Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

6 May, 2024: The networking issue during the past two days has been identified and appears to be fixed. Will keep monitoring.


computers / alt.comp.os.windows-10 / SHARPEXT can access Gmail without compromising login credentials

SubjectAuthor
* SHARPEXT can access Gmail without compromising login credentialsNewsKrawler
`* SHARPEXT can access Gmail without compromising login credentialsJack Webb
 `* SHARPEXT can access Gmail without compromising login credentialsEdward Hernandez
  `* Re: SHARPEXT can access Gmail without compromising login credentialsNewsKrawler
   +- Re: SHARPEXT can access Gmail without compromising login credentialsNewsKrawler
   `* Re: SHARPEXT can access Gmail without compromising login credentialsOld Mother Hubbard
    `- Re: SHARPEXT can access Gmail without compromising login credentialsNewsKrawler

1
SHARPEXT can access Gmail without compromising login credentials

<tcfd0k$1719i$1@paganini.bofh.team>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=65012&group=alt.comp.os.windows-10#65012

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: newskr...@krawl.org (NewsKrawler)
Newsgroups: alt.comp.os.windows-10
Subject: SHARPEXT can access Gmail without compromising login credentials
Date: Thu, 4 Aug 2022 03:04:53 -0000 (UTC)
Organization: To protect and to server
Message-ID: <tcfd0k$1719i$1@paganini.bofh.team>
Injection-Date: Thu, 4 Aug 2022 03:04:53 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="1279282"; posting-host="Dj+cCDj8UalGBjrWyMkOzw.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team";
X-Notice: Filtered by postfilter v. 0.9.1
 by: NewsKrawler - Thu, 4 Aug 2022 03:04 UTC

https://www.forbes.com/sites/daveywinder/2022/08/02/gmail-warning-as-new-attack-bypasses-passwords--2fa-to-read-all-email/?sh=26b2da4288d92
SHARPEXT can access Gmail without compromising login credentials

SHARPEXT reads Gmail emails silently without triggering Google unusual
usage protections.

According to cyber security firm Volexity, the threat research team has
found the North Korean 'SharpTongue' group, which appears to be part of, or
related to, the Kimsuky advanced persistent threat group, deploying malware
called SHARPEXT that doesn't need your Gmail login credentials at all.

There is nothing to alert Google and the user that someone has logged into
Gmail from a different browser, machine, or location. Bypassing this
protection is crucial as it means the threat actors can remain truly
persistent, reading all the received and sent emails as if they were the
user themselves.

The good news is that your system needs to be compromised by some means
before this malicious extension can be deployed.

"Remarkably, the malware is delivered and installed by PowerShell,
something all too typical, and you would think that by now, the built-in
protections to the Microsoft Operating System, third-party extended
detection and response (XDR), and endpoint detection and response (EDR),
along with browser malware protection in the Windows version of Chrome," he
concludes, "would easily prevent these invoke PowerShell attacks.
Especially on workstations where you would think PowerShell activities
would be rare for most victim organization's users."

SHARPEXT can access Gmail without compromising login credentials

<UA_GK.1199364$cEE9.575037@usenetxs.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=65037&group=alt.comp.os.windows-10#65037

  copy link   Newsgroups: alt.comp.os.windows-10 free.spam
Followup: alt.test.group
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!news-out.netnews.com!news.alt.net!fdc2.netnews.com!peer03.ams1!peer.ams1.xlned.com!news.xlned.com!peer02.ams4!peer.am4.highwinds-media.com!news.highwinds-media.com!fx03.ams4.POSTED!not-for-mail
From: myopin...@least.com (Jack Webb)
Newsgroups: alt.comp.os.windows-10,free.spam
Subject: SHARPEXT can access Gmail without compromising login credentials
Followup-To: alt.test.group
References: <tcfd0k$1719i$1@paganini.bofh.team>
Injection-Date: Thu, 4 Aug 2022 21:43:15 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="aefae07b417003b570527823e77a9930";
logging-data="29200"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18QBXYPJWay5G0R7zD10mjY5gUD5xOvt6I="
User-Agent: Xnews/2006.08.05
Lines: 17
Message-ID: <UA_GK.1199364$cEE9.575037@usenetxs.com>
X-Complaints-To: https://www.astraweb.com/aup
NNTP-Posting-Date: Fri, 05 Aug 2022 01:43:16 UTC
Date: Fri, 05 Aug 2022 01:43:16 GMT
X-Received-Bytes: 1585
 by: Jack Webb - Fri, 5 Aug 2022 01:43 UTC

Off-topic troll...

