The guy even has his full name and contact info in there.
This is harmless.
If you don't trust me you could upload to an online malware multiscanner (which tends to invite false positives, but better than nothing).
The guy even has his full name and contact info in there.
This is harmless.
If you don't trust me you could upload to an online malware multiscanner (which tends to invite false positives, but better than nothing).
It's about the whole process of regularly downloading and running executables uploaded by individuals to a BBS-type forum being unimaginable in most other parts of the software world, and violating every security "best practice" written about in the past 30 years.
I know that this is how things were once done everywhere. But that was a long time ago.
The vast majority of the world still downloads and runs executables uploaded by individuals, albeit perhaps not on a bulletin board or forum (most of those have been killed and replaced by social media).
No, the majority of the world does not download and run binaries from non-reputable sources.
The distinction between reputable and non-reputable varies, but broadly easily spoofable user uploaded content falls into the non-reputable.
Most people download software from trust worthy websites like the official chrome website.
Indeed, the fact that people are continually scammed by this sort of attack is why Apple now refuses to run unsigned binaries by default.
To pretend nothing is wrong here is like pretending JavaScript supply chain attacks don’t exist because you don’t want them to exist.
…and yet. They do exist; wanting it not to be true does not make it so.
Likewise, downloading and running arbitrary binaries from a forum is naive.
You simply want nothing bad to happen.
That does not mean nothing bad will actually happen.
Even if you trust the authors of the posts, how reputable is the forum itself? Are the binary hashes posted? (No, they aren’t).
> I'm new in this forum
^ does not inspire confidence.
This year, "3rd Global Data Compression(gdcc.tech)" organized by Huawei and Barcelona Autonoma University was held. In this competition, I have the world 3rd place in the "Professional Task 6 - Ultra Fast" category(JABBAR). And I spent only 2 weeks of the 5-month competition process for this degree.
We can only share and test such a specific work in specific environments.
That is what is leading us to dystopia.
We are not "pretending", we are simply stating that the magnitude of risk is absolutely tiny.
Insecurity is freedom. Don't let them take away the latter in the name of security.
"There is nothing to fear but fear itself."
I don't run any binaries if i can help it
A) the risk exists.
B) you’ve taken no steps to verify that it’s tiny
C) you’re trusting new users just as much as well established users
D) your community is not as obscure and tiny as you imagine when it floats to the top of HN.
It’s not corporate dictatorship to say “there are bad actors out there looking to take advantage of naive users”; it’s reality.
You can refuse to acknowledge that reality, that’s your choice.
However, it’s probably irresponsible to encourage other people to do so.
I said there weren't any network APIs either (whose presence in an application like this would definitely be a red flag.)
If you say their presence can be obfuscated, then let it be known that obfuscation is also very obvious in a binary and another red flag.
But, from a technical perspective, I think it’s naive to assume that you can easily spot obfuscation that’s trying to stay hidden. If I understood your analysis model (open in a hex viewer and scroll around), then it is quite trivial to just add a few normal-looking functions that happen do things like manually load socket DLLs and make network requests without the API names being visible.
I could even, say, hide the code or data in a table of opaque filter constants or lookup tables, and it wouldn’t have to be much: you can implement a very dumb PE parser and function loader in a couple dozen lines of C, and an IP address target is just 4 bytes which can be smuggled into anything. Open up a socket, read everything from it into an RWX buffer, jump to it and voila, a programmable backdoor. Make the trigger something random so dynamic analysis doesn’t find it immediately.
The Underhanded C Code Contest demonstrates that even with source you can hide malicious behaviour; how are you going to detect malicious behaviour in a binary that’s trying to evade manual detection?