winget: Install ROGUE Software & Packages?

Sdílet
Vložit
  • čas přidán 6. 09. 2024
  • j-h.io/plextrac || Save time and effort on pentest reports with PlexTrac's premiere reporting & collaborative platform in a FREE one-month trial! j-h.io/plextrac 😎
    🔥 CZcams ALGORITHM ➡ Like, Comment, & Subscribe!
    🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware

Komentáře • 34

  • @MoustacheChauveau
    @MoustacheChauveau Před rokem +13

    I did not validate this with the winget docs, but if setting the LocalManifestFiles configuration would modify the user settings of winget, why would an attacker not simply edit that file to have the setting on instead of having to impersonate local admin? I think this would explain why changing the setting does not edit the user settings json.

    • @CZghost
      @CZghost Před rokem +4

      I guess the file is likely also protected against writing with admin privileges.

  • @aviationbutterr
    @aviationbutterr Před rokem +2

    Little tip, around 6:24 you exit the terminal to open up a new admin one. I don't know about you but that gets a little annoying for me to do so I found this tool called "gsudo". You can call it as gsudo or just sudo. If you just type `gsudo` it will do a UAC prompt and then bring you to a new privliaged powershell environment, but if you do `gsudo [commands ...]` it will just do that command with admin privliages and then bring you back to your normal environment. I find it pretty handy

  • @6r1nch4
    @6r1nch4 Před rokem +1

    Love it, I use winget all the time as a System Engineer

  • @ReligionAndMaterialismDebunked

    Just 31 comments. Damn. Hehe. I saw this on my feed many hours ago, but now I'm here, at 21 hours ago posted status. Hehe

  • @f.andersen3824
    @f.andersen3824 Před rokem +1

    Uhhh, didn’t know about winget at all. Thanks man, very interesting.

  • @blinking_dodo
    @blinking_dodo Před rokem +3

    Neat. Also,
    I am pretty sure that unzipping a folder can trigger network activity...
    Not gonna talk about it here, since i would be using it as my own 0-day.
    (Or is John interested?)

    • @Thiole
      @Thiole Před rokem +2

      You should email him directly instead of having it up here.

    • @blinking_dodo
      @blinking_dodo Před rokem +1

      @@Thiole Yeah no, i am not going to just burn a potential 0-day on my own.
      If he is interested he can ask me to mail something, but if he doesn't read it, I'd rather not wake the sleeping John... 🙃

    • @DD-vp7fz
      @DD-vp7fz Před rokem +3

      That's not a 0day but expected behavior

    • @ryanstricklin198
      @ryanstricklin198 Před rokem +4

      Don’t think you understand what a zero day is since this is a common action that occurs

    • @uuu12343
      @uuu12343 Před rokem +2

      You keep calling it zero-day, but thats not a zero day
      Unzipping a folder via remote network connections such as ssh will trigger as a network activity...BECAUSE IT IS A NETWORK ACTIVITY
      it's down to your IDS to note down the whitelisted addresses or the blacklisted addresses
      Thats by nature

  • @_._._._._._._.__._._._._._._._

    Interesting....

  • @Vilematrix
    @Vilematrix Před rokem +1

    I always wonder. Malwarebytes uses LOL strings. Whut

  • @dom1310df
    @dom1310df Před rokem +4

    TIL that winget is a thing. Will have to use it when I next need to install software on Windows. Might stop me from going crazy.

    • @Beateau
      @Beateau Před rokem

      Seriously. I seem to have to install teams every time I use a new computer or tablet at work (which is often) This will be a lot faster than trying to do it through the store or browser. One simple cmd line. Elegant.

  • @uzumakiuchiha7678
    @uzumakiuchiha7678 Před rokem

    Its kewl

  • @dtvdavid
    @dtvdavid Před rokem

    So if I interpret it correctly, these LOLBAS things are like syskey.exe in the past?

  • @YouChwb
    @YouChwb Před rokem

    Probs malware...well, someone was going to say it eventually.

  • @baxuvis275
    @baxuvis275 Před rokem

    sixth comment posted here

  • @RazoBeckett.
    @RazoBeckett. Před rokem

    i was watching ...

  • @RX_100.0
    @RX_100.0 Před rokem +1

    Okay, i am first

  • @DayzGone
    @DayzGone Před rokem

    He uses PowerShell instead of cmd. Is there any reason as to why?

    • @sahilsinhahhh8329
      @sahilsinhahhh8329 Před rokem

      winget is powershell native

    • @iam-py-test
      @iam-py-test Před rokem +3

      @@sahilsinhahhh8329 winget is not part of PowerShell; it is an executable and can be run from cmd, or any other way to run an executable. (It is located in C:\Users\%username%\AppData\Local\Microsoft\WindowsApps\ on my system)

    • @1stAshaMan
      @1stAshaMan Před rokem +5

      Probably because powershell is more similar to the linux terminals he's used to than command prompt is

    • @DayzGone
      @DayzGone Před rokem +1

      @@1stAshaMan I noticed a difference even with the dir command. cmd just shows directories. PowerShell displays permissions and the last time a folder was accessed. I might switch lol

    • @iam-py-test
      @iam-py-test Před rokem +1

      @@DayzGone Agreed. The only thing is that I'm familiar with Linux ls and cmd.exe dir, so it will take some learning

  • @vnc.t
    @vnc.t Před rokem

    why have winget download and execute the virus if you have a shell already? why not do it yourself?

  • @BoneE710S
    @BoneE710S Před rokem

    There no audio