--
NewsKrawler <newskrawl@krawl.org> wrote:

> Path: not-for-mail
> From: NewsKrawler <newskrawl@krawl.org>
> Newsgroups: alt.comp.os.windows-10
> Subject: SHARPEXT can access Gmail without compromising login credentials
> Date: Thu, 4 Aug 2022 03:04:53 -0000 (UTC)
> Organization: To protect and to server
> Message-ID: <tcfd0k$1719i$1@paganini.bofh.team>
> Injection-Date: Thu, 4 Aug 2022 03:04:53 -0000 (UTC)
> Injection-Info: paganini.bofh.team; logging-data="1279282"; posting-host="Dj+cCDj8UalGBjrWyMkOzw.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team";
> X-Notice: Filtered by postfilter v. 0.9.1
> X-Received-Bytes: 2279

SHARPEXT can access Gmail without compromising login credentials

<pH_GK.375221$7kM1.24689@usenetxs.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=65044&group=alt.comp.os.windows-10#65044

  copy link   Newsgroups: alt.comp.os.windows-10 free.spam
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!newsreader4.netcologne.de!news.netcologne.de!peer03.ams1!peer.ams1.xlned.com!news.xlned.com!peer02.ams4!peer.am4.highwinds-media.com!news.highwinds-media.com!fx09.ams4.POSTED!not-for-mail
From: dtgame...@gmail.com (Edward Hernandez)
Subject: SHARPEXT can access Gmail without compromising login credentials
Newsgroups: alt.comp.os.windows-10,free.spam
References: <tcfd0k$1719i$1@paganini.bofh.team> <UA_GK.1199364$cEE9.575037@usenetxs.com>
Lines: 47
Message-ID: <pH_GK.375221$7kM1.24689@usenetxs.com>
X-Complaints-To: https://www.astraweb.com/aup
NNTP-Posting-Date: Fri, 05 Aug 2022 01:50:13 UTC
Date: Fri, 05 Aug 2022 01:50:13 GMT
X-Received-Bytes: 2359
 by: Edward Hernandez - Fri, 5 Aug 2022 01:50 UTC

See also these Jake Isks (aka John Doe) troll nym-shift names:

John Doe <always.look@message.header>
John <look@post.header>
Judge Dredd <always.look@post.header>
"Edward's Mother" <always.see@post.header>
"Edward's Father" <always.see@post.header>
Edward Hernandez Loves Porn <always.view@post.header>
Edward Hernandez Smells Funny <view@post.header>
Jack Webb <myopinion@least.com>

Jake Isks (aka John Doe troll) claiming it has never nym-shifted on
Usenet: http://al.howardknight.net/?ID=165248158300

In message-id <t6nt3e$7bp$3@dont-email.me>
(http://al.howardknight.net/?ID=165357273000) posted Thu, 26 May 2022
12:50:54 -0000 (UTC) John Dope stated:

> Always Wrong, the utterly foulmouthed group idiot, adding absolutely
> NOTHING but insults to this thread, as usual...

Yet, since Wed, 5 Jan 2022 04:10:38 -0000 (UTC) John Dope's post ratio
to USENET (**) has been 76.9% of its posts contributing "nothing except
insults" to USENET.

** Since Wed, 5 Jan 2022 04:10:38 -0000 (UTC) John Dope has posted at
least 3730 articles to USENET. Of which 176 have been pure insults and
2691 have been John Dope "troll format" postings.

