Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


roobarb

646 posts

Ultimate Geek

Trusted

#312593 30-Apr-2024 05:49
Send private message

Hi,

 

Does anyone who has a background in security research (ideally on Windows) and/or PCI-DSS compliance want to have a quick look at something?

 

I would like a second opinion on a PowerShell matter.

 

Background, AMSI allows applications to hook into Antivirus Scanning.

 

https://learn.microsoft.com/en-us/windows/win32/amsi/how-amsi-helps

 

https://learn.microsoft.com/en-us/windows/win32/amsi/how-amsi-helps#more-background-info-about-fileless-threats

 

PowerShell has implemented ... something ...

 

https://learn.microsoft.com/en-us/powershell/scripting/whats-new/what-s-new-in-powershell-73?view=powershell-7.3

 

PSAMSIMethodInvocationLogging - Extends the data sent to AMSI for inspection to include all invocations of .NET method members.

 

Now the problem is not the script scanning, the problem is it expands every string variable sent to .NET method invocations to the AV.

 

This is with no concept of privacy, restriction or sensitivity of the data. Everything that is a string goes to AV.

 

So if you implemented any code calling .NET methods, your arguments values are going to AV.

 

But not only that, if you call anybody elses code that calls .NET methods, even in a PowerShell module, that still gets sent to AV.

 

From what I have seen, stuff sent to AV finds it's way into the EventViewer, if it can get into the EventViewer it can end up anywhere.

 

So with no optout or discretion, all data values sent to .NET methods go to AV.

 

This is an attempt to outline the problem, but it is considered working as designed.

 

https://github.com/PowerShell/PowerShell/issues/21491

 

This includes attempts at mediation, and a proof of concept with an existing popular Luhn algorithm checker that leaks credit card numbers to AV.

 

https://github.com/PowerShell/PowerShell/issues/21536

 

Am I making a mountain out of a molehill or is there a real security risk here?

 

Thanks,

 

roobarb


Create new topic
roobarb

646 posts

Ultimate Geek

Trusted

  #3225639 2-May-2024 18:55
Send private message

Nobody curious enough? No one, say, from Lateral Security with a bit of time on their hands?


Create new topic





News and reviews »

Synology DS925+ Review
Posted 23-Apr-2025 15:00


Synology Announces DiskStation DS925+ and DX525 Expansion Unit
Posted 23-Apr-2025 10:34


JBL Tour Pro 3 Review
Posted 22-Apr-2025 16:56


Samsung 9100 Pro NVMe SSD Review
Posted 11-Apr-2025 13:11


Motorola Announces New Mid-tier Phones moto g05 and g15
Posted 4-Apr-2025 00:00


SoftMaker Releases Free PDF editor FreePDF 2025
Posted 3-Apr-2025 15:26


Moto G85 5G Review
Posted 30-Mar-2025 11:53


Ring Launches New AI-Powered Smart Video Search
Posted 27-Mar-2025 16:30


OPPO RENO13 Series Launches in New Zealand
Posted 27-Mar-2025 05:00


Sony Electronics Announces the WF-C710N Truly Wireless Noise Cancelling Earbuds
Posted 26-Mar-2025 20:37


New Harman Kardon Portable Home Speakers Bring Performance and Looks Together
Posted 26-Mar-2025 20:30


Data Insight Launches The Data Academy
Posted 26-Mar-2025 20:21


Oclean AirPump A10 Portable Water Flosser Wins iF Design Award 2025
Posted 20-Mar-2025 12:05


OPPO Find X8 Pro Review
Posted 14-Mar-2025 14:59


Samsung Galaxy Ring Now Available in New Zealand
Posted 14-Mar-2025 13:52



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.