Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

steve2470

(37,457 posts)
Sat Sep 16, 2017, 01:14 PM Sep 2017

Beware of the Bashware: A New Method for Any Malware to Bypass Security Solutions

https://research.checkpoint.com/beware-bashware-new-method-malware-bypass-security-solutions/

With a growing number of cyber-attacks and the frequent news headlines on database breaches, spyware and ransomware, quality security products have become a commodity in every business organization. Consequently a lot of thought is being invested in devising an appropriate information security strategy to combat these breaches and providing the best solutions possible.

We have recently found a new and alarming method that allows any known malware to bypass even the most common security solutions, such as next generation anti-viruses, inspection tools, and anti-ransomware. This technique, dubbed Bashware, leverages a new Windows 10 feature called Subsystem for Linux (WSL), which recently exited Beta and is now a fully supported Windows feature.

This feature makes the popular bash terminal available for Windows OS users, and in so doing, enables users to natively run Linux operating system executables on the Windows operating system.

Existing security solutions are still not adapted to monitor processes of Linux executables running on Windows OS, a hybrid concept which allows a combination of Linux and Windows systems to run at the same time. This may open a door for cyber criminals wishing to run their malicious code undetected, and allow them to use the features provided by WSL to hide from security products that have not yet integrated the proper detection mechanisms.

Watch the Demo of the Attack:


more at link above
1 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Beware of the Bashware: A New Method for Any Malware to Bypass Security Solutions (Original Post) steve2470 Sep 2017 OP
I have Windows Subsystem for Linux on my Windows 10 build but it's not on teach1st Sep 2017 #1

teach1st

(5,935 posts)
1. I have Windows Subsystem for Linux on my Windows 10 build but it's not on
Sat Sep 16, 2017, 02:09 PM
Sep 2017

If you go to Control Panel > Programs > Turn Windows features on and off, and look for Windows Subsystem for Linux (beta). By default, it's not checked. If it's there and it's not checked, it's not on. If it's there and checked, and you don't need it, uncheck it.

How to install or uninstall:
https://www.howtogeek.com/261188/how-to-uninstall-or-reinstall-windows-10s-ubuntu-bash-shell/

ON EDIT: Oops. Apparently the article you posted says the new malware enables Windows Subsystem for Linux for those running developer mode.

Latest Discussions»Help & Search»Computer Help and Support»Beware of the Bashware: A...