Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


freitasm

BDFL - Memuneh
79306 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#280869 16-Jan-2021 15:48
Send private message

Right now there's a Windows 10 vulnerability that can corrupt NTFS-based drives on Windows systems. Microsoft is working to create a patch.

 

Until Windows machines are completely patched, it is recommended not to open links without checking domain target. 

 

The vulnerability can be invoked through command line, through a link to an invalid URL or even by inserting a broken image in a webpage. By the time the browser tries to render the image/link the filesystem is already compromised.

 

The only SAFE WAY to browse is to either use Windows Sandbox or a virtual machine (with a checkpoint you can go back to if needed). Any link or image could potentially be harmful. 

 

More information here. If you see something like below then it's too late:

 

 





Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


Filter this topic showing only the reply marked as answer Create new topic

gzt

gzt
17157 posts

Uber Geek

Lifetime subscriber

  #2636553 16-Jan-2021 16:23
Send private message

Linked article refers to a .url local file and other local methods. Microsoft are advising this requires social engineering to execute. Ie; file download or command run locally. I just read an article with a claim this can work with only a url in the browser address bar. No idea if that's true at this time.



freitasm

BDFL - Memuneh
79306 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2636554 16-Jan-2021 16:31
Send private message

It doesn't need to be local. Remote will work.





Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


freitasm

BDFL - Memuneh
79306 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2636564 16-Jan-2021 16:57
Send private message

Whoever says this can not be activated remotely, is underestimating the flaw.

 

Update: It seems it can only be remotely activated with Microsoft Edge non-Chromium.

 

Workaround: do not use Microsoft Edge (non-Chromium) or Internet Explorer. Do not open downloaded file from unknown/untrusted source (any browser).





Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 




waikariboy
902 posts

Ultimate Geek

ID Verified
Trusted

  #2636596 16-Jan-2021 19:48
Send private message

freitasm:

 

Whoever says this can not be activated remotely, is underestimating the flaw.

 

Update: It seems it can only be remotely activated with Microsoft Edge non-Chromium.

 

Workaround: do not use Microsoft Edge (non-Chromium) or Internet Explorer. Do not open downloaded file from unknown/untrusted source (any browser).

 

 

 

 

This video show Edge Chromium and it working

 

 

 

https://www.youtube.com/watch?v=8tyqVus-QdA





Balm its gone!


freitasm

BDFL - Memuneh
79306 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2636599 16-Jan-2021 19:57
Send private message

That is a local file, not a hosted file.

When opening a local file browsers can access the file system. When opening a remote file that access is blocked.

The exception to this rule are Microsoft Edge (non-Chromium) and Internet Explorer.




Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


gehenna
8518 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  #2636611 16-Jan-2021 20:52
Send private message

Thanks for sharing this. Far out, the year in infosec has started strong!

gzt

gzt
17157 posts

Uber Geek

Lifetime subscriber

  #2636725 16-Jan-2021 23:36
Send private message

Edge is automatically disabled if Edge Chromium is installed. Edge is not included in fresh installs of 20H2.

Internet Explorer don't know.

 
 
 

Trade NZ and US shares and funds with Sharesies (affiliate link).
freitasm

BDFL - Memuneh
79306 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2636726 17-Jan-2021 00:05
Send private message

Still, there is quite a lot of people using old Edge (IE volume is not representative these days).




Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


ech3lon
369 posts

Ultimate Geek

Subscriber

  #2636995 17-Jan-2021 19:10
Send private message

Since no one has posted, the whole thing is a whole lot of nothing.

 

It's essentially an NTFS bug that trigger/set hard-drive "dirty" flag, which usually means Windows will schedule chkdsk on next start up.
It is a bug, as explained here (https://www.youtube.com/watch?v=PtHTqmp-Jt8), as marking a disk as "dirty" normally requires elevated priviledges/admin.

 

I'd suppose it would be an addition to the collection of "tools" those phone/website scammers could use that make it looks impressively legitimate.


  #2637004 17-Jan-2021 19:23
Send private message

Would using exFAT instead of NTFS get around the issue?
Does exFAT have any other advantages?




Gordy

 

My first ever AM radio network connection was with a 1MHz AM crystal(OA91) radio receiver.


SirHumphreyAppleby
2849 posts

Uber Geek


  #2637007 17-Jan-2021 19:32
Send private message

Gordy7: Would using exFAT instead of NTFS get around the issue?
Does exFAT have any other advantages?

 

Yes.

 

Does exFAT have any advantages? I'd say not. For internal file systems, NTFS is still your best option.


timmmay
20589 posts

Uber Geek

Trusted
Lifetime subscriber

  #2637011 17-Jan-2021 19:57
Send private message

Everyone here, and hopefully all our families, should have sufficient backups that losing your entire hard drive is an inconvenience. Have you done a restore lately? I schedule restore tests of my home machine backups for twice a year, and so far, so good.


Hammerer
2476 posts

Uber Geek

Lifetime subscriber

  #2637332 18-Jan-2021 12:54
Send private message

Clearing the NTFS dirty bit, if that is the only problem, isn't too hard.

 

https://www.raymond.cc/blog/manually-reset-or-clear-dirty-bit-in-windows-without-chkdsk/2/


Varkk
643 posts

Ultimate Geek


  #2637351 18-Jan-2021 13:21
Send private message

I have heard of some drives not being bootable after being hit with this and rebooting. After a scan it then reboots and gives a 0x0000007B BSOD.


Hammerer
2476 posts

Uber Geek

Lifetime subscriber

  #2637362 18-Jan-2021 13:48
Send private message

Varkk:

 

I have heard of some drives not being bootable after being hit with this and rebooting. After a scan it then reboots and gives a 0x0000007B BSOD.

 

 

Yes, having the Windows system disk affected will be a bigger job.

 

Booting from a USB drive/recovery disk and running the fix might also require changing BIOS/UEFI options.


Filter this topic showing only the reply marked as answer Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.