwaretestingfan
@malwaretestingfan 2 жыл бұрын
Well, at least on Windows, there are plenty of UAC bypass methods.
@carnivorebear6582
@carnivorebear6582 Жыл бұрын
Most of the valuable files attacked by ransomware (documents, photos, etc.) are generally writable with standard user privileges. There is bigger scope for attack with higher privileges (other user accounts, etc.) but it can still be extremely damaging regardless.
@xasmaniusvolk8416
@xasmaniusvolk8416 2 жыл бұрын
5:50 the programs I made don't log anything but only bc I only make dead simple applications (not everything is simple tho - I don't blame anyone for using it)
@13thravenpurple94
@13thravenpurple94 2 жыл бұрын
If i may ask, is this zero day vulnerability does affect android users? Thank you
@the-Gammaron
@the-Gammaron 2 жыл бұрын
Yep, even "unhackable" linux and mac os, Minecraft Java Edition and even android...
@citizenkimi
@citizenkimi 2 жыл бұрын
It may affect with no doubt, but I guess I haven't seen any mobile company claiming to be a huge target or menace around. So, make sure you always are in a patched device, that's and will probably always be the best and shortest protection.
@hrsh042
@hrsh042 2 жыл бұрын
@@citizenkimi we're fuked
@jackmio
@jackmio 2 жыл бұрын
User: Who does this aff- *YES*
@casewhite5048
@casewhite5048 2 жыл бұрын
wondering if more advanced AI would ever be able to crack these within a reasonable amount of time
@anwarulbashirshuaib5673
@anwarulbashirshuaib5673 2 жыл бұрын
no, aes256 is rock solid encryption, and considered quantum safe. No matter how sophisticated AI gets it will never, never be able to break aes256
@wrockd
@wrockd 2 жыл бұрын
AIs can't crack a encryption algorithm no matter how advance they get, primary goal of AIs is Data processing and correlation. For the most part it's trying to achieve something near human intelligence/awareness. Cracking an Encryption algorithm requires wither exponential processing power or an another algorithm that reduces the time or data complexity of the said algorithm. AES-256 is considered pretty secure as even the best attacks against it(if you don't include attacks against bad implementations) only reduce its complexity by very small values.
@ltxr9973
@ltxr9973 2 жыл бұрын
The worst? Surely not. But I would agree that it's the dumbest zero day ever considering that it's literally not a bug but a feature in the wrong place. The Java community needs to stop bloating everything to death.
@orbitalonyx
@orbitalonyx 2 жыл бұрын
Ok well I have anxiety, can you tell me if I’m okay, I did some school work today on a website, it’s the website that we did for school nothing else and I had discord open all day idk am I safe I’m pretty scared right now, like I just wanna know if I’m safe I have a pretty bad anxiety for this and stuff I don’t want anything bad on my pc
@monkey6226
@monkey6226 2 жыл бұрын
The dark days
@sherlockstech
@sherlockstech 2 жыл бұрын
I wonder why Leo likes Shakespere so much...
@railfanningstuff8333
@railfanningstuff8333 2 жыл бұрын
It sound's like Oracle USA is going to have a big Lawsuit on its hands
@DaniilStanisevschi
@DaniilStanisevschi 2 жыл бұрын
Log4j is not maintained by Oracle, it's a 3rd party repo. No liability to vendor.
@souchikjoardar201
@souchikjoardar201 2 жыл бұрын
Bro why don't you test Quick heal it can be a better competitor to Kaspersky please brother kindly make a video on this is very interesting topic
@darshpatel5035
@darshpatel5035 2 жыл бұрын
Log4shell and Log4j
@108kitsune
@108kitsune 2 жыл бұрын
Hahaha I run window 98!
@echidubemfm1524
@echidubemfm1524 2 жыл бұрын
can you do f secure online virus scanner, please
@mc_mzcgt
@mc_mzcgt 2 жыл бұрын
My friend got khonsari ransomware lol
@StephSancia
@StephSancia 2 жыл бұрын
"HaHaHa I'm on LINUX" 🔥 just testing 🙃 nope, windows 11 here BUT my entire data backed up on a 2TB HDD that is disconnected from life itself 🙏 Happy Christmas
@StephSancia
@StephSancia 2 жыл бұрын
@user i do. 1x 2TB plus 2 x 1TB SEAGATE. Anything else ?
