Hacking Software Updates With Evilgrade

Posted By: SecurityTube_Bot
Posted On: Mon 21 Feb 2011
Views: 5261
Share this video:
Share it on Facebook Share it on Twitter Share it on Reddit Share it on Digg Share it on Stumbleupon
Support SecurityTube:


Description:

We had covered EvilGrade a while back. In this demo, g0tmi1k shows us a demo of EvilGrade using Notepad Plus. The underlying hack uses an ARP MITM and DNS Poisoning to redirect all software upgrade request checks to the attacker's server. This server serves a metasploit payload to Notepad Plus instead of the actual payload. Once the update gets exectuted a reverse connect shell provides full access to the victim's computer.

For full details on the script used and other information please visit g0tmi1k's blog post. Thanks go out to g0tmi1k for referring this video to us.

Tags: fun ,


Comments (None)

Login to post a comment