The Tech Behind Dropbox’s New User Experience on Mobile, Part 2
tech.dropbox.com
tech.dropbox.com
So they sign 90% of the executable, but 10% of it is unsigned.
Only a fool would, after their actions of the past year, still believe this company has good intentions or that their payload system hasn't already been totally compromised (with their cooperation, no less).
Signing is mostly useful to help reduce anti-virus false positives. AV systems learn binary reputations just like spam filters do. It doesn't matter if the app goes off and downloads another program for this purpose - that's an implementation detail that doesn't impact whether the app is malicious or not.
These attributes are not part of the signedAttributes which is used to actually authenticate the signature. A quick dump of the asn.1 structure of the authenticode signature block from my installer shows that right after the timestamp extension is a new object with a private OID (presumably assigned to dropbox for this purpose) that includes a unique string.
6519 11: OBJECT IDENTIFIER '1 3 6 1 4 1 42921 1 2 1' 6532 1049: SET { 6536 1045: UTF8String : 'Dropbox-Installer-Id:DBPREAUTH::msie::xxxx..........................................'
Interesting hack, kudos!
Can you offer some more info on this topic in a follow-up post?
In order to inject an unauthenticated attribute to the signature, you may want to use osslsigncode for signing (instead of MS signtool).
In this case, the install succeeds and only auto sign-in fails.
sounds like Condi didn't need much time for Dropbox to build a nice new home for NSA implants.
quite an intriguing attack surface for mobile malware...arbitrary code of Dropbox's choosing when combined with another 0day or two? no thanks.
this makes me glad i dropped dropbox like a bad habit.