@StephSancia
@StephSancia 2 жыл бұрын
@user and I have 4 laptops with the same data on each. Each with 1TB HDD from PB Tech in Auckland
@dend1
@dend1 2 жыл бұрын
Does it affect andriod?
@PaperBagMan884
@PaperBagMan884 2 жыл бұрын
It's a vulnerability in a Java library, it affects every platform with Java and a JVM running on it, which is basically every platform in existence.
@hrsh042
@hrsh042 2 жыл бұрын
@@PaperBagMan884 sad. We need an alternative to java
@funwithalbi2425
@funwithalbi2425 2 жыл бұрын
Why is log4j everywhere it only logs
@tommybronze3451
@tommybronze3451 2 жыл бұрын
java not being secure ? who would've known ...
@wiekiatong4018
@wiekiatong4018 2 жыл бұрын
Can i have this sample?
@-GameHacKeR-
@-GameHacKeR- 2 жыл бұрын
youtube removed my like on this video, I added it back again.
@tvmichaelt9885
@tvmichaelt9885 2 жыл бұрын
Is it going to hit Minecraft Java?
@kingdragonheart222
@kingdragonheart222 2 жыл бұрын
It already did.
@skia5635
@skia5635 2 жыл бұрын
> oPeN soURCe is MoRE seCUrE > log4j is open source
@kemiyt1811
@kemiyt1811 2 жыл бұрын
Pro tip - Unplug your internet connection 🤣😎😎
@R.K_Chalkboard
@R.K_Chalkboard 2 жыл бұрын
I wonder if it works on MacOS. Probably tbh.
@AviatingRandom
@AviatingRandom 2 жыл бұрын
well macos is linux
@bestGaming132
@bestGaming132 2 жыл бұрын
Android is based on Linux too
@AviatingRandom
@AviatingRandom 2 жыл бұрын
@@bestGaming132 chrome os too
@ProTechShow
@ProTechShow 2 жыл бұрын
Java is cross-platform and runs on pretty much everything, so if a Java application that uses the vulnerable library is deployed on a Mac I see no reason it would be any safer. Their old slogan "Write once, run anywhere" applies to this exploit as well, unfortunately!
@senge1337
@senge1337 2 жыл бұрын
@@AviatingRandom No. MacOS is Unix
@meowskull
@meowskull 2 жыл бұрын
Android and Mac is safe tho... Right?
@amogustroll69
@amogustroll69 2 жыл бұрын
nope since they both use java and log4shell is a java library
@arturm4558
@arturm4558 2 жыл бұрын
Ha ha ha, I actively avoid Java apps. (you asked for this...) ;)
@sh_gosha6867
@sh_gosha6867 2 жыл бұрын
Nice
@Sciophobia.
@Sciophobia. 2 жыл бұрын
Common sense and Windows Defender are enough 🤣 /s
@tomasofficial.
@tomasofficial. 2 жыл бұрын
but im on Chrome OS!
@amogustroll69
@amogustroll69 2 жыл бұрын
still affects you cuz log4shell is a java library and chromeos uses java
@JustaRegularGuy0
@JustaRegularGuy0 2 жыл бұрын
I like peanut butter
@GoodGooseThingit
@GoodGooseThingit 2 жыл бұрын
I like jelly
@asafberger4108
@asafberger4108 2 жыл бұрын
I like cheese
@wzard3156
@wzard3156 2 жыл бұрын
i like pudding
@Jet_Ink
@Jet_Ink 2 жыл бұрын
I like
@cerinthe802
@cerinthe802 2 жыл бұрын
Creamy or crunchy
@ciepla_woda
@ciepla_woda 2 жыл бұрын
EternalBlue2.0??
@amogustroll69
@amogustroll69 2 жыл бұрын
probably?