The Troll Doe stated the following in message-id
<sdhn7c$pkp$4@dont-email.me>:

> The troll doesn't even know how to format a USENET post...

And the Troll Doe stated the following in message-id
<sg3kr7$qt5$1@dont-email.me>:

> The reason Bozo cannot figure out how to get Google to keep from
> breaking its lines in inappropriate places is because Bozo is
> CLUELESS...

And yet, the clueless Troll Doe has itself posted yet another
incorrectly formatted USENET posting on Fri, 05 Aug 2022 01:43:16 GMT in
message-id <UA_GK.1199364$cEE9.575037@usenetxs.com>.

fyw4YqTZD92h

Re: SHARPEXT can access Gmail without compromising login credentials

<tcjt4s$1r503$1@paganini.bofh.team>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=65048&group=alt.comp.os.windows-10#65048

  copy link   Newsgroups: alt.comp.os.windows-10 free.spam
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: newskr...@krawl.org (NewsKrawler)
Newsgroups: alt.comp.os.windows-10,free.spam
Subject: Re: SHARPEXT can access Gmail without compromising login credentials
Date: Fri, 5 Aug 2022 20:04:45 -0000 (UTC)
Organization: To protect and to server
Message-ID: <tcjt4s$1r503$1@paganini.bofh.team>
References: <tcfd0k$1719i$1@paganini.bofh.team> <UA_GK.1199364$cEE9.575037@usenetxs.com> <pH_GK.375221$7kM1.24689@usenetxs.com>
Injection-Date: Fri, 5 Aug 2022 20:04:45 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="1938435"; posting-host="5IFKlfXIIF692ushLKoxOA.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team";
X-Notice: Filtered by postfilter v. 0.9.1
 by: NewsKrawler - Fri, 5 Aug 2022 20:04 UTC

Both the "Jack Webb" & "Edward Hernandez" trolls did not understand this is
a Windows-only problem, powershell-only, and a Windows Chrome only issue.

They didn't even read the cite before making their senseless declarations.

Re: SHARPEXT can access Gmail without compromising login credentials

<tcjtf0$1r6gp$1@paganini.bofh.team>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=65049&group=alt.comp.os.windows-10#65049

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: newskr...@krawl.org (NewsKrawler)
Newsgroups: alt.comp.os.windows-10
Subject: Re: SHARPEXT can access Gmail without compromising login credentials
Date: Fri, 5 Aug 2022 20:10:09 -0000 (UTC)
Organization: To protect and to server
Message-ID: <tcjtf0$1r6gp$1@paganini.bofh.team>
References: <tcfd0k$1719i$1@paganini.bofh.team> <UA_GK.1199364$cEE9.575037@usenetxs.com> <pH_GK.375221$7kM1.24689@usenetxs.com> <tcjt4s$1r503$1@paganini.bofh.team>
Injection-Date: Fri, 5 Aug 2022 20:10:09 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="1939993"; posting-host="5IFKlfXIIF692ushLKoxOA.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team";
X-Notice: Filtered by postfilter v. 0.9.1
 by: NewsKrawler - Fri, 5 Aug 2022 20:10 UTC

Please ignore my prior response to the troll as I have since found out that
the "Edward Hernandez" troll is forging the "Jack Webb" account, according
to a subsequent explanatory post by "Jack Webb" on the Windows 11 ng.

Suffice to say this is a Windows only problem due to a flaw in Powershell
that affects Chrome-like browsers (Microsoft's and Google's anyway).