@malwaretestingfan
@malwaretestingfan 2 жыл бұрын
No, but it risks being as harmful.
@amogustroll69
@amogustroll69 2 жыл бұрын
@@malwaretestingfan yep
@minepolz320
@minepolz320 2 жыл бұрын
apperenly no Minecraft anymore
@kamertonaudiophileplayer847
@kamertonaudiophileplayer847 2 жыл бұрын
Such videos make me laugh, I've never used Log4j and actively resisted to it, now folks understand why. Do not tell me about Tomcat, it isn't my tool, especially when back to 2000 I had a fight with its creator.
@grizius4123
@grizius4123 2 жыл бұрын
Cool
@hrsh042
@hrsh042 2 жыл бұрын
Ok
@CoryResilient
@CoryResilient 2 жыл бұрын
Snitches
@Turann99
@Turann99 2 жыл бұрын
Lol i using macOS
@hrsh042
@hrsh042 2 жыл бұрын
Affected
@amogustroll69
@amogustroll69 2 жыл бұрын
affected cuz mac uses java and log4shell is a java library
@Turann99
@Turann99 2 жыл бұрын
@@amogustroll69 I don’t have java based software :)
@amogustroll69
@amogustroll69 2 жыл бұрын
@@Turann99 even if you dont have java software, macOS does use java for some of its core components under-the-hood
@thevault1575
@thevault1575 2 жыл бұрын
hahaha i run linux
@bernardohchongching224
@bernardohchongching224 2 жыл бұрын
God damn it 2021, this does not look good for 2022
@NorthernS0utherer
@NorthernS0utherer 2 жыл бұрын
Gg
@keypc675
@keypc675 2 жыл бұрын
Grisoft Malware Hunter Crack is a winning software that provides complete protection from all kinds of threats, protects your data, protects your privacy, and keeps you up to date with viruses on your Windows computer.
@harshalibirajdar8536
@harshalibirajdar8536 Жыл бұрын
hahaha i run Android
@Handlebrake2
@Handlebrake2 2 жыл бұрын
Not when you don't use Java 🙈
@dfgdfhfgjghjdtyu
@dfgdfhfgjghjdtyu 2 жыл бұрын
hahaahaha i use linux
@MrRetroDev
@MrRetroDev 2 жыл бұрын
I hate it when someone says Linux systems can't get viruses, because they can, easily. It's a lot easier to build a virus for Linux than Windows since, once the file is run with _sudo_ , it can do anything it wants to the system. At least Windows checks what's running, and tries to protect core files, even if it has escalated permissions. People don't build as many viruses for Linux as it's not as widely used as Windows, simple as that.
@malwaretestingfan
@malwaretestingfan 2 жыл бұрын
Depends more on the device than on the OS. Linux is actually very secure, but since IoT devices are rarely updated and Android relies (or better, used to) rely more on the user security-wise (and not counting the cases where malware is shipped together with the firmware, see Triada), Linux may be easily attacked.
@Sumire973
@Sumire973 2 жыл бұрын
Default user account in Windows is admin, which means that by default malware developers shouldn't bother with privilege escalation since as soon as they enter the device they will already have admin rights anyway. Not all Linux distros has the same security settings/levels, some has kernel modules that are responsible for protecting the OS. others like Fedora Silverblue and Endless OS are immutable and are based on OSTree technology, core files are protected with read-only images and the root filesystem is also immutable. Windows doesn't have that, and it's easy for things like StarForce's DRM to break your OS by being able to manipulate system files, mainly because you has to give admin rights to anything you install.
@malwaretestingfan
@malwaretestingfan 2 жыл бұрын
@@Sumire973 The default user account in Windows is not the Administrator, but the UAC that Windows provides is extremely weak.
@wrockd
@wrockd 2 жыл бұрын
@@Sumire973 A few things wrong with this, while you're true that the default account is Admin in windows(and while any sane person uses a separate user account), but that doesn't allow for automated admin rights. The UAC is well implemented and uses Winlogon Desktop which is a SYSTEM Privileged account for the UAC Prompts. And yea, certain Linux distros provide immutable fs but let's not forget that it's not the standard/de-facto practice even in Linux. Also, most of the core windows system files are read-only aswell, even with Admin privileges you need to take ownership in order to modify those. Also, the problem with games and other software requiring Admin privileges is purely for a different reason. It has nothing to do with the security of UAC implementation in Windows. And FOSS alternatives exist in windows too. Moreover, most of the Privilege Escalation exploiting in Windows are done by either exploiting a UAF(Use After Free) vulnerability, Memory injection in unprotected escalated processes, or simple DLL Hijacking. The thing is that your statement would've been true like 3-4 years ago, given that windows itself had a plethora of exploitable system processes, but most of them(if not all) have been fixed, so now in order to pull off a guaranteed Privilege Escalation you need to either somehow trick the user into thinking that they're Escalating a trustworthy process(for example some malwares use the good old notepad.exe for the UAC bypass) or exploit some other third party escalated process.
@wrockd
@wrockd 2 жыл бұрын
@@malwaretestingfanWrong, UAC is not weak, in fact its pretty much one of the best security implementations in Windows. It uses Winlogon Desktop to display a sandboxed prompt and there exists no direct bypass or vulnerability in the implementation itself. The problem is other processes/programs which run with Admin Privileges and are vulnerable to UAF, Memory injection or DLL injection.
@rb6725
@rb6725 2 жыл бұрын
I wouldn’t put much faith in the accuracy of this channel viewers. Your antivirus test in December 2021 showed your results but you have not tested those antivirus programs individually for months or over a year. I went back over a year on your channel and could not find a McAfee review either. Professional antivirus testing websites, AV Test and AV Comparatives, do much thorough reviews and their results are different to yours, to say the least.
@retrocu
@retrocu 2 жыл бұрын
i can remove all log4j programs in a linux system because i can see the source code. i can remove every trace of java and jvm. i have all the control if im using a libre kernel linux. if we compare your system with an open source system you have no control over your system. so who is affected more?
@DevenAbhyankar
@DevenAbhyankar 2 жыл бұрын
Thanks
@keypc675
@keypc675 2 жыл бұрын
Grisoft Malware Hunter Crack is a winning software that provides complete protection from all kinds of threats, protects your data, protects your privacy, and keeps you up to date with viruses on your Windows computer.
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 925 М.
3CX: How this malware almost hacked every business
10:39
The PC Security Channel
Рет қаралды 159 М.
Did you find it?! 🤔✨✍️ #funnyart
00:11
Artistomg
Рет қаралды 124 МЛН
Cat story: from hate to love! 😻 #cat #cute #kitten
00:40
Stocat
Рет қаралды 15 МЛН
The Scariest Week in Minecraft History
9:48
FitMC
Рет қаралды 2,1 МЛН
Top 5 Most Dangerous Ransomware
13:12
The PC Security Channel
Рет қаралды 206 М.
The Malware that hacked Linus Tech Tips
10:13
The PC Security Channel
Рет қаралды 1,5 МЛН
Hackers Abuse Zero-Day Exploit for CrushFTP
31:49
John Hammond
Рет қаралды 67 М.
why are more people not talking about this?
5:24
Low Level Learning
Рет қаралды 114 М.
AMD is About to CRUSH Intel… Just Like I Predicted
9:34
Linus Tech Tips
Рет қаралды 437 М.
Malwarebytes vs 2000 Malware
11:12
The PC Security Channel
Рет қаралды 154 М.
Log4J & JNDI Exploit: Why So Bad? - Computerphile
26:31
Computerphile
Рет қаралды 496 М.
Is Kaspersky safe to use?
7:21
The PC Security Channel
Рет қаралды 276 М.
Ransomware vs UAC
11:14
The PC Security Channel
Рет қаралды 50 М.
Обзор игрового компьютера Макса 2в1
23:34
Samsung or iPhone
0:19
rishton vines😇
Рет қаралды 9 МЛН
Apple Pencil Nasıl Yapılır?🤯
0:13
Safak Novruz
Рет қаралды 1,4 МЛН
ПК с Авито за 3000р
0:58
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 1,6 МЛН