Re: SHARPEXT can access Gmail without compromising login credentials

<3b92cc78ae9db5af55b51f46adae12e6@bare.invalid>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=65050&group=alt.comp.os.windows-10#65050

  copy link   Newsgroups: alt.comp.os.windows-10 alt.comp.os.windows-11
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!newsreader4.netcologne.de!news.netcologne.de!peer01.ams1!peer.ams1.xlned.com!news.xlned.com!peer02.ams4!peer.am4.highwinds-media.com!news.highwinds-media.com!fx01.ams4.POSTED!not-for-mail
From: hubb...@cupboard.bare.invalid (Old Mother Hubbard)
Newsgroups: alt.comp.os.windows-10,alt.comp.os.windows-11
Subject: Re: SHARPEXT can access Gmail without compromising login credentials
Message-ID: <3b92cc78ae9db5af55b51f46adae12e6@bare.invalid>
References: <tcfd0k$1719i$1@paganini.bofh.team> <tcfd28$171j7$1@paganini.bofh.team> <DA_GK.1199342$cEE9.1132074@usenetxs.com> <UA_GK.1199364$cEE9.575037@usenetxs.com> <pH_GK.375221$7kM1.24689@usenetxs.com> <nG_GK.375185$7kM1.142138@usenetxs.com> <tcjt9b$1r5kq$1@paganini.bofh.team> <tcjt4s$1r503$1@paganini.bofh.team>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.11.0
MIME-Version: 1.0
In-Reply-To: <tcjt4s$1r503$1@paganini.bofh.team>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Lines: 9
X-Complaints-To: https://www.astraweb.com/aup
NNTP-Posting-Date: Fri, 05 Aug 2022 22:05:05 UTC
Date: Fri, 5 Aug 2022 22:05:05 -0000
X-Received-Bytes: 1519
 by: Old Mother Hubbard - Fri, 5 Aug 2022 22:05 UTC

NewsKrawler <newskrawl@krawl.org> wrote:

> Both the "Jack Webb" & "Edward Hernandez" trolls did not understand this is
> a Windows-only problem, powershell-only, and a Windows Chrome only issue.

"NewsKrawler" had also not understood this, because "NewsKrawler" posted
the same to both the Firefox and Thunderbird newsgroups. (That is, to
both alt.comp.software.firefox and alt.comp.software.thunderbird.)

Re: SHARPEXT can access Gmail without compromising login credentials

<tcknak$1urkf$1@paganini.bofh.team>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=65052&group=alt.comp.os.windows-10#65052

  copy link   Newsgroups: alt.comp.os.windows-10 alt.comp.os.windows-11
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: newskr...@krawl.org (NewsKrawler)
Newsgroups: alt.comp.os.windows-10,alt.comp.os.windows-11
Subject: Re: SHARPEXT can access Gmail without compromising login credentials
Date: Sat, 6 Aug 2022 03:31:33 -0000 (UTC)
Organization: To protect and to server
Message-ID: <tcknak$1urkf$1@paganini.bofh.team>
References: <tcfd0k$1719i$1@paganini.bofh.team> <tcfd28$171j7$1@paganini.bofh.team> <DA_GK.1199342$cEE9.1132074@usenetxs.com> <UA_GK.1199364$cEE9.575037@usenetxs.com> <pH_GK.375221$7kM1.24689@usenetxs.com> <nG_GK.375185$7kM1.142138@usenetxs.com> <tcjt9b$1r5kq$1@paganini.bofh.team> <tcjt4s$1r503$1@paganini.bofh.team> <3b92cc78ae9db5af55b51f46adae12e6@bare.invalid>
Injection-Date: Sat, 6 Aug 2022 03:31:33 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="2059919"; posting-host="5IFKlfXIIF692ushLKoxOA.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team";
X-Notice: Filtered by postfilter v. 0.9.1
 by: NewsKrawler - Sat, 6 Aug 2022 03:31 UTC

On 2022-08-05, Old Mother Hubbard <hubbard@cupboard.bare.invalid> wrote:

> "NewsKrawler" had also not understood this, because "NewsKrawler" posted
> the same to both the Firefox and Thunderbird newsgroups. (That is, to
> both alt.comp.software.firefox and alt.comp.software.thunderbird.)

When it was breaking news, it was unknown to me that ONLY Chrome and Edge
were affected. Not even Chromium (as far as I'm aware at this moment).

Just Chrome and Edge.
However at the time the news was posted that wasn't known to be the case.

What more do you know about this exploit that hasn't been publicized yet?